* Most artifacts have parameters that allow us to be more targeted in
collection
* Being targeted is good because it reduces the amount of data we
collect!
---
## More targeted in collection
* Treat the endpoint as the ultimate source of truth - need more
data? go back and re-fetch it from the endpoint.
data:image/s3,"s3://crabby-images/5222a/5222ace2a6181af624d6162158d80d389df0fff7" alt=""
---
## Post processing with notebooks
* Another alternative is to collect all the data and then post-process using the GUI
* Helps us drill into the data and understand what is going on.
data:image/s3,"s3://crabby-images/7d53f/7d53fd0309a197a1042e2884841ed99166ec9e64" alt=""
---
# Hunting at scale
---
## Hunting - mass collections
Hunting is Velociraptor's strength - collect the same artifact from thousands of endpoints in minutes!
* Two types of hunts:
* Detection hunts are very targeted aimed at yes/no answer
* Collection hunts collect a lot more data and can be used to
build a baseline.
---
## Exercise - baseline event logs
For this exercise we start a few more clients.
```text
c:\Users\test>cd c:\Users\test\AppData\Local\Temp\
c:\Users\test\AppData\Local\Temp>Velociraptor.exe
--config client.config.yaml pool_client --number 100
```
This starts 100 virtual clients so we can hunt them
* We use pool clients to simulate load on the server
---
## Pool clients
Simply multiple instances of the same client
data:image/s3,"s3://crabby-images/1ec4a/1ec4a2a2a3b9ab458017d6f796c424689dfd1f2f" alt=""
---
## Create a hunt
data:image/s3,"s3://crabby-images/7efcb/7efcbc7f45567bfaccca55dc4d0211f056e875b6" alt=""
---
## Select hunt artifacts
data:image/s3,"s3://crabby-images/10417/1041783588a2b7f7e2e013e9b30982ff0af98a8e" alt=""
---
## Collect results
data:image/s3,"s3://crabby-images/a6187/a618795a61a55a1c76215653d317bd14ddfc8f67" alt=""
---
## Exercise - Stacking
* The previous collection may be considered the baseline
* For this exercise we want to create a few different clients.
* Stop the pool client
* Disable a log channel
* Start the pool client with an additional number of clients
```
Velociraptor.exe --config client.config.yaml pool_client --number 110
```
---
## Stacking can reveal results that stand out
data:image/s3,"s3://crabby-images/4b5c1/4b5c15a6b3edb008b3e608c443506f43b41af44b" alt=""