Actions8
Download Flow File
AI-generatedSummary
Download files uploaded by a completed Velociraptor collection flow from a specific client using the Velociraptor gRPC API.
Inputs
- Client ID (required) — Velociraptor client ID (e.g. C.1234567890abcdef) identifying the client from which to download the flow file.
- Flow ID (required) — Flow ID returned by a Collect Artifact or Collect VFS File operation (e.g. F.C123456) specifying the collection flow whose files to download.
- File Path Filter — Optional exact file path to filter which uploaded file to download from the flow. Leave blank to download all files uploaded by the flow.
- Password-Protected ZIP — Whether to wrap the downloaded file(s) in a password-protected ZIP archive for safer handling of suspicious or potentially malicious files.
- ZIP Password — Password to use for the ZIP archive when password protection is enabled. Defaults to 'infected' following malware analysis conventions.
Output shape
a list of binary file items
Returns one binary item per downloaded file matching the filter. Each item contains metadata (client ID, flow ID, original file path, size) in JSON and the file content in binary form. Files can be optionally wrapped in password-protected ZIP archives (using ZipCrypto encryption compatible with common tools). If no files match the filter, an error is thrown advising to check available file paths via List Flow Uploads operation.
Examples
Example 1: Download a single specific file from a flow as a password-protected ZIP
Set Client ID and Flow ID for the completed collection flow, provide the exact 'File Path Filter' for the file to download, enable 'Password-Protected ZIP', and optionally adjust the ZIP password.
Example 2: Download all files uploaded by a flow without ZIP wrapping
Set Client ID and Flow ID, leave 'File Path Filter' blank, and disable 'Password-Protected ZIP' to retrieve all uploaded files as raw binaries.