Velociraptor icon

Velociraptor

Interact with Velociraptor DFIR platform via gRPC API

Collect VFS File

AI-generated

Summary

Collect a specific file from a Velociraptor client by specifying the client ID and the file path to run the System.VFS.DownloadFile artifact and start a collection flow.

Inputs

  • Client ID (required) — Velociraptor client ID (e.g. C.1234567890abcdef) identifying the target client from which to collect the file.
  • File Path (required) — Absolute path of the file on the client to collect (e.g. C:\Windows\System32\drivers\etc\hosts or /etc/passwd). This triggers System.VFS.DownloadFile with that path.

Output shape

a single JSON object representing the initiated collection flow with client ID, flow ID, artifact name, file path, and current state.

The operation returns immediately with flow information including flow_id that can be used subsequently to track flow status or retrieve collected data. No file content is returned directly by this node.

Examples

Example 1: Collect the hosts file from a Windows client

Set Client ID to the target client like 'C.1234567890abcdef' and File Path to 'C:\Windows\System32\drivers\etc\hosts' to trigger file collection.

Links

Discussion