Actions8
Collect Artifact
AI-generatedSummary
Trigger an artifact collection on a specified Velociraptor client, optionally passing parameters to customize the artifact collection.
Inputs
- Client ID (required) — Velociraptor client ID, e.g., C.1234567890abcdef, identifying the target client to collect the artifact from.
- Artifact Name (required) — Name of the artifact to collect on the client, such as 'Custom.BrowserExtensions' or any artifact registered in Velociraptor.
- Artifact Parameters — Optional JSON string providing parameters to pass to the artifact. Parameter keys must exactly match those defined by the artifact. For example, use '{"Path": "C:\Temp\file.txt"}' to specify a file path for System.VFS.DownloadFile artifact.
Output shape
A single JSON object representing the initiated collection flow containing client_id, flow_id, artifact name, and the current flow state (usually 'RUNNING').
The node triggers the collection using Velociraptor's collect_client VQL function and waits for the server response. It returns an object with the flow_id required for subsequent flow status or result queries. If parameters are provided, they are parsed from JSON and included in the VQL query. Errors occur if artifact parameters are invalid JSON or the server does not return a flow ID.
Examples
Example 1: Collect a custom artifact named Custom.BrowserExtensions on client C.1234567890abcdef with no parameters
Set Client ID to C.1234567890abcdef, Artifact Name to Custom.BrowserExtensions, leave Artifact Parameters empty.
Example 2: Collect System.VFS.DownloadFile artifact from client specifying a path parameter
Set Client ID appropriately, Artifact Name to System.VFS.DownloadFile, and Artifact Parameters to a JSON string like {"Path": "C:\Temp\file.txt"}.