* Most artifacts have parameters that allow us to be more targeted in
collection
* Being targeted is good because it reduces the amount of data we
collect!
---
## More targeted in collection
* Treat the endpoint as the ultimate source of truth - need more
data? go back and re-fetch it from the endpoint.
data:image/s3,"s3://crabby-images/78adb/78adb3f046760666b3aea957a4497120818fcc41" alt=""
---
## Post processing with notebooks
* Another alternative is to collect all the data and then post-process using the GUI
* Helps us drill into the data and understand what is going on.
data:image/s3,"s3://crabby-images/ae1d8/ae1d8dadd41cb0a244f07b711a1f185dd2f917fb" alt=""
---
# Hunting at scale
---
## Hunting - mass collections
Hunting is Velociraptor's strength - collect the same artifact from thousands of endpoints in minutes!
* Two types of hunts:
* Detection hunts are very targeted aimed at yes/no answer
* Collection hunts collect a lot more data and can be used to
build a baseline.
---
## Exercise - baseline event logs
For this exercise we start a few more clients.
```text
c:\Users\test>cd c:\Users\test\AppData\Local\Temp\
c:\Users\test\AppData\Local\Temp>Velociraptor.exe
--config client.config.yaml pool_client --number 100
```
This starts 100 virtual clients so we can hunt them
* We use pool clients to simulate load on the server
---
## Pool clients
Simply multiple instances of the same client
data:image/s3,"s3://crabby-images/3a331/3a33113e9b0fda2c49c94835c653dbfcd15960da" alt=""
---
## Create a hunt
data:image/s3,"s3://crabby-images/737f5/737f551d4315ded02015eb29aaff71385b8c14eb" alt=""
---
## Select hunt artifacts
data:image/s3,"s3://crabby-images/ae26b/ae26bab73548f33e1bc5ecb1700b842b877cf5ef" alt=""
---
## Collect results
data:image/s3,"s3://crabby-images/c75d2/c75d218fa9c2968327885aa00128d9244375ca19" alt=""
---
## Exercise - Stacking
* The previous collection may be considered the baseline
* For this exercise we want to create a few different clients.
* Stop the pool client
* Disable a log channel
* Start the pool client with an additional number of clients
```
Velociraptor.exe --config client.config.yaml pool_client --number 110
```
---
## Stacking can reveal results that stand out
data:image/s3,"s3://crabby-images/be542/be54290bc891a38cbfcaca48d741ba85120b5900" alt=""