Actions8
Collect VFS File
AI-generatedSummary
Collect a specific file from a Velociraptor client by specifying the client ID and the file path to run the System.VFS.DownloadFile artifact and start a collection flow.
Inputs
- Client ID (required) — Velociraptor client ID (e.g. C.1234567890abcdef) identifying the target client from which to collect the file.
- File Path (required) — Absolute path of the file on the client to collect (e.g. C:\Windows\System32\drivers\etc\hosts or /etc/passwd). This triggers System.VFS.DownloadFile with that path.
Output shape
a single JSON object representing the initiated collection flow with client ID, flow ID, artifact name, file path, and current state.
The operation returns immediately with flow information including flow_id that can be used subsequently to track flow status or retrieve collected data. No file content is returned directly by this node.
Examples
Example 1: Collect the hosts file from a Windows client
Set Client ID to the target client like 'C.1234567890abcdef' and File Path to 'C:\Windows\System32\drivers\etc\hosts' to trigger file collection.