diff --git a/.github/workflows/verify.yaml b/.github/workflows/verify.yaml index 67eec2eb93af..57df54442408 100644 --- a/.github/workflows/verify.yaml +++ b/.github/workflows/verify.yaml @@ -20,6 +20,12 @@ jobs: # Set to true when we want to start having errors fail the pipeline. fail_on_error: true + # Pin the Vale version. 3.22.0 regressed inline-HTML/markdown-link + # tokenization (concatenating adjacent words into single tokens, + # e.g. "Publishedon" -> "Publishedon"), failing the + # build on long-unchanged content. Bump intentionally. + version: 3.21.0 + # Only check lines touched by the PR to avoid reviewdog's # "too many annotations" failures on full-corpus scans. filter_mode: added diff --git a/assets/css/custom.css b/assets/css/custom.css index 8702f532d488..db547fa84bf1 100644 --- a/assets/css/custom.css +++ b/assets/css/custom.css @@ -332,12 +332,20 @@ p.egg { } /* --- Generated config reference page (docs/deployment/references) --- - The item comments read as normal prose; each config item is the - code-font element on an unshaded bordered card, so the key/value lines - stand out from the comments around them without dual grey shading. */ + Each config item and its documentation comment are wrapped together in + a .ref-block div. The item renders as a code-font bordered card with + the key/breadcrumb/value as code; its comment reads as normal prose + beside the key, so key/value lines stand out without dual grey + shading. Leaf comments sit under the card; container comments sit + inside the right under the key row so they stay put. */ +.ref-block { + display: block; + margin: 0 0 1rem 0; +} + .item-comment { font-family: var(--hx-font-sans); - margin: 16px 0 6px 0; + margin: 6px 0 0 0; color: inherit; } @@ -359,6 +367,7 @@ p.egg { display: flex; align-items: center; padding-right: 1ex; + font-weight: 700; } /* Example values: same indent as the key/breadcrumb above them so the @@ -407,9 +416,17 @@ p.egg { list-style: none; cursor: pointer; display: flex; + flex-wrap: wrap; align-items: center; } +/* A container's own comment lives inside the summary right under its key + row, so it stays "under the ref-item" on every line regardless of + expansion depth. Force it to its own line below the key. */ +.reference-document details > summary .item-comment { + flex-basis: 100%; +} + .reference-document details > summary::-webkit-details-marker { display: none; } @@ -434,6 +451,9 @@ p.egg { padding: 0.5rem 0.75rem; margin: 0 0 0.5rem 0; transition: border-color 0.2s ease, background-color 0.2s ease; + /* Anchor targets: offset item cards below the sticky top navbar when a + shared #fragment link is opened, so the item is not hidden under it. */ + scroll-margin-top: calc(var(--navbar-height) + 1rem); } .dark .ref-item { @@ -472,11 +492,9 @@ p.egg { max-width: 30em; } -/* Filtered-out items are hidden; containers that match stay expanded. - The item's associated comment block hides with it (the filter toggles - filtered-out on both; see references/reference-filter script). */ -.ref-item.filtered-out, -.item-comment.filtered-out { +/* Each config item and its documentation comment are wrapped in one + .ref-block div, so hiding a block hides both. */ +.ref-block.filtered-out { display: none; } @@ -782,6 +800,14 @@ html.dark .hextra-nav-btn[aria-current] { --hextra-max-page-width: 84rem; --hextra-max-navbar-width: 84rem; --hextra-max-footer-width: 84rem; + /* The theme's static default --hextra-banner-height: 2rem is smaller than + the real banner (its h-10 close button makes it 2.5rem tall), and the + theme only re-measures that variable in deferred core/banner.js. Pre-set + the correct height here so first paint is already right and the floating + TOC chevrons (which offset by this variable) don't jump once the script + runs. When the banner is dismissed, head/banner.js sets the variable to + 0 inline before paint, which overrides this default. */ + --hextra-banner-height: 2.5rem; } @media (min-width: 768px) { @@ -1234,82 +1260,42 @@ html.dark #pagefind-site-search .pagefind-ui__result-tag { margin-left: 0.375rem; } -/* --- Pagefind filter panel (/search/ page) --- - Once the index carries data-pagefind-filter values, the old PagefindUI - renders a checkbox sidebar (fieldset.pagefind-ui__filter-panel) next to - the results. On this site the /search/ column (~768px) wraps the drawer, - so the panel renders as a collapsible "Section" accordion above the - results - style it as such (border-bottom, no right rules). */ -#pagefind-site-search .pagefind-ui__filter-panel { - margin-top: 1rem; -} -#pagefind-site-search .pagefind-ui__filter-panel-label { - font-size: 0.75rem; - font-weight: 700; - text-transform: uppercase; - letter-spacing: 0.05em; - color: var(--hx-color-neutral-500, #737373); -} -#pagefind-site-search .pagefind-ui__filter-block { - border-bottom: 1px solid var(--hx-color-neutral-200, #e5e5e5); -} -#pagefind-site-search .pagefind-ui__filter-name { - font-size: 0.875rem; - font-weight: 600; - color: var(--hx-color-neutral-900, #171717); -} -html.dark #pagefind-site-search .pagefind-ui__filter-name { - color: var(--hx-color-neutral-100, #f5f5f5); -} -#pagefind-site-search .pagefind-ui__filter-group { - gap: 0.625rem; - padding-top: 0.875rem; -} -#pagefind-site-search .pagefind-ui__filter-value { - display: flex; - align-items: center; - gap: 0.5rem; -} -#pagefind-site-search .pagefind-ui__filter-label { - font-size: 0.875rem; - color: var(--hx-color-neutral-700, #404040); -} -html.dark #pagefind-site-search .pagefind-ui__filter-label { - color: var(--hx-color-neutral-300, #d4d4d4); -} -#pagefind-site-search .pagefind-ui__filter-checkbox { - border: 1px solid var(--hx-color-neutral-300, #d4d4d4); - background-color: transparent; - border-radius: 4px; -} -#pagefind-site-search .pagefind-ui__filter-checkbox:checked { - background-color: var(--hx-color-primary-600, #2563eb); - border-color: var(--hx-color-primary-600, #2563eb); -} - -/* The search modal keeps the tag chips but not the filter sidebar - (filtering is a /search/ page feature). */ +/* --- /search/ page: native Pagefind filter panel is hidden --- + PagefindUI renders a checkbox "Section"/"Tags" filter panel per query once + the index carries data-pagefind-filter values. On this site the /search/ + column (~768px) would wrap it next to the results, and the shortcode already + renders its own server-side "Filter by Section" / "Filter by Tag" + accordions (visible before any query is typed). The native panel is + therefore hidden and used only as a source of truth: search.js reads its + per-value counts to prune the accordion pills and toggles its checkboxes + on pill click. The search modal keeps the tag chips but not the filter + sidebar (filtering is a /search/ page feature). */ +#pagefind-site-search .pagefind-ui__filter-panel, #pagefind-ui .pagefind-ui__filter-panel { display: none; } +/* The native filter blocks are left in the DOM (search.js reads their + counts) but must never paint. */ +#pagefind-site-search .pagefind-ui__filter-block[hidden] { + display: none !important; +} -/* --- /search/ page: "Tags" accordion (shortcode renders the same - taxonomy listing as the /tags/ page; search.js moves it into the - filter panel, under the Section block). The svelte-scoped pagefind - rules don't cover this element, so it needs its own chrome here. - The rules are scoped to the element id so they apply both before the - search (as a sibling of the PagefindUI mount) and once it is moved - into the filter panel; id specificity also beats the pagefind - `.pagefind-ui--reset * { all: unset }` inside the UI root. */ +/* --- /search/ page: "Filter by Section" and "Filter by Tag" accordions + (shortcode renders both, with the full server-side lists, so they are + visible before any query). The pagefind rules don't cover these elements, + so they need their own chrome here. The rules are scoped to the element + ids so they apply independently of the PagefindUI mount; id specificity + also beats the pagefind `.pagefind-ui--reset * { all: unset }`. */ +#pagefind-site-sections, #pagefind-site-tags { cursor: default; margin-top: 0.75rem; } -/* Inside the panel, the filter-panel already carries margin-top — - reset so the accordion sits flush under the Section block. */ -#pagefind-site-search .pagefind-ui__filter-panel #pagefind-site-tags { - margin-top: 0; +/* Keep the accordions visually separate from the PagefindUI input below. */ +.search-box[data-site-search] #pagefind-site-search { + margin-top: 1rem; } +#pagefind-site-sections .search-sections-name, #pagefind-site-tags .search-tags-name { position: relative; cursor: pointer; @@ -1321,14 +1307,18 @@ html.dark #pagefind-site-search .pagefind-ui__filter-label { font-weight: 600; color: var(--hx-color-neutral-900, #171717); } +html.dark #pagefind-site-sections .search-sections-name, html.dark #pagefind-site-tags .search-tags-name { color: var(--hx-color-neutral-100, #f5f5f5); } +#pagefind-site-sections .search-sections-name::-webkit-details-marker, +#pagefind-site-sections .search-sections-name::marker, #pagefind-site-tags .search-tags-name::-webkit-details-marker, #pagefind-site-tags .search-tags-name::marker { display: none; } /* Same disclosure chevron as the Section blocks (border triangle). */ +#pagefind-site-sections .search-sections-name::after, #pagefind-site-tags .search-tags-name::after { content: ""; position: absolute; @@ -1341,21 +1331,29 @@ html.dark #pagefind-site-tags .search-tags-name { border-top: 0; transform: translateY(-70%) rotate(-45deg); } +#pagefind-site-sections[open] .search-sections-name::after, #pagefind-site-tags[open] .search-tags-name::after { transform: translateY(-70%) rotate(-225deg); } -/* Tag cloud: the panel column is narrow, so wrap instead of the /tags/ +/* Pill clouds: the panel column is narrow, so wrap instead of the /tags/ page's multi-column grid. */ +#pagefind-site-sections .search-sections-grid, #pagefind-site-tags .search-tags-grid { display: flex; flex-wrap: wrap; gap: 0.25rem 1.5rem; padding-top: 0.875rem; } -/* Filter-toggle pills in the /search/ Tags accordion. - Originally styled for elements; now rendered as +
Client > proxy_config > proxy_url_regexp
+
- -
- - Location of a PAC file (overrides the above settings). This can - be a file:// URL or even a data: url. -
+ +
  • @@ -603,14 +661,15 @@ description: |
    Client > proxy_config > pac
    <not set>
  • -
    - If this is set we ignore the HTTP_PROXY and HTTPS_PROXY - environment variables. By default we allow these environment - variables to override the settings in this file. + Location of a PAC file (overrides the above settings). This can + be a file:// URL or even a data: url.
    +
    + +
  • @@ -620,19 +679,21 @@ description: |
    Client > proxy_config > ignore_environment
    false
  • +
    + + If this is set we ignore the HTTP_PROXY and HTTPS_PROXY + environment variables. By default we allow these environment + variables to override the settings in this file. + +
    +
    - -
    - - The Internal Velociraptor CA certificate used to verify the - server certificates. Do not change this! This will be generated - by the config wizard and can not be replaced. It is only used - internally. -
    + +
  • @@ -646,15 +707,17 @@ Generated by the config wizard!!! -----END CERTIFICATE-----
  • -
    - This is a shared secret between servers and clients. The server - will refuse to communicate with clients having the wrong nonce. - The nonce is used to group clients into Org Groups - so clients - from different orgs have different nonce. + The Internal Velociraptor CA certificate used to verify the + server certificates. Do not change this! This will be generated + by the config wizard and can not be replaced. It is only used + internally.
    + + +
  • @@ -664,17 +727,17 @@ Generated by the config wizard!!!
    Client > nonce
    rKNKAYam310=
  • -
    - The following are the locations to write the writeback file - - this file is used to keep client state. In the default - configuration, writeback files persist across uninstall/reinstall - cycles to keep the client id consistent. If you don't want this - you can change the location of the writeback to be inside the - tempdir_windows directory (it will be removed on uninstall). + This is a shared secret between servers and clients. The server + will refuse to communicate with clients having the wrong nonce. + The nonce is used to group clients into Org Groups - so clients + from different orgs have different nonce.
    +
    + +
  • @@ -684,12 +747,19 @@ Generated by the config wizard!!!
    Client > writeback_darwin
    /etc/velociraptor.writeback.yaml
  • -
    + The following are the locations to write the writeback file - + this file is used to keep client state. In the default + configuration, writeback files persist across uninstall/reinstall + cycles to keep the client id consistent. If you don't want this + you can change the location of the writeback to be inside the + tempdir_windows directory (it will be removed on uninstall). -
    +
    + +
  • @@ -699,14 +769,14 @@ Generated by the config wizard!!!
    Client > writeback_linux
    /tmp/velociraptor.writeback.yaml
  • -
    - On Windows, if the writeback path starts with HKLM\ the path will - be interpreted as a registry key that will be used to store the - writeback instead of files on disk. +
    +
    + +
  • @@ -716,16 +786,16 @@ Generated by the config wizard!!!
    Client > writeback_windows
    $ProgramFiles\Velociraptor\velociraptor.writeback.yaml
  • -
    - If this value is specified, Velociraptor will create a level 2 - writeback file. This second file is used as a backup and to write - more frequently updated content. This scheme should reduce the - likelihood that the file is corrupted to the point that the client - id is lost. + On Windows, if the writeback path starts with HKLM\ the path will + be interpreted as a registry key that will be used to store the + writeback instead of files on disk.
    +
    + +
  • @@ -735,14 +805,18 @@ Generated by the config wizard!!!
    Client > level2_writeback_suffix
    l2
  • -
    - This is the directory Velociraptor will use for temporary - files. If not specified or not writable, Velociraptor will use - the $TMP or $TEMP env variable. + If this value is specified, Velociraptor will create a level 2 + writeback file. This second file is used as a backup and to write + more frequently updated content. This scheme should reduce the + likelihood that the file is corrupted to the point that the client + id is lost.
    +
    + +
  • @@ -752,12 +826,16 @@ Generated by the config wizard!!!
    Client > tempdir_windows
    $ProgramFiles\Velociraptor\Tools
  • -
    + This is the directory Velociraptor will use for temporary + files. If not specified or not writable, Velociraptor will use + the $TMP or $TEMP env variable. -
    +
    + +
  • @@ -767,12 +845,14 @@ Generated by the config wizard!!!
    Client > tempdir_linux
    /tmp/
  • -
    +
    + +
  • @@ -782,16 +862,14 @@ Generated by the config wizard!!!
    Client > tempdir_darwin
    /tmp/
  • -
    - Number of seconds to wait before polling. Typically Velociraptor - connections are persistent but will force a re-connection every - max_poll seconds to refresh the connection. NOTE that typically - Velociraptor reuses TCP connections so this only applies to the - HTTP transactions, i.e. The TCP connections are always up. + +
    + +
  • @@ -801,14 +879,18 @@ Generated by the config wizard!!!
    Client > max_poll
    60
  • -
    - Standard deviation between polls adds randomness to the poll - period. This ensures that clients are not synchronized to even up - the load on the server. + Number of seconds to wait before polling. Typically Velociraptor + connections are persistent but will force a re-connection every + max_poll seconds to refresh the connection. NOTE that typically + Velociraptor reuses TCP connections so this only applies to the + HTTP transactions, i.e. The TCP connections are always up.
    +
    + +
  • @@ -818,16 +900,16 @@ Generated by the config wizard!!!
    Client > max_poll_std
    30
  • -
    - If this is set, the nanny will exit if we are not able to send - messages to the server within this many seconds. NOTE - even a - failed connection will reset the counter, the nanny will only fire - if the client has failed in some way - e.g. the communicator is - stopped for some reason + Standard deviation between polls adds randomness to the poll + period. This ensures that clients are not synchronized to even up + the load on the server.
    +
    + +
  • @@ -837,13 +919,18 @@ Generated by the config wizard!!!
    Client > nanny_max_connection_delay
    0
  • -
    - If this is set, prevent arbitrary code execution on clients. NOTE: - This will vastly reduce the capabilities of the client. + If this is set, the nanny will exit if we are not able to send + messages to the server within this many seconds. NOTE - even a + failed connection will reset the counter, the nanny will only fire + if the client has failed in some way - e.g. the communicator is + stopped for some reason
    +
    + +
  • @@ -853,14 +940,15 @@ Generated by the config wizard!!!
    Client > prevent_execve
    false
  • -
    - The default max time to wait before we send partial VQL - results. This setting is used to ensure we don't send too many - small requests by batching the rows into time batches. + If this is set, prevent arbitrary code execution on clients. NOTE: + This will vastly reduce the capabilities of the client.
    +
    + +
  • @@ -870,15 +958,16 @@ Generated by the config wizard!!!
    Client > default_max_wait
    60
  • -
    - Maximum number of concurrent queries the client will allow - (default 2). This ensures we do not overwhelm the client by - scheduling too many concurrent queries. NOTE: Queries marked as - URGENT will skip this control and run anyway. + The default max time to wait before we send partial VQL + results. This setting is used to ensure we don't send too many + small requests by batching the rows into time batches.
    +
    + +
  • @@ -888,14 +977,17 @@ Generated by the config wizard!!!
    Client > concurrency
    2
  • -
    - If set the client will hard exit when it uses this much memory (in - bytes). This is a safety feature to prevent runaway process - - ensure this is not set too low. + Maximum number of concurrent queries the client will allow + (default 2). This ensures we do not overwhelm the client by + scheduling too many concurrent queries. NOTE: Queries marked as + URGENT will skip this control and run anyway.
    +
    + +
  • @@ -905,15 +997,16 @@ Generated by the config wizard!!!
    Client > max_memory_hard_limit
    0
  • -
    - Clients will send a Server.Internal.ClientInfo message to the - server every this many seconds. This helps to keep the server info - up to date about each client. This should not be sent too - frequently. The default is 1 day (86400 seconds). + If set the client will hard exit when it uses this much memory (in + bytes). This is a safety feature to prevent runaway process - + ensure this is not set too low.
    +
    + +
  • @@ -923,16 +1016,17 @@ Generated by the config wizard!!!
    Client > client_info_update_time
    86400
  • -
    - When a collection starts on the client, the client writes a - checkpoint file so it can detect when it crashed previously and - restarted. If this option is set we disable client checkpoints - and so we can not report to the server when the client crashes - while collecting an artifact. + Clients will send a Server.Internal.ClientInfo message to the + server every this many seconds. This helps to keep the server info + up to date about each client. This should not be sent too + frequently. The default is 1 day (86400 seconds).
    +
    + +
  • @@ -942,29 +1036,36 @@ Generated by the config wizard!!!
    Client > disable_checkpoints
    false
  • -
    - These settings are used by the `velociraptor service install` - command. We typically do not use this as we prefer to distribute - MSI packages via package management systems. + When a collection starts on the client, the client writes a + checkpoint file so it can detect when it crashed previously and + restarted. If this option is set we disable client checkpoints + and so we can not report to the server when the client crashes + while collecting an artifact.
    +
    + +
  • - -
    Client > windows_installer
    -
      -
      - + These settings are used by the `velociraptor service install` + command. We typically do not use this as we prefer to distribute + MSI packages via package management systems.
      + +
      Client > windows_installer
      +
        + +
      • @@ -974,13 +1075,15 @@ Generated by the config wizard!!!
        Client > windows_installer > service_name
        Velociraptor
      • -
        -
      • +
      • + +
        +
      • install_path @@ -989,12 +1092,14 @@ Generated by the config wizard!!!
        Client > windows_installer > install_path
        $ProgramFiles\Velociraptor\Velociraptor.exe
      • -
        +
        + +
      • @@ -1004,31 +1109,35 @@ Generated by the config wizard!!!
        Client > windows_installer > service_description
        Velociraptor service
      • +
        + + + +
        +
  • - -
    - - Settings used by the darwin `velociraptor service install` command. -
    + +
  • - -
    Client > darwin_installer
    -
      -
      - + Settings used by the darwin `velociraptor service install` command.
      + +
      Client > darwin_installer
      +
        + +
      • @@ -1038,12 +1147,14 @@ Generated by the config wizard!!!
        Client > darwin_installer > service_name
        com.velocidex.velociraptor
      • -
        +
        + +
      • @@ -1053,20 +1164,19 @@ Generated by the config wizard!!!
        Client > darwin_installer > install_path
        /usr/local/sbin/velociraptor
      • +
        + + + +
        +
  • - -
    - - If this setting is true, Velociraptor will expect the server to - use self signed TLS certificates. The client will verify the TLS - connection by checking that the server certificate is signed by - the Velociraptor internal CA. With this setting it is possible to - use an IP address for the server URL (not recommended though) -
    + +
  • @@ -1076,12 +1186,18 @@ Generated by the config wizard!!!
    Client > use_self_signed_ssl
    true
  • -
    - Do not change this! + If this setting is true, Velociraptor will expect the server to + use self signed TLS certificates. The client will verify the TLS + connection by checking that the server certificate is signed by + the Velociraptor internal CA. With this setting it is possible to + use an IP address for the server URL (not recommended though)
    +
    + +
  • @@ -1091,13 +1207,14 @@ Generated by the config wizard!!!
    Client > pinned_server_name
    VelociraptorServer
  • -
    - The maximum size of the POST request the client will send to the - server. Some proxy servers limit the size of POST messages. + Do not change this!
    +
    + +
  • @@ -1107,13 +1224,15 @@ Generated by the config wizard!!!
    Client > max_upload_size
    5242880
  • -
    - Maximum timeout for connection retry - the length of time we - try a connection before restarting it (default 5 min). + The maximum size of the POST request the client will send to the + server. Some proxy servers limit the size of POST messages.
    +
    + +
  • @@ -1123,13 +1242,15 @@ Generated by the config wizard!!!
    Client > connection_timeout
    300
  • -
    - Disable client/server compression. Typically no need to change - this. + Maximum timeout for connection retry - the length of time we + try a connection before restarting it (default 5 min).
    +
    + +
  • @@ -1139,54 +1260,77 @@ Generated by the config wizard!!!
    Client > disable_compression
    false
  • -
    - It is possible to pre-label clients using the configuration - file. The server will add these labels to the clients - automatically upon enrollment. This allows different client - packages to be distributed in the real world and have them - automatically identified. + Disable client/server compression. Typically no need to change + this.
    +
    + +
  • - -
    Client > labels
    -
      -
      - + It is possible to pre-label clients using the configuration + file. The server will add these labels to the clients + automatically upon enrollment. This allows different client + packages to be distributed in the real world and have them + automatically identified.
      + +
      Client > labels
      +
        + +
      • Label1
        Client > labels
      • -
        +
        + +
      • Label1
        Client > labels
      • +
        + + + +
        +
  • +
    +
    +
  • + + + +
    Client > logfile_name
    +
    logfile.log
    +
  • The client normally does not write any logs on the @@ -1200,31 +1344,35 @@ Generated by the config wizard!!! decrypted on the server to read.
    -
  • +
  • + +
    +
  • -
    Client > logfile_name
    -
    logfile.log
    +
    Client > logfile_size
    +
    10000000
  • -
    -
  • +
  • + +
    +
  • -
    Client > logfile_size
    -
    10000000
    +
    Client > panic_file
    +
    $TEMP/panic.log
  • -
    On Windows, the client usually runs as a service. If a crash occurs @@ -1238,16 +1386,15 @@ Generated by the config wizard!!! where this setting will have no effect.
    -
  • - - - -
    Client > panic_file
    -
    $TEMP/panic.log
    -
  • +
    +
    +
  • +
    + +
    Velociraptor keeps a local buffer file to store query results @@ -1259,23 +1406,11 @@ Generated by the config wizard!!! out).
    -
  • -
    - -
    Client > local_buffer
      -
      - - Maximum size of the in-memory buffer. When this size is - exhausted the query is paused until the data is sent over the - network. - -
      +
    • @@ -1285,13 +1420,16 @@ Generated by the config wizard!!!
      Client > local_buffer > memory_size
      52428800
    • -
      - If the disk size of the local buffer is set to 0, no disk file - will be used, only a memory buffer will be used. + Maximum size of the in-memory buffer. When this size is + exhausted the query is paused until the data is sent over the + network.
      +
      + +
    • @@ -1301,13 +1439,15 @@ Generated by the config wizard!!!
      Client > local_buffer > disk_size
      1073741824
    • -
      - Where to store the files on the local disk for the various - operating systems. + If the disk size of the local buffer is set to 0, no disk file + will be used, only a memory buffer will be used.
      +
      + +
    • @@ -1317,12 +1457,15 @@ Generated by the config wizard!!!
      Client > local_buffer > filename_linux
      /var/tmp/Velociraptor_Buffer.bin
    • -
      + Where to store the files on the local disk for the various + operating systems. -
      +
      + +
    • @@ -1332,12 +1475,14 @@ Generated by the config wizard!!!
      Client > local_buffer > filename_windows
      $TEMP/Velociraptor_Buffer.bin
    • -
      +
      + +
    • @@ -1347,11 +1492,28 @@ Generated by the config wizard!!!
      Client > local_buffer > filename_darwin
      /var/tmp/Velociraptor_Buffer.bin
    • +
      + + + +
      +
  • +
  • +
    +
  • + + + +
    Client > insecure_network_trace_file
    +
    /tmp/trace.txt
    +
  • Setting this will write clear text network traces to this @@ -1366,36 +1528,25 @@ Generated by the config wizard!!! encrypted however.
    -
  • - - - -
    Client > insecure_network_trace_file
    -
    /tmp/trace.txt
    -
  • - -
    - - The server that created this config file - this is only a hint. -
    + +
  • - -
    Client > server_version
    -
      -
      - + The server that created this config file - this is only a hint.
      + +
      Client > server_version
      +
        + +
      • @@ -1405,18 +1556,19 @@ Generated by the config wizard!!!
        Client > server_version > system
        linux
      • +
        + + + +
        +
  • - -
    - - By default when running on a low resource machine we cap the - CPU use to 50%. This allows to change that - needs to be - between 0 and 100 (100 disables throttling). -
    + +
  • @@ -1426,14 +1578,16 @@ Generated by the config wizard!!!
    Client > low_resource_max_cpu
    50
  • -
    - We determine we are running on a low resource machine if the - system has less than 2 cores. This allows you to increase the - threshold. Set to a large number to disable. + By default when running on a low resource machine we cap the + CPU use to 50%. This allows to change that - needs to be + between 0 and 100 (100 disables throttling).
    +
    + +
  • @@ -1443,17 +1597,16 @@ Generated by the config wizard!!!
    Client > low_resource_cpu_count
    1
  • -
    - If greater than 0 we install a local DNS cache. This is usually - not needed as most operating systems already have local DNS - caching resolvers. This DNS cache will be refreshed periodically - from upstream. Note that the ttl of the record is currently - ignored and we refresh according to this setting. This setting - takes effect both on the client and on the server. + We determine we are running on a low resource machine if the + system has less than 2 cores. This allows you to increase the + threshold. Set to a large number to disable.
    +
    + +
  • @@ -1463,11 +1616,30 @@ Generated by the config wizard!!!
    Client > dns_cache_refresh_min
    0
  • +
    + + If greater than 0 we install a local DNS cache. This is usually + not needed as most operating systems already have local DNS + caching resolvers. This DNS cache will be refreshed periodically + from upstream. Note that the ttl of the record is currently + ignored and we refresh according to this setting. This setting + takes effect both on the client and on the server. + +
    +
    +
    +
    +
  • +
    + +
    + API +
    This section configures the API service. The API server accepts @@ -1475,23 +1647,11 @@ Generated by the config wizard!!! the gRPC API clients (e.g. with pyvelociraptor).
    -
  • -
    - -
    - API -
    API
      -
      - - This is the hostname used to connect to - it is used here to copy - into new api client configuration files to assist gRPC API - connections (e.g. pyvelociraptor). - -
      +
    • @@ -1501,14 +1661,16 @@ Generated by the config wizard!!!
      API > hostname
      192.168.1.11
    • -
      - Interface to bind to - by default only bind to 127.0.0.1 but will - need to be exposed on 0.0.0.0 for external pyvelociraptor clients - to connect. + This is the hostname used to connect to - it is used here to copy + into new api client configuration files to assist gRPC API + connections (e.g. pyvelociraptor).
      +
      + +
    • @@ -1518,12 +1680,16 @@ Generated by the config wizard!!!
      API > bind_address
      127.0.0.1
    • -
      - The port to listen on. + Interface to bind to - by default only bind to 127.0.0.1 but will + need to be exposed on 0.0.0.0 for external pyvelociraptor clients + to connect.
      +
      + +
    • @@ -1533,12 +1699,14 @@ Generated by the config wizard!!!
      API > bind_port
      8001
    • -
      - Usually these do not need to be changed. + The port to listen on.
      +
      + +
    • @@ -1548,14 +1716,14 @@ Generated by the config wizard!!!
      API > bind_scheme
      tcp
    • -
      - Do not change this. It is the common name of the certificate that - will be trusted to be from the GUI. ACL checks will be disabled - for all connections from this name. + Usually these do not need to be changed.
      +
      + +
    • @@ -1565,34 +1733,37 @@ Generated by the config wizard!!!
      API > pinned_gw_name
      GRPC_GW
    • +
      + + Do not change this. It is the common name of the certificate that + will be trusted to be from the GUI. ACL checks will be disabled + for all connections from this name. + +
      +
  • - -
    - - Configure the GUI admin web application. -
    + +
  • GUI
    -
    -
    GUI
    -
      -
      - Allows the GUI to start with no encryption - **WARNING** This only - makes sense if you have TLS proxy in front. In fact the GUI **will - not work** without a TLS proxy because the CSRF cookie is still - set to secure only. + Configure the GUI admin web application.
      +
  • +
    GUI
    +
      + +
    • @@ -1602,13 +1773,17 @@ Generated by the config wizard!!!
      GUI > use_plain_http
      false
    • -
      - You can serve Velociraptor at a sub path of the server. All URLs - will then be formed below the base path. + Allows the GUI to start with no encryption - **WARNING** This only + makes sense if you have TLS proxy in front. In fact the GUI **will + not work** without a TLS proxy because the CSRF cookie is still + set to secure only.
      +
      + +
    • @@ -1618,13 +1793,15 @@ Generated by the config wizard!!!
      GUI > base_path
      /
    • -
      - The public URL of this server. Change this if you are proxying the - GUI using a different URL. + You can serve Velociraptor at a sub path of the server. All URLs + will then be formed below the base path.
      +
      + +
    • @@ -1634,53 +1811,54 @@ Generated by the config wizard!!!
      GUI > public_url
      http://velo.example.com/app/index.html
    • -
      - A list of CIDR addresses from permitted networks. If this is not - set, permit all connections to the GUI from anywhere. This is - useful when you want to limit access to the GUI by IP address but - still allow access to clients from any IP, while running both the - frontend and GUI on the same port (normally port 443) + The public URL of this server. Change this if you are proxying the + GUI using a different URL.
      +
      + +
    • - -
      GUI > allowed_cidr
      -
        -
        - + A list of CIDR addresses from permitted networks. If this is not + set, permit all connections to the GUI from anywhere. This is + useful when you want to limit access to the GUI by IP address but + still allow access to clients from any IP, while running both the + frontend and GUI on the same port (normally port 443)
        + +
        GUI > allowed_cidr
        +
          + +
        • 192.168.0.0/16
          GUI > allowed_cidr
        • +
          + + + +
          +
    • - -
      - - Header defined by the proxy containing the remote address. This - header will be used in the allowed_cidr matching if specified. - NOTE: Only use this if you do have a reverse proxy in front of - the server. Otherwise an attacker can simply send this header - to pretend to come from any IP address. If this setting is - specified we take the src address from the header, otherwise - from the remote IP address. Default is not set. -
      + +
    • @@ -1690,42 +1868,52 @@ Generated by the config wizard!!!
      GUI > forwarded_proxy_header
      X-Forwarded-For
    • -
      - Allows additional links to be defined for site customization. + Header defined by the proxy containing the remote address. This + header will be used in the allowed_cidr matching if specified. + NOTE: Only use this if you do have a reverse proxy in front of + the server. Otherwise an attacker can simply send this header + to pretend to come from any IP address. If this setting is + specified we take the src address from the header, otherwise + from the remote IP address. Default is not set.
      +
      + +
      - -
      - - Bind the GUI to this port. By default: For self signed SSL the - GUI will be bound to the localhost only! For Let's Encrypt - deployments the GUI will be bound on 0.0.0.0 making it accessible - from anywhere. NOTE: The **only** valid settings here are 0.0.0.0 - for external access and 127.0.0.1 for localhost - Do not specify - any other address unless you know what you are doing! -
      + +
    • @@ -1887,14 +2090,19 @@ Generated by the config wizard!!!
      GUI > bind_address
      127.0.0.1
    • -
      - Bind port for the GUI. When using Let's Encrypt the GUI is bound - to port 443 and this setting is ignored because Let's Encrypt - only supports port 443. + Bind the GUI to this port. By default: For self signed SSL the + GUI will be bound to the localhost only! For Let's Encrypt + deployments the GUI will be bound on 0.0.0.0 making it accessible + from anywhere. NOTE: The **only** valid settings here are 0.0.0.0 + for external access and 127.0.0.1 for localhost - Do not specify + any other address unless you know what you are doing!
      +
      + +
    • @@ -1904,13 +2112,16 @@ Generated by the config wizard!!!
      GUI > bind_port
      8889
    • -
      - The internal certificate for gRPC connections between the gateway - and the API server. DO NOT Change this! + Bind port for the GUI. When using Let's Encrypt the GUI is bound + to port 443 and this setting is ignored because Let's Encrypt + only supports port 443.
      +
      + +
    • @@ -1924,12 +2135,15 @@ Generated by the config wizard!!! -----END CERTIFICATE-----
    • -
      + The internal certificate for gRPC connections between the gateway + and the API server. DO NOT Change this! -
      +
      + +
    • @@ -1943,44 +2157,47 @@ Generated by the config wizard!!! -----END RSA PRIVATE KEY-----
    • -
      - Velociraptor supports a reverse proxy allowing you to place other - applications behind the Velociraptor Oauth2/TLS server. + +
      + +
    • - -
      GUI > reverse_proxy
      -
        -
        - + Velociraptor supports a reverse proxy allowing you to place other + applications behind the Velociraptor Oauth2/TLS server.
        + +
        GUI > reverse_proxy
        +
          + +
        • [0]
          -
          -
          GUI > reverse_proxy > [0]
          -
            -
            - Any paths below this route will be forwarded to the given URL - (and the path copied into the target) +
            + +
            GUI > reverse_proxy > [0]
            +
              + +
            • @@ -1990,13 +2207,15 @@ Generated by the config wizard!!!
              GUI > reverse_proxy > [0] > route
              /CyberChef/
            • -
              - The URL to forward to. This can be a file:// URL which allows - you to host static files at this location. + Any paths below this route will be forwarded to the given URL + (and the path copied into the target)
              +
              + +
            • @@ -2006,13 +2225,15 @@ Generated by the config wizard!!!
              GUI > reverse_proxy > [0] > url
              file:///shared/CyberChef/
            • -
              - If this is set to true, the user needs to be authenticated to - Velociraptor before they are proxied. + The URL to forward to. This can be a file:// URL which allows + you to host static files at this location.
              +
              + +
            • @@ -2022,15 +2243,31 @@ Generated by the config wizard!!!
              GUI > reverse_proxy > [0] > require_auth
              true
            • +
              + + If this is set to true, the user needs to be authenticated to + Velociraptor before they are proxied. + +
              +
        • +
    • +
      +
      +
    • +
      + +
      A list of domains that we will trust to send us the CSRF @@ -2038,32 +2275,36 @@ Generated by the config wizard!!! than the API server.
      -
    • -
      - -
      GUI > trusted_origins
        -
        - - - -
        +
      • www.example.com
        GUI > trusted_origins
      • +
        + + + +
        +
    • +
    • +
      +
    • +
      + +
      When the Velociraptor server starts for the first time, the @@ -2073,36 +2314,27 @@ Generated by the config wizard!!! or change their ACLs/Roles later.
      -
    • -
      - -
      GUI > initial_users
        -
        - - - -
        +
      • [0]
        -
        -
        GUI > initial_users > [0]
        -
          -
          - Username to create +
          +
    • +
      GUI > initial_users > [0]
      +
        + +
      • @@ -2112,14 +2344,14 @@ Generated by the config wizard!!!
        GUI > initial_users > [0] > name
        mic
      • -
        - Password hashes - this is only useful for Basic Authenticator - which uses passwords. They can be left empty for Oauth based - authenticator. + Username to create
        +
        + +
      • @@ -2129,12 +2361,16 @@ Generated by the config wizard!!!
        GUI > initial_users > [0] > password_hash
        aa3a779e09062dea3a46811e0c0624ba7999cf15a2d12dce7489aca339c3deff
      • -
        + Password hashes - this is only useful for Basic Authenticator + which uses passwords. They can be left empty for Oauth based + authenticator. -
        +
        + +
      • @@ -2144,50 +2380,56 @@ Generated by the config wizard!!!
        GUI > initial_users > [0] > password_salt
        f8707a7a9c876a4e6210d4f5bbdee4846adff7465d50efc43a305175aab8f146
      • +
        + + + +
        +
    • +
  • - -
    - - When Velociraptor starts the first time these orgs will be created. -
    + +
  • - -
    GUI > initial_orgs
    -
      -
      - + When Velociraptor starts the first time these orgs will be created.
      + +
      GUI > initial_orgs
      +
        + +
      • [0]
        -
        -
        GUI > initial_orgs > [0]
        -
          -
          + +
          GUI > initial_orgs > [0]
          +
            + +
          • @@ -2197,12 +2439,14 @@ Generated by the config wizard!!!
            GUI > initial_orgs > [0] > org_id
            O1234
          • -
            +
            + +
          • @@ -2212,14 +2456,14 @@ Generated by the config wizard!!!
            GUI > initial_orgs > [0] > name
            My Company
          • -
            - If this is empty we use the org id. The nonce is a shared - secret in the client configuration which binds clients to - this Org. See Client.nonce. +
            +
            + +
          • @@ -2229,15 +2473,32 @@ Generated by the config wizard!!!
            GUI > initial_orgs > [0] > nonce
            O1234
          • +
            + + If this is empty we use the org id. The nonce is a shared + secret in the client configuration which binds clients to + this Org. See Client.nonce. + +
            +
      • +
  • +
    +
    +
  • +
    + +
    How to authenticate users to the server. Velociraptor comes with @@ -2245,22 +2506,11 @@ Generated by the config wizard!!! authenticator to use.
    -
  • -
    - -
    GUI > authenticator
      -
      - - The type of authenticator to use. Currently: - basic, google, azure, oidc-cognito (prior to v0.75.6), github, saml, oidc, multi - -
      +
    • @@ -2270,12 +2520,15 @@ Generated by the config wizard!!!
      GUI > authenticator > type
      basic
    • -
      - Used by SAML authenticator + The type of authenticator to use. Currently: + basic, google, azure, oidc-cognito (prior to v0.75.6), github, saml, oidc, multi
      +
      + +
    • @@ -2288,12 +2541,14 @@ Generated by the config wizard!!! -----END CERTIFICATE-----
    • -
      + Used by SAML authenticator -
      +
    + +
  • @@ -2306,12 +2561,14 @@ Generated by the config wizard!!! -----END RSA PRIVATE KEY-----
  • -
    +
  • + +
  • @@ -2321,12 +2578,14 @@ Generated by the config wizard!!!
    GUI > authenticator > saml_idp_metadata_url
    http://localhost:8080/simplesaml/saml2/idp/metadata.php
  • -
    +
    + +
  • @@ -2336,12 +2595,14 @@ Generated by the config wizard!!!
    GUI > authenticator > saml_root_url
    https://localhost:8889
  • -
    +
    + +
  • @@ -2351,12 +2612,14 @@ Generated by the config wizard!!!
    GUI > authenticator > saml_user_attribute
    email
  • -
    - Allow IdP-initiated SAML flow. + +
    + +
  • @@ -2366,7 +2629,20 @@ Generated by the config wizard!!!
    GUI > authenticator > saml_allow_idp_initiated
    false
  • +
    + + Allow IdP-initiated SAML flow. + +
    +
    +
    +
  • +
    + +
    This feature allows roles to be set in the SAML claims. It is a @@ -2384,50 +2660,44 @@ Generated by the config wizard!!! with the override_acls flag.
    -
  • -
    - -
    GUI > authenticator > saml_user_roles
      -
      - - - -
      +
    • analyst
      GUI > authenticator > saml_user_roles
    • -
      +
      + +
    • investigator
      GUI > authenticator > saml_user_roles
    • +
      + + + +
      +
  • - -
    - - URL to OIDC Configuration Document. The configuration should be - available in the 'oidc_issuer + /.well-known/openid-configuration' endpoint. -
    + +
  • @@ -2437,15 +2707,15 @@ Generated by the config wizard!!!
    GUI > authenticator > oidc_issuer
  • -
    - Name of this authenticator to show in the GUI (e.g company - name). Note that you can provide many OIDC authenticators as - part of the multi authenticator so having a name here helps keep - them recognizable. + URL to OIDC Configuration Document. The configuration should be + available in the 'oidc_issuer + /.well-known/openid-configuration' endpoint.
    +
    + +
  • @@ -2455,28 +2725,34 @@ Generated by the config wizard!!!
    GUI > authenticator > oidc_name
    Company Name
  • -
    - Additional URL parameters that should be added to the OIDC - redirect URL. + Name of this authenticator to show in the GUI (e.g company + name). Note that you can provide many OIDC authenticators as + part of the multi authenticator so having a name here helps keep + them recognizable.
    +
    + +
  • - -
    GUI > authenticator > oidc_auth_url_params
    -
      -
      - + Additional URL parameters that should be added to the OIDC + redirect URL.
      +
  • +
    GUI > authenticator > oidc_auth_url_params
    +
      + +
    • @@ -2486,16 +2762,19 @@ Generated by the config wizard!!!
      GUI > authenticator > oidc_auth_url_params > Key
      Value
    • -
    -
    -
    -
  • -
    +
    + +
    + + +
    + +
  • @@ -2505,12 +2784,14 @@ Generated by the config wizard!!!
    GUI > authenticator > avatar
    http://www.example.com/icon.png
  • -
    - These are required for the oauth flow - get from the OIDC provider. +
    +
    + +
  • @@ -2520,12 +2801,14 @@ Generated by the config wizard!!!
    GUI > authenticator > oauth_client_id
    C123445
  • -
    + These are required for the oauth flow - get from the OIDC provider. -
    +
    + +
  • @@ -2535,14 +2818,14 @@ Generated by the config wizard!!!
    GUI > authenticator > oauth_client_secret
    X23456
  • -
    - When this is set we emit detailed logging. Turn this on when - configuring the server initially if you want to debug your OIDC - setup. You probably do not want this enabled in production. +
    +
    + +
  • @@ -2552,23 +2835,42 @@ Generated by the config wizard!!!
    GUI > authenticator > oidc_debug
    false
  • -
    - Additional OIDC claims configuration. This is an experimental - setting and should not be used except for specific situations. + When this is set we emit detailed logging. Turn this on when + configuring the server initially if you want to debug your OIDC + setup. You probably do not want this enabled in production.
    +
    + +
  • +
    + + Additional OIDC claims configuration. This is an experimental + setting and should not be used except for specific situations. + +
    GUI > authenticator > claims
      +
      +
    • + +
      + username +
      +
      +
      GUI > authenticator > claims > username
      +
      email
      +
    • The name of the claim that represents the username (by default @@ -2578,16 +2880,18 @@ Generated by the config wizard!!! their OIDC accounts!
      -
    • +
    • + +
      +
    • -
      GUI > authenticator > claims > username
      -
      email
      +
      GUI > authenticator > claims > roles
      +
    • -
      The field that specifies the roles. If this not set (the @@ -2600,94 +2904,87 @@ Generated by the config wizard!!! NOTE: The roles will be assigned to the user in all orgs.
      -
    • - -
      - roles -
      -
      -
      GUI > authenticator > claims > roles
      -
      -
    • - -
      - - A mapping between OIDC claim roles and Velociraptor roles. - For example: -
      + +
    • - -
      GUI > authenticator > claims > role_map
      -
        -
        - + A mapping between OIDC claim roles and Velociraptor roles. + For example:
        + +
        GUI > authenticator > claims > role_map
        +
          + +
        • - -
          GUI > authenticator > claims > role_map > Velociraptor.Reader
          -
            -
            + +
            GUI > authenticator > claims > role_map > Velociraptor.Reader
            +
              + +
            • - -
              GUI > authenticator > claims > role_map > Velociraptor.Reader > roles
              -
                -
                + +
                GUI > authenticator > claims > role_map > Velociraptor.Reader > roles
                +
                  + +
                • reader
                  GUI > authenticator > claims > role_map > Velociraptor.Reader > roles
                • +
                  + + + +
                  +
            • +
        • +
    • - -
      - - Velociraptor usually requires the email_verified claim before - we can trust the email claim and use it as the - username. However, some IDP (e.g. Azure) do not set this. If - you want to ignore this requirement, set the below to true. -
      + +
    • @@ -2697,15 +2994,17 @@ Generated by the config wizard!!!
      GUI > authenticator > claims > allow_unverified_email
      false
    • -
      - When this is set, the OIDC roles override (clear) existing - velociraptor roles. The default behavior is to ensure the - user's ACL contains at least the OIDC roles. This is needed if - you want to be able to **remove** access from the IDP. + Velociraptor usually requires the email_verified claim before + we can trust the email claim and use it as the + username. However, some IDP (e.g. Azure) do not set this. If + you want to ignore this requirement, set the below to true.
      +
      + +
    • @@ -2715,16 +3014,22 @@ Generated by the config wizard!!!
      GUI > authenticator > claims > override_acls
      false
    • +
      + + When this is set, the OIDC roles override (clear) existing + velociraptor roles. The default behavior is to ensure the + user's ACL contains at least the OIDC roles. This is needed if + you want to be able to **remove** access from the IDP. + +
      +
  • - -
    - - This is specifically required by the Azure authenticator only. -
    + +
  • @@ -2734,13 +3039,14 @@ Generated by the config wizard!!!
    GUI > authenticator > tenant
    O...
  • -
    - URL to redirect to on Unauthorized API call. If blank we just - cycle to the logon screen again. + This is specifically required by the Azure authenticator only.
    +
    + +
  • @@ -2750,47 +3056,54 @@ Generated by the config wizard!!!
    GUI > authenticator > auth_redirect_template
    http://www.google.com
  • -
    - Certs authenticator: If a user presents a certificate but does - not exist in the system, the user will automatically receive a - default role. If this is not set the user will be rejected and - you will have to manually add the user to a role before they are - allowed. + URL to redirect to on Unauthorized API call. If blank we just + cycle to the logon screen again.
    +
    + +
  • - -
    GUI > authenticator > default_roles_for_unknown_user
    -
      -
      - + Certs authenticator: If a user presents a certificate but does + not exist in the system, the user will automatically receive a + default role. If this is not set the user will be rejected and + you will have to manually add the user to a role before they are + allowed.
      + +
      GUI > authenticator > default_roles_for_unknown_user
      +
        + +
      • administrator
        GUI > authenticator > default_roles_for_unknown_user
      • +
        + + + +
        +
  • - -
    - - How long to keep the session alive between auth flows - default 24 hours -
    + +
  • @@ -2800,44 +3113,48 @@ Generated by the config wizard!!!
    GUI > authenticator > default_session_expiry_min
    1440
  • -
    - Used by the multi authenticator to provide multiple - authenticators. NOTE: Sub authenticators must be oauth based - (i.e. not basic auth). + How long to keep the session alive between auth flows - default 24 hours
    +
    + +
  • - -
    GUI > authenticator > sub_authenticators
    -
      -
      - + Used by the multi authenticator to provide multiple + authenticators. NOTE: Sub authenticators must be oauth based + (i.e. not basic auth).
      -
    • -
      - + +
      GUI > authenticator > sub_authenticators
      +
        + +
        +
      • +
        +
        [0]
        -
        -
        GUI > authenticator > sub_authenticators > [0]
        -
          -
          + +
          GUI > authenticator > sub_authenticators > [0]
          +
            + +
          • @@ -2847,23 +3164,40 @@ Generated by the config wizard!!!
            GUI > authenticator > sub_authenticators > [0] > type
            Google
          • +
            + + + +
            +
      • +
    • +
  • +
    +
    +
    +
  • +
    + +
    + CA +
    This is the internal Velociraptor CA configuration. It is needed to @@ -2871,22 +3205,11 @@ Generated by the config wizard!!! config and safely store it offline.
    -
  • -
    - -
    - CA -
    CA
      -
      - - CA private key - the public certificate is in - Client.ca_certificate - -
      +
    • @@ -2899,32 +3222,37 @@ Generated by the config wizard!!! -----END RSA PRIVATE KEY-----
    • +
      + + CA private key - the public certificate is in + Client.ca_certificate + +
      +
  • - -
    - - Configuration of the frontend. The Frontend is the service that - directly talks with clients. -
    + +
  • - -
    Frontend
    -
      -
      - Serve the Frontend from this base path instead of "/" + Configuration of the frontend. The Frontend is the service that + directly talks with clients.
      + +
      Frontend
      +
        + +
      • @@ -2934,7 +3262,23 @@ Generated by the config wizard!!!
        Frontend > base_path
        /
      • +
        + + Serve the Frontend from this base path instead of "/" + +
        +
        +
        +
      • + + + +
        Frontend > use_plain_http
        +
        false
        +
      • This allows the frontends to listen on plain HTTP - It is useful @@ -2943,16 +3287,18 @@ Generated by the config wizard!!! know what you are doing here!
        -
      • +
      • + +
        +
      • -
        Frontend > use_plain_http
        +
        Frontend > require_client_certificates
        false
      • -
        Enabling this requires the clients to present a valid certificate @@ -2970,16 +3316,18 @@ Generated by the config wizard!!! curl -kv https://localhost:8000/server.pem --cert client.pem --key key.pem
        -
      • +
      • + +
        +
      • -
        Frontend > require_client_certificates
        -
        false
        +
        Frontend > proxy
        +
        http://127.0.0.1:3128
      • -
        A proxy setting to use - Velociraptor needs to connect to download @@ -2996,37 +3344,26 @@ Generated by the config wizard!!! proxy or configure proxy_url_regexp to limit outbound destinations
        -
      • - -
        - proxy -
        -
        -
        Frontend > proxy
        -
        http://127.0.0.1:3128
        -
      • - -
        - - These proxy settings are exactly the same as the - Cllient.proxy_config settings but apply to the server. -
        + +
      • - -
        Frontend > proxy_config
        -
          -
          - + These proxy settings are exactly the same as the + Cllient.proxy_config settings but apply to the server.
          + +
          Frontend > proxy_config
          +
            + +
          • @@ -3036,12 +3373,14 @@ Generated by the config wizard!!!
            Frontend > proxy_config > http
            <not set>
          • -
            +
            + +
          • @@ -3051,27 +3390,30 @@ Generated by the config wizard!!!
            Frontend > proxy_config > https
            <not set>
          • -
            +
            + +
          • - -
            Frontend > proxy_config > proxy_url_regexp
            -
              -
              + +
              Frontend > proxy_config > proxy_url_regexp
              +
                + +
              • @@ -3081,16 +3423,19 @@ Generated by the config wizard!!!
                Frontend > proxy_config > proxy_url_regexp > ^https://localhost/
              • -
              -
              -
            -
          • -
            +
            +
          +
          +
        +
      • +
        + +
      • @@ -3100,12 +3445,14 @@ Generated by the config wizard!!!
        Frontend > proxy_config > pac
        <not set>
      • -
        +
        + +
      • @@ -3115,18 +3462,19 @@ Generated by the config wizard!!!
        Frontend > proxy_config > ignore_environment
        false
      • +
        + + + +
        +
  • - -
    - - Velociraptor can attempt to obfuscate artifact names when - compiling them into raw VQL. If this is set to false this - obfuscation is removed. -
    + +
  • @@ -3136,12 +3484,16 @@ Generated by the config wizard!!!
    Frontend > do_not_compress_artifacts
    true
  • -
    - The publicly accessible hostname of the frontend. + Velociraptor can attempt to obfuscate artifact names when + compiling them into raw VQL. If this is set to false this + obfuscation is removed.
    +
    + +
  • @@ -3151,13 +3503,14 @@ Generated by the config wizard!!!
    Frontend > hostname
    192.168.1.11
  • -
    - Which interface to bind to. Usually the frontend is bound to - 0.0.0.0 to allow all clients to connect from anywhere. + The publicly accessible hostname of the frontend.
    +
    + +
  • @@ -3167,12 +3520,15 @@ Generated by the config wizard!!!
    Frontend > bind_address
    0.0.0.0
  • -
    - + Which interface to bind to. Usually the frontend is bound to + 0.0.0.0 to allow all clients to connect from anywhere.
    +
    + +
  • @@ -3182,17 +3538,14 @@ Generated by the config wizard!!!
    Frontend > bind_port
    8000
  • -
    - These are used to secure the client/server communications - Even - when using external TLS certificates! This certificate must be - signed by the Velociraptor root CA in all cases - (tls_certificate_filename for that). If using an external TLS - configuration this layer of encryption happens **in addition** to - the external TLS certificates. +
    +
    + +
  • @@ -3205,12 +3558,19 @@ Generated by the config wizard!!! -----END CERTIFICATE-----
  • -
    - + These are used to secure the client/server communications - Even + when using external TLS certificates! This certificate must be + signed by the Velociraptor root CA in all cases + (tls_certificate_filename for that). If using an external TLS + configuration this layer of encryption happens **in addition** to + the external TLS certificates.
    +
    + +
  • @@ -3223,19 +3583,14 @@ Generated by the config wizard!!! -----END RSA PRIVATE KEY-----
  • -
    - If you want to use your own certificates for TLS as an alternative - to Autocert, then you can set those here. These certificates will - be used for TLS on both the frontend and GUI. NOTE: We expect - these to be proper certificates - i.e. NOT self signed. If you - want to use certificates issued by another CA you will also need - to add that CA cert to the Client.Crypto.root_certs field. - Be sure to set Client.use_self_signed_ssl=false when you set this.
    + + +
  • @@ -3245,12 +3600,21 @@ Generated by the config wizard!!!
    Frontend > tls_certificate_filename
    /etc/cert.pem
  • -
    + If you want to use your own certificates for TLS as an alternative + to Autocert, then you can set those here. These certificates will + be used for TLS on both the frontend and GUI. NOTE: We expect + these to be proper certificates - i.e. NOT self signed. If you + want to use certificates issued by another CA you will also need + to add that CA cert to the Client.Crypto.root_certs field. + Be sure to set Client.use_self_signed_ssl=false when you set this.
    +
    + +
  • @@ -3260,29 +3624,32 @@ Generated by the config wizard!!!
    Frontend > tls_private_key_filename
    /etc/cert.key
  • -
    - If configured, Velociraptor will attempt to update the dynamic - DNS server with its public IP address. Currently we only support - a number of providers including noip and cloudflare. + +
    + +
  • - -
    Frontend > dyn_dns
    -
      -
      - The type of DynDNS provider (Can be cloudfront or noip) + If configured, Velociraptor will attempt to update the dynamic + DNS server with its public IP address. Currently we only support + a number of providers including noip and cloudflare.
      + +
      Frontend > dyn_dns
      +
        + +
      • @@ -3292,12 +3659,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > type
        noip
      • -
        - The hostname to update + The type of DynDNS provider (Can be cloudfront or noip)
        +
        + +
      • @@ -3307,12 +3676,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > hostname
        www.velo.com
      • -
        - + The hostname to update
        +
        + +
      • @@ -3322,12 +3693,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > ddns_username
        1234233452
      • -
        +
        + +
      • @@ -3337,12 +3710,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > ddns_password
        2313e2324
      • -
        - The hostname to update - if empty we use Frontend.hostname +
        +
        + +
      • @@ -3352,12 +3727,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > ddns_hostname
        <not set>
      • -
        - If empty we use Google Domains. + The hostname to update - if empty we use Frontend.hostname
        +
        + +
      • @@ -3367,12 +3744,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > update_url
        http://dyndns.provider.com/
      • -
        - How often to check for IP assigned + If empty we use Google Domains.
        +
        + +
      • @@ -3382,13 +3761,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > frequency
        60
      • -
        - The url we will use to check the ip. Should return a plain IP - address (default is Google Domains) + How often to check for IP assigned
        +
        + +
      • @@ -3398,13 +3778,15 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > checkip_url
        http://dyndns.provider.com/checkip
      • -
        - DNS server we query for our own hostname/ip mapping (default - 8.8.8.8:53) + The url we will use to check the ip. Should return a plain IP + address (default is Google Domains)
        +
        + +
      • @@ -3414,12 +3796,15 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > dns_server
        8.8.8.8:53
      • -
        - Used by the cloudfront provider + DNS server we query for our own hostname/ip mapping (default + 8.8.8.8:53)
        +
        + +
      • @@ -3429,12 +3814,14 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > api_token
        <not set>
      • -
        - The zone to update (dns domain). + Used by the cloudfront provider
        +
        + +
      • @@ -3444,19 +3831,19 @@ Generated by the config wizard!!!
        Frontend > dyn_dns > zone_name
        <not set>
      • +
        + + The zone to update (dns domain). + +
        +
  • - -
    - - Header defined by the proxy containing the remote address. If this - is not set we use the remote IP address from the TCP - connection. This setting is needed if you have a reverse proxy in - front of the server. -
    + +
  • @@ -3466,82 +3853,89 @@ Generated by the config wizard!!!
    Frontend > proxy_header
    X-Forwarded-For
  • -
    - We have the Server.Monitor.Health enabled always but these are - any additional artifacts that should be installed by default. + Header defined by the proxy containing the remote address. If this + is not set we use the remote IP address from the TCP + connection. This setting is needed if you have a reverse proxy in + front of the server.
    +
    + +
  • - -
    Frontend > default_server_monitoring_artifacts
    -
      -
      - + We have the Server.Monitor.Health enabled always but these are + any additional artifacts that should be installed by default.
      + +
      Frontend > default_server_monitoring_artifacts
      +
        + +
      • Server.Monitor.Health
        Frontend > default_server_monitoring_artifacts
      • +
        + + + +
        +
  • - -
    - - When creating the initial client monitoring artifact table, these - artifacts will be assigned to all clients. -
    + +
  • - -
    Frontend > default_client_monitoring_artifacts
    -
      -
      - + When creating the initial client monitoring artifact table, these + artifacts will be assigned to all clients.
      + +
      Frontend > default_client_monitoring_artifacts
      +
        + +
      • Generic.Client.Stats
        Frontend > default_client_monitoring_artifacts
      • +
        + + + +
        +
  • - -
    - - The user that the frontend should run as. If set we refuse to run - as a different user. This is normally set by the Ubuntu deb - package as it is running as a low privilege user called - "velociraptor". This setting is important as it stops users from - running velociraptor as root with sudo - doing this will break the - velociraptor datastore when it creates files only readable by - root. -
    + +
  • @@ -3551,46 +3945,57 @@ Generated by the config wizard!!!
    Frontend > run_as_user
    velociraptor
  • -
    - When the server is created initially, these server artifacts will - be collected. You can use this to fire custom initialization - sequences. + The user that the frontend should run as. If set we refuse to run + as a different user. This is normally set by the Ubuntu deb + package as it is running as a low privilege user called + "velociraptor". This setting is important as it stops users from + running velociraptor as root with sudo - doing this will break the + velociraptor datastore when it creates files only readable by + root.
    +
    + +
  • - -
    Frontend > initial_server_artifacts
    -
      -
      - + When the server is created initially, these server artifacts will + be collected. You can use this to fire custom initialization + sequences.
      + +
      Frontend > initial_server_artifacts
      +
        + +
      • MySpecialArtifact
        Frontend > initial_server_artifacts
      • +
        + + + +
        +
  • - -
    - - Number of gRPC connections in the pool to use to connect to the - API server. -
    + +
  • @@ -3600,12 +4005,15 @@ Generated by the config wizard!!!
    Frontend > GRPC_pool_max_size
    100
  • -
    - + Number of gRPC connections in the pool to use to connect to the + API server.
    +
    + +
  • @@ -3615,12 +4023,14 @@ Generated by the config wizard!!!
    Frontend > GRPC_pool_max_wait
    60
  • -
    - Load artifacts from this directory at startup +
    +
    + +
  • @@ -3630,16 +4040,14 @@ Generated by the config wizard!!!
    Frontend > artifact_definitions_directory
    /tmp/
  • -
    - A regular expression that if matches any log messages from the - client's query represent a failure of the collection. Marking the - collection as failed can highlight potential problems with the VQL - so this regex tries to detect common issues (e.g. Symbol not - found) to draw attention to failures. + Load artifacts from this directory at startup
    +
    + +
  • @@ -3649,29 +4057,36 @@ Generated by the config wizard!!!
    Frontend > collection_error_regex
    ERROR:
  • -
    - Sets resource limitations on the server. These parameters - represent the set of tunable parameters you can use to optimize - performance on loaded servers. + A regular expression that if matches any log messages from the + client's query represent a failure of the collection. Marking the + collection as failed can highlight potential problems with the VQL + so this regex tries to detect common issues (e.g. Symbol not + found) to draw attention to failures.
    +
    + +
  • - -
    Frontend > resources
    -
      -
      - Load shed connections faster than this to preserve stability. + Sets resource limitations on the server. These parameters + represent the set of tunable parameters you can use to optimize + performance on loaded servers.
      + +
      Frontend > resources
      +
        + +
      • @@ -3681,14 +4096,14 @@ Generated by the config wizard!!!
        Frontend > resources > connections_per_second
        300
      • -
        - The rate at which we notify clients of new work (e.g. a new hunt - is started). Slower notification rate helps to slow down the - swarm effect and reduced load on the server. + Load shed connections faster than this to preserve stability.
        +
        + +
      • @@ -3698,13 +4113,16 @@ Generated by the config wizard!!!
        Frontend > resources > notifications_per_second
        1000
      • -
        - How quickly do we enroll clients (default 100/s, -1 to disable - enrollments) + The rate at which we notify clients of new work (e.g. a new hunt + is started). Slower notification rate helps to slow down the + swarm effect and reduced load on the server.
        +
        + +
      • @@ -3714,18 +4132,15 @@ Generated by the config wizard!!!
        Frontend > resources > enrollments_per_second
        100
      • -
        - The maximum number of concurrent client connections we can - process. Concurrency limits helps to ensure the server is not - overloaded serving too many clients at the same time. - Concurrency refers to the actual serving time of a client - (i.e. time taken to read the response and write to the - datastore), not the total number of clients served by - server. Default is number of cores * 2. + How quickly do we enroll clients (default 100/s, -1 to disable + enrollments)
        +
        + +
      • @@ -3735,14 +4150,20 @@ Generated by the config wizard!!!
        Frontend > resources > concurrency
        20
      • -
        - The maximum time a client will be waiting for a concurrency slot - before timing out. A small value will result in many - reconnections under load and may degrade performance. + The maximum number of concurrent client connections we can + process. Concurrency limits helps to ensure the server is not + overloaded serving too many clients at the same time. + Concurrency refers to the actual serving time of a client + (i.e. time taken to read the response and write to the + datastore), not the total number of clients served by + server. Default is number of cores * 2.
        +
        + +
      • @@ -3752,14 +4173,16 @@ Generated by the config wizard!!!
        Frontend > resources > concurrency_timeout
        600
      • -
        - Increasing this allows the frontend to receive larger POST - messages lowering crypto overheads but this comes at the - expense of more memory use. + The maximum time a client will be waiting for a concurrency slot + before timing out. A small value will result in many + reconnections under load and may degrade performance.
        +
        + +
      • @@ -3769,15 +4192,16 @@ Generated by the config wizard!!!
        Frontend > resources > max_upload_size
        10485760
      • -
        - This setting controls the size of various LRU caches in the - frontend (e.g. the session key cache, client info cache). This - number should be larger than the number of actual clients or - else the system will see high CPU load from cache misses. + Increasing this allows the frontend to receive larger POST + messages lowering crypto overheads but this comes at the + expense of more memory use.
        +
        + +
      • @@ -3787,16 +4211,17 @@ Generated by the config wizard!!!
        Frontend > resources > expected_clients
        10000
      • -
        - Bandwidth control: Per client and global rates in - bytes/sec. This is useful for low bandwidth deployments where we - want to ensure Velociraptor does not saturate slow links. The - bandwidth limitation caps the total bandwidth used by the server - per client and globally. + This setting controls the size of various LRU caches in the + frontend (e.g. the session key cache, client info cache). This + number should be larger than the number of actual clients or + else the system will see high CPU load from cache misses.
        +
        + +
      • @@ -3806,12 +4231,18 @@ Generated by the config wizard!!!
        Frontend > resources > per_client_upload_rate
        0
      • -
        + Bandwidth control: Per client and global rates in + bytes/sec. This is useful for low bandwidth deployments where we + want to ensure Velociraptor does not saturate slow links. The + bandwidth limitation caps the total bandwidth used by the server + per client and globally. -
        +
        + +
      • @@ -3821,14 +4252,14 @@ Generated by the config wizard!!!
        Frontend > resources > global_upload_rate
        0
      • -
        - Wait time for collecting events from clients - smaller means - less latency to respond to client events but also means more - TLS handshake and network overheads due to frequent POST. + +
        + +
      • @@ -3838,14 +4269,16 @@ Generated by the config wizard!!!
        Frontend > resources > client_event_max_wait
        100
      • -
        - Minions batch updates to the master so as to minimize RPC as - much as possible, this controls how often these batches are - flushed to the master (default 10 sec). + Wait time for collecting events from clients - smaller means + less latency to respond to client events but also means more + TLS handshake and network overheads due to frequent POST.
        +
        + +
      • @@ -3855,15 +4288,16 @@ Generated by the config wizard!!!
        Frontend > resources > minion_batch_wait_time_ms
        10
      • -
        - Number of seconds before expiring client info cache - entries. Default (0) means do not expire at all. Expiring - client info from cache too frequently can result in a lot more - IO. Default size of this cache is the expected_clients above. + Minions batch updates to the master so as to minimize RPC as + much as possible, this controls how often these batches are + flushed to the master (default 10 sec).
        +
        + +
      • @@ -3873,13 +4307,17 @@ Generated by the config wizard!!!
        Frontend > resources > client_info_lru_ttl
        0
      • -
        - How often to sync client info records (ms) between minion and - master. + Number of seconds before expiring client info cache + entries. Default (0) means do not expire at all. Expiring + client info from cache too frequently can result in a lot more + IO. Default size of this cache is the expected_clients above.
        +
        + +
      • @@ -3889,12 +4327,15 @@ Generated by the config wizard!!!
        Frontend > resources > client_info_sync_time
        0
      • -
        + How often to sync client info records (ms) between minion and + master. -
        +
        + +
      • @@ -3903,17 +4344,15 @@ Generated by the config wizard!!!
        Frontend > resources > client_info_write_time
        0
        -
      • - -
        - - The journal files are used to queue messages between event - generators and event consumers when the consumer is unable to - drain these quickly enough. The setting specifies the maximum - size of the file - when it is exceeded, the file will be - truncated and events will be lost. Default is 1gb + +
        + +
        +
        + +
      • @@ -3923,13 +4362,18 @@ Generated by the config wizard!!!
        Frontend > resources > max_journal_buffer_size
        1000000000
      • -
        - How often to save an index snapshot to storage (default 600 - sec). Index files are typically 150kb / 1000 clients. + The journal files are used to queue messages between event + generators and event consumers when the consumer is unable to + drain these quickly enough. The setting specifies the maximum + size of the file - when it is exceeded, the file will be + truncated and events will be lost. Default is 1gb
        +
        + +
      • @@ -3939,15 +4383,31 @@ Generated by the config wizard!!!
        Frontend > resources > index_snapshot_frequency
        10
      • +
        + + How often to save an index snapshot to storage (default 600 + sec). Index files are typically 150kb / 1000 clients. + +
        +
  • +
    +
    +
    +
  • +
    + +
    + Datastore +
    Velociraptor has a datastore abstraction and can use a number of @@ -3955,22 +4415,11 @@ Generated by the config wizard!!! store implementation.
    -
  • -
    - -
    - Datastore -
    Datastore
      -
      - - The data store implementation to use. This is usually set to - FileBaseDataStore. - -
      +
    • @@ -3980,12 +4429,15 @@ Generated by the config wizard!!!
      Datastore > implementation
      FileBaseDataStore
    • -
      - The directory under which we store small files. + The data store implementation to use. This is usually set to + FileBaseDataStore.
      +
      + +
    • @@ -3995,15 +4447,14 @@ Generated by the config wizard!!!
      Datastore > location
      /mnt/data
    • -
      - Larger result sets and uploads are stored in the - filestore_directory. This is usually the same as the location - setting but it can be different to keep larger slower storage - options away from smaller and faster data. + The directory under which we store small files.
      +
      + +
    • @@ -4013,12 +4464,17 @@ Generated by the config wizard!!!
      Datastore > filestore_directory
      /mnt/data
    • -
      - How long before a write is forced from the pool for delayed writes + Larger result sets and uploads are stored in the + filestore_directory. This is usually the same as the location + setting but it can be different to keep larger slower storage + options away from smaller and faster data.
      +
      + +
    • @@ -4028,13 +4484,14 @@ Generated by the config wizard!!!
      Datastore > memcache_write_mutation_max_age
      1
    • -
      - Maximum amount of data cached in memory before we force it to be - flushed to disk. Default 100mb + How long before a write is forced from the pool for delayed writes
      +
      + +
    • @@ -4044,15 +4501,15 @@ Generated by the config wizard!!!
      Datastore > memcache_write_max_memory
      100000000
    • -
      - When using a master/minion setup it is necessary to have the - Master and Minion nodes use different filesystem - implementations. These more specific parameters can control - datastore implementations on the master and minion separately. + Maximum amount of data cached in memory before we force it to be + flushed to disk. Default 100mb
      +
      + +
    • @@ -4062,12 +4519,17 @@ Generated by the config wizard!!!
      Datastore > minion_implementation
      RemoteFileDataStore
    • -
      - + When using a master/minion setup it is necessary to have the + Master and Minion nodes use different filesystem + implementations. These more specific parameters can control + datastore implementations on the master and minion separately.
      +
      + +
    • @@ -4077,14 +4539,14 @@ Generated by the config wizard!!!
      Datastore > master_implementation
      MemcacheFileDataStore
    • -
      - Cap directories to this size after reporting error - this should - not happen normally but may happen if the deployment has been very - active or due to a bug! + +
      + +
    • @@ -4094,15 +4556,16 @@ Generated by the config wizard!!!
      Datastore > max_dir_size
      50000
    • -
      - Set to the min required disk space. When we fall below this - available disk space, we refuse to write files. This avoids the - possibility of writing corrupted files. Default is 50mb. Set to -1 - to disable disk space monitoring. + Cap directories to this size after reporting error - this should + not happen normally but may happen if the deployment has been very + active or due to a bug!
      +
      + +
    • @@ -4112,12 +4575,17 @@ Generated by the config wizard!!!
      Datastore > min_allowed_file_space_mb
      50
    • -
      - How often to check the disk space (default 10 sec) + Set to the min required disk space. When we fall below this + available disk space, we refuse to write files. This avoids the + possibility of writing corrupted files. Default is 50mb. Set to -1 + to disable disk space monitoring.
      +
      + +
    • @@ -4127,13 +4595,14 @@ Generated by the config wizard!!!
      Datastore > disk_check_frequency_sec
      10
    • -
      - The following apply to the MemcacheFileDataStore - How long to expire the memcache (default 10 min) + How often to check the disk space (default 10 sec)
      +
      + +
    • @@ -4143,15 +4612,15 @@ Generated by the config wizard!!!
      Datastore > memcache_expiration_sec
      6000
    • -
      - How many mutations to queue up ahead of busy writers. By - default 0 means writes will be blocked until they are handed - off to a writer thread. Set to -1 to disable asynchronous - writes. + The following apply to the MemcacheFileDataStore + How long to expire the memcache (default 10 min)
      +
      + +
    • @@ -4161,15 +4630,17 @@ Generated by the config wizard!!!
      Datastore > memcache_write_mutation_buffer
      100
    • -
      - The MemcacheFileDataStore separates writers into a writing - pool. These set the number of writer threads in that pool. - Number of writing threads - increase for high latency - filesystems (default 100). + How many mutations to queue up ahead of busy writers. By + default 0 means writes will be blocked until they are handed + off to a writer thread. Set to -1 to disable asynchronous + writes.
      +
      + +
    • @@ -4179,19 +4650,17 @@ Generated by the config wizard!!!
      Datastore > memcache_write_mutation_writers
      100
    • -
      - How long to delay writes so they can be combined. This applies for - writing result sets - we keep the writes in memory for min_age - seconds in order to combine further writes. If another write - occurs to the same result sets the TTL is extended and writes are - delayed. However, once we reach max_age, a write is forced. The aim - is to keep combining separate writes as much as possible into larger - writes but at the same time prevent frequently written files from - never flushing to disk. + The MemcacheFileDataStore separates writers into a writing + pool. These set the number of writer threads in that pool. + Number of writing threads - increase for high latency + filesystems (default 100).
      +
      + +
    • @@ -4201,12 +4670,21 @@ Generated by the config wizard!!!
      Datastore > memcache_write_mutation_min_age
      1000
    • -
      - + How long to delay writes so they can be combined. This applies for + writing result sets - we keep the writes in memory for min_age + seconds in order to combine further writes. If another write + occurs to the same result sets the TTL is extended and writes are + delayed. However, once we reach max_age, a write is forced. The aim + is to keep combining separate writes as much as possible into larger + writes but at the same time prevent frequently written files from + never flushing to disk.
      +
      + +
    • @@ -4216,14 +4694,14 @@ Generated by the config wizard!!!
      Datastore > int64 memcache_write_mutation_max_age
      5000
    • -
      - MemcacheFileDataStore will cache small files in memory to improve - efficiency. This is the maximum size of the cache. - Maximum size of memcache lru (default 10000) + +
      + +
    • @@ -4233,13 +4711,16 @@ Generated by the config wizard!!!
      Datastore > memcache_datastore_max_size
      10000
    • -
      - Do not cache large objects in memory - falls back to - FileBaseDataStore + MemcacheFileDataStore will cache small files in memory to improve + efficiency. This is the maximum size of the cache. + Maximum size of memcache lru (default 10000)
      +
      + +
    • @@ -4249,12 +4730,15 @@ Generated by the config wizard!!!
      Datastore > memcache_datastore_max_item_size
      1000
    • -
      + Do not cache large objects in memory - falls back to + FileBaseDataStore -
      +
      + +
    • @@ -4264,7 +4748,23 @@ Generated by the config wizard!!!
      Datastore > memcache_datastore_max_dir_size
      50000
    • +
      + + + +
      +
      +
      +
    • + + + +
      Datastore > compression
      +
      zlib
      +
    • The compression mode for collections. This setting allows @@ -4283,16 +4783,18 @@ Generated by the config wizard!!! default setting when communicating with newer clients.
      -
    • +
    • + +
      +
    • -
      Datastore > compression
      -
      zlib
      +
      Datastore > max_object_size
      +
      4194304
    • -
      The maximum size of stored objects in the datastore. The Datastore @@ -4304,40 +4806,30 @@ Generated by the config wizard!!! default size is 4Mb.
      -
    • - - - -
      Datastore > max_object_size
      -
      4194304
      -
    • +
  • - -
    - - Configure logging behavior -
    + +
  • - -
    Logging
    -
      -
      - A directory to write log files in . + Configure logging behavior
      +
  • +
    Logging
    +
      + +
    • @@ -4347,14 +4839,14 @@ Generated by the config wizard!!!
      Logging > output_directory
      /mnt/data/logs
    • -
      - If this is set the logs will be separated into different - components (e.g. Frontend, GUI, Audit etc). This makes it easier - to find the source of the log messages + A directory to write log files in .
      +
      + +
    • @@ -4364,13 +4856,16 @@ Generated by the config wizard!!!
      Logging > separate_logs_per_component
      true
    • -
      - If you want to forward events to a remote syslog server, fill this - server addresss or hostname. If a port is omitted we use port 514. + If this is set the logs will be separated into different + components (e.g. Frontend, GUI, Audit etc). This makes it easier + to find the source of the log messages
      +
      + +
    • @@ -4380,12 +4875,15 @@ Generated by the config wizard!!!
      Logging > remote_syslog_server
      localhost:514
    • -
      - The protocol to use for remote syslog (default udp). + If you want to forward events to a remote syslog server, fill this + server addresss or hostname. If a port is omitted we use port 514.
      +
      + +
    • @@ -4395,60 +4893,67 @@ Generated by the config wizard!!!
      Logging > remote_syslog_protocol
      udp
    • -
      - The logging components to forward. If not specified we only send - Audit events. + The protocol to use for remote syslog (default udp).
      +
      + +
    • - -
      Logging > remote_syslog_components
      -
        -
        - + The logging components to forward. If not specified we only send + Audit events.
        + +
        Logging > remote_syslog_components
        +
          + +
        • VelociraptorAudit
          Logging > remote_syslog_components
        • +
          + + + +
          +
    • - -
      - - Specific configuration for each log level. If a log level is not - configured here it is logged as normal. -
      + +
    • - -
      Logging > debug
      -
        -
        - How often to rotate the files in seconds. + Specific configuration for each log level. If a log level is not + configured here it is logged as normal.
        + +
        Logging > debug
        +
          + +
        • @@ -4458,12 +4963,14 @@ Generated by the config wizard!!!
          Logging > debug > rotation_time
          8000
        • -
          - Maximum age of each file (File will be deleted after this time (1 year). + How often to rotate the files in seconds.
          +
          + +
        • @@ -4473,12 +4980,14 @@ Generated by the config wizard!!!
          Logging > debug > max_age
          31536000
        • -
          - If this is true this log source is disabled. + Maximum age of each file (File will be deleted after this time (1 year).
          +
          + +
        • @@ -4488,31 +4997,35 @@ Generated by the config wizard!!!
          Logging > debug > disabled
          true
        • +
          + + If this is true this log source is disabled. + +
          +
    • - -
      - - -
      + +
    • - -
      Logging > info
      -
        -
        + +
        Logging > info
        +
          + +
        • @@ -4522,12 +5035,14 @@ Generated by the config wizard!!!
          Logging > info > rotation_time
          8000
        • -
          +
          + +
        • @@ -4537,12 +5052,14 @@ Generated by the config wizard!!!
          Logging > info > max_age
          31536000
        • -
          +
          + +
        • @@ -4552,31 +5069,35 @@ Generated by the config wizard!!!
          Logging > info > disabled
          true
        • -
        -
        -
      -
    • -
      +
      +
    +
    +
    +
  • +
    + +
  • - -
    Logging > error
    -
      -
      + +
      Logging > error
      +
        + +
      • @@ -4586,12 +5107,14 @@ Generated by the config wizard!!!
        Logging > error > rotation_time
        8000
      • -
        +
        + +
      • @@ -4601,12 +5124,14 @@ Generated by the config wizard!!!
        Logging > error > max_age
        31536000
      • -
        +
        + +
      • @@ -4616,15 +5141,30 @@ Generated by the config wizard!!!
        Logging > error > disabled
        true
      • +
        + + + +
        +
  • +
    +
    +
    +
  • +
    + +
    This controls the Monitoring server (i.e. Prometheus) If you have a @@ -4632,21 +5172,11 @@ Generated by the config wizard!!! to bind to 0.0.0.0 and point your scraper at it.
    -
  • -
    - -
    Monitoring
      -
      - - - -
      +
    • @@ -4656,12 +5186,14 @@ Generated by the config wizard!!!
      Monitoring > bind_address
      127.0.0.1
    • -
      +
      + +
    • @@ -4671,13 +5203,14 @@ Generated by the config wizard!!!
      Monitoring > bind_port
      8003
    • -
      - If set we use this in links etc, otherwise we take a guess - based on bind_address and bind_port above. + +
      + +
    • @@ -4687,26 +5220,42 @@ Generated by the config wizard!!!
      Monitoring > metrics_url
      http://localhost:8003/metrics
    • +
      + + If set we use this in links etc, otherwise we take a guess + based on bind_address and bind_port above. + +
      +
  • - -
    - - Run these automatically when the binary starts. -
    + +
  • +
    + + Run these automatically when the binary starts. + +
    autoexec
      +
      +
    • +
      + +
      + argv +
      When starting without any command line parameters, this argv array @@ -4715,56 +5264,64 @@ Generated by the config wizard!!! startup when used without parameters.
      -
    • -
      - -
      - argv -
      autoexec > argv
        -
        - - - -
        +
      • artifacts
        autoexec > argv
      • -
        +
        + +
      • collect
        autoexec > argv
      • -
        +
        + +
      • Generic.Client.Info
        autoexec > argv
      • +
        + + + +
        +
    • +
    • +
      +
    • +
      + +
      Load these artifact definitions into the binary at startup. NOTE: @@ -4776,37 +5333,27 @@ Generated by the config wizard!!! generally.
      -
    • -
      - -
      autoexec > artifact_definitions
        -
        - - - -
        +
      • [0]
        -
        -
        autoexec > artifact_definitions > [0]
        -
          -
          - The name of the artifact. Artifacts are referred to by name - within the system. +
          +
    • +
      autoexec > artifact_definitions > [0]
      +
        + +
      • @@ -4816,13 +5363,15 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > name
        Generic.Client.InfoXXX
      • -
        - A Human readable description of the artifact. This should have a - single summary paragraph + The name of the artifact. Artifacts are referred to by name + within the system.
        +
        + +
      • @@ -4832,12 +5381,15 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > description
        Artifact Description
      • -
        - The artifact author + A Human readable description of the artifact. This should have a + single summary paragraph
        +
        + +
      • @@ -4847,12 +5399,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > author
        Author
      • -
        - Type of the artifact: CLIENT, SERVER, CLIENT_EVENT, SERVER_EVENT + The artifact author
        +
        + +
      • @@ -4862,38 +5416,55 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > type
        CLIENT
      • -
        - A list of references + Type of the artifact: CLIENT, SERVER, CLIENT_EVENT, SERVER_EVENT
        +
        + +
      • - -
        autoexec > artifact_definitions > [0] > reference
        -
          -
          - + A list of references
          +
  • +
    autoexec > artifact_definitions > [0] > reference
    +
      + +
    • https://www.google.com
      autoexec > artifact_definitions > [0] > reference
    • +
      + + + +
      +
  • +
    +
    +
  • +
    + +
    + tools +
    Artifacts can specify third party tools to load. Velociraptor @@ -4902,36 +5473,27 @@ Generated by the config wizard!!! so the artifact may use it.
    -
  • -
    - -
    - tools -
    autoexec > artifact_definitions > [0] > tools
      -
      - - - -
      +
    • [0]
      -
      -
      autoexec > artifact_definitions > [0] > tools > [0]
      -
        -
        - The name of the tool +
        +
  • +
    autoexec > artifact_definitions > [0] > tools > [0]
    +
      + +
    • @@ -4941,13 +5503,14 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > name
      MyTool
    • -
      - The URL to fetch the tool from when we upload it the first - time, or when we update. + The name of the tool
      +
      + +
    • @@ -4957,14 +5520,15 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > url
      http://www.google.com
    • -
      - As an alternative to a url we allow scrapping of GitHub - releases using the github API. NOTE: When this method is - specified, the file will always be served locally. + The URL to fetch the tool from when we upload it the first + time, or when we update.
      +
      + +
    • @@ -4974,12 +5538,16 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > github_project
      GitHubProject
    • -
      + As an alternative to a url we allow scrapping of GitHub + releases using the github API. NOTE: When this method is + specified, the file will always be served locally. -
      +
      + +
    • @@ -4989,14 +5557,14 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > github_asset_regex
      GitHubAsset
    • -
      - If set, the tool will be served locally from the filestore - path - otherwise the endpoint will download the file by - itself from the url above. +
      +
      + +
    • @@ -5006,14 +5574,16 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > serve_locally
      true
    • -
      - This is set when an admin explicitly overrides a tool. If - this is set we will not update the tool definition when - upgrading server versions. + If set, the tool will be served locally from the filestore + path - otherwise the endpoint will download the file by + itself from the url above.
      +
      + +
    • @@ -5023,16 +5593,16 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > admin_override
      true
    • -
      - Once the tool is added with the above fields, the following - fields are used to keep state on it. - The URL we serve the tool from when we serve locally. If this - is empty we just let the endpoint download its own tool from - the url above. + This is set when an admin explicitly overrides a tool. If + this is set we will not update the tool definition when + upgrading server versions.
      +
      + +
    • @@ -5042,12 +5612,18 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > serve_url
      https://www.google.com
    • -
      - Only valid for local dummy inventory. + Once the tool is added with the above fields, the following + fields are used to keep state on it. + The URL we serve the tool from when we serve locally. If this + is empty we just let the endpoint download its own tool from + the url above.
      +
      + +
    • @@ -5057,13 +5633,14 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > serve_path
      Where to read the file from the filesystem
    • -
      - A filestore path where the file can be downloaded from - if - served locally. + Only valid for local dummy inventory.
      +
      + +
    • @@ -5073,15 +5650,15 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > filestore_path
      /public/1234
    • -
      - The name of the cached file on the endpoint. This file will - persist and can be accessed again if this tool is needed in - future. If the file is missing (or has the wrong hash), then it - will be downloaded again. + A filestore path where the file can be downloaded from - if + served locally.
      +
      + +
    • @@ -5091,14 +5668,17 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > filename
      MyTool.exe
    • -
      - Hex encoded sha256 hash of the file. Endpoints will check - this hash against their fetch file to ensure it was - correctly transferred. + The name of the cached file on the endpoint. This file will + persist and can be accessed again if this tool is needed in + future. If the file is missing (or has the wrong hash), then it + will be downloaded again.
      +
      + +
    • @@ -5108,12 +5688,16 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > expected_hash
      1234
    • -
      - If set on a request we refresh the hash. + Hex encoded sha256 hash of the file. Endpoints will check + this hash against their fetch file to ensure it was + correctly transferred.
      +
      + +
    • @@ -5123,67 +5707,76 @@ Generated by the config wizard!!!
      autoexec > artifact_definitions > [0] > tools > [0] > materialize
      true
    • +
      + + If set on a request we refresh the hash. + +
      +
  • +
    - -
    - - A list of permissions the user needs to possess before they are - allowed to collect this artifact. -
    + +
  • - -
    autoexec > artifact_definitions > [0] > required_permissions
    -
      -
      - + A list of permissions the user needs to possess before they are + allowed to collect this artifact.
      + +
      autoexec > artifact_definitions > [0] > required_permissions
      +
        + +
      • EXECVE
        autoexec > artifact_definitions > [0] > required_permissions
      • -
      -
      -
    -
  • -
    +
    + + + + + + +
  • - -
    autoexec > artifact_definitions > [0] > resources
    -
      -
      - Default timeout for this artifact +
      + +
      autoexec > artifact_definitions > [0] > resources
      +
        + +
      • @@ -5193,12 +5786,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > timeout
        600
      • -
        + Default timeout for this artifact -
        +
        + +
      • @@ -5208,12 +5803,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > ops_per_second
        100
      • -
        +
        + +
      • @@ -5223,12 +5820,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > cpu_limit
        20
      • -
        +
        + +
      • @@ -5238,12 +5837,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > iops_limit
        20
      • -
        - Default resource use for the entire collection. +
        +
        + +
      • @@ -5253,12 +5854,14 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > max_rows
        1000000
      • -
        + Default resource use for the entire collection. -
        +
        + +
      • @@ -5268,21 +5871,19 @@ Generated by the config wizard!!!
        autoexec > artifact_definitions > [0] > resources > max_upload_bytes
        1000000
      • +
        + + + +
        +
  • - -
    - - If the artifact specifies a precondition the client will - evaluate this query before evaluating the main artifact. If the - precondition returns no rows (ie. FALSE) then the artifact will - not be collected. You can use the precondition to protect - incompatible clients from collecting the artifact (usually the - OS condition). -
    + +
  • @@ -5292,44 +5893,52 @@ Generated by the config wizard!!!
    autoexec > artifact_definitions > [0] > precondition
    SELECT OS FROM info() WHERE OS =~ "windows"
  • -
    - Parameters are provided to the artifact by the user. They can - change the way the VQL is evaluated. + If the artifact specifies a precondition the client will + evaluate this query before evaluating the main artifact. If the + precondition returns no rows (ie. FALSE) then the artifact will + not be collected. You can use the precondition to protect + incompatible clients from collecting the artifact (usually the + OS condition).
    +
    + +
  • - -
    autoexec > artifact_definitions > [0] > parameters
    -
      -
      - + Parameters are provided to the artifact by the user. They can + change the way the VQL is evaluated.
      + +
      autoexec > artifact_definitions > [0] > parameters
      +
        + +
      • [0]
        -
        -
        autoexec > artifact_definitions > [0] > parameters > [0]
        -
          -
          - The name of the parameter. This name will appear in the - scope during query execution. +
          + +
          autoexec > artifact_definitions > [0] > parameters > [0]
          +
            + +
          • @@ -5339,13 +5948,15 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > parameters > [0] > name
            Foo
          • -
            - A human friendly name for the parameter (if not specified - we show the name). + The name of the parameter. This name will appear in the + scope during query execution.
            +
            + +
          • @@ -5355,14 +5966,15 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > parameters > [0] > friendly_name
            A Foo Variable
          • -
            - A default value for the parameter. NOTE: Parameters are - always strings so this field needs to be the string - representation of the type - e.g. "10" rather than 10. + A human friendly name for the parameter (if not specified + we show the name).
            +
            + +
          • @@ -5372,12 +5984,16 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > parameters > [0] > default
            10
          • -
            - A description of this parameter to be shown in the GUI + A default value for the parameter. NOTE: Parameters are + always strings so this field needs to be the string + representation of the type - e.g. "10" rather than 10.
            +
            + +
          • @@ -5387,14 +6003,14 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > parameters > [0] > description
            A parameter
          • -
            - The type of this parameter. Currently one of: - string, regex, yara, upload, int, int64, integer, timestamp, - csv, artifactset, json, json_array, bool, choices + A description of this parameter to be shown in the GUI
            +
            + +
          • @@ -5404,64 +6020,76 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > parameters > [0] > type
            int
          • -
            - For parameters of type "choices" this is a list of possible - choices. + The type of this parameter. Currently one of: + string, regex, yara, upload, int, int64, integer, timestamp, + csv, artifactset, json, json_array, bool, choices
            +
            + +
          • - -
            autoexec > artifact_definitions > [0] > parameters > [0] > choices
            -
              -
              - + For parameters of type "choices" this is a list of possible + choices.
              + +
              autoexec > artifact_definitions > [0] > parameters > [0] > choices
              +
                + +
              • One
                autoexec > artifact_definitions > [0] > parameters > [0] > choices
              • -
                +
                + +
              • Two
                autoexec > artifact_definitions > [0] > parameters > [0] > choices
              • +
                + + + +
                +
          • +
      • +
  • - -
    - - A snippet of VQL that can be imported by other artifacts -
    + +
  • @@ -5471,73 +6099,81 @@ Generated by the config wizard!!!
    autoexec > artifact_definitions > [0] > export
    VQL here
  • -
    - A list of artifacts that will be imported by this artifact. + A snippet of VQL that can be imported by other artifacts
    +
    + +
  • - -
    autoexec > artifact_definitions > [0] > imports
    -
      -
      - + A list of artifacts that will be imported by this artifact.
      + +
      autoexec > artifact_definitions > [0] > imports
      +
        + +
      • Artifact.Name
        autoexec > artifact_definitions > [0] > imports
      • +
        + + + +
        +
  • - -
    - - A list of queries to gather data from. -
    + +
  • - -
    autoexec > artifact_definitions > [0] > sources
    -
      -
      - + A list of queries to gather data from.
      + +
      autoexec > artifact_definitions > [0] > sources
      +
        + +
      • [0]
        -
        -
        autoexec > artifact_definitions > [0] > sources > [0]
        -
          -
          - An optional name for the query +
          + +
          autoexec > artifact_definitions > [0] > sources > [0]
          +
            + +
          • @@ -5547,12 +6183,14 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > sources > [0] > name
            MySource
          • -
            - + An optional name for the query
            +
            + +
          • @@ -5562,12 +6200,14 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > sources > [0] > description
            A description for the source
          • -
            +
            + +
          • @@ -5577,44 +6217,50 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > sources > [0] > query
            SELECT * FROM info()
          • -
            - An internal list of compiled queries. For backwards - compatibility with very old artifacts. + +
            + +
          • - -
            autoexec > artifact_definitions > [0] > sources > [0] > queries
            -
              -
              - + An internal list of compiled queries. For backwards + compatibility with very old artifacts.
              + +
              autoexec > artifact_definitions > [0] > sources > [0] > queries
              +
                + +
              • DO NOT USE
                autoexec > artifact_definitions > [0] > sources > [0] > queries
              • +
                + + + +
                +
          • - -
            - - A precondition applying to this source only. -
            + +
          • @@ -5624,44 +6270,48 @@ Generated by the config wizard!!!
            autoexec > artifact_definitions > [0] > sources > [0] > precondition
            SELECT OS FROM info() WHERE OS =~ "windows"
          • -
            - An artifact source may define multiple notebook cells to be - used when the artifact is collected or hunted for. + A precondition applying to this source only.
            +
            + +
          • - -
            autoexec > artifact_definitions > [0] > sources > [0] > notebook
            -
              -
              - The type of the notebook cell: e.g. suggestion adds a cell - to the suggestion button. Also can be vql or markdown. + An artifact source may define multiple notebook cells to be + used when the artifact is collected or hunted for.
              + +
              autoexec > artifact_definitions > [0] > sources > [0] > notebook
              +
                + +
              • [0]
                -
                -
                autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0]
                -
                  -
                  - + The type of the notebook cell: e.g. suggestion adds a cell + to the suggestion button. Also can be vql or markdown.
                  + +
                  autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0]
                  +
                    + +
                  • @@ -5671,42 +6321,46 @@ Generated by the config wizard!!!
                    autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > type
                    suggestion
                  • -
                    - Parameters to pre-populate in the cell. +
                    +
                    + +
                  • env
                    -
                    -
                    autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env
                    -
                      -
                      - + Parameters to pre-populate in the cell.
                      + +
                      autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env
                      +
                        + +
                      • [0]
                        -
                        -
                        autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env > [0]
                        -
                          -
                          + +
                          autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env > [0]
                          +
                            + +
                          • @@ -5716,12 +6370,14 @@ Generated by the config wizard!!!
                            autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env > [0] > key
                            X
                          • -
                            +
                            + +
                          • @@ -5731,20 +6387,24 @@ Generated by the config wizard!!!
                            autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > env > [0] > value
                            Y
                          • +
                            + + + +
                            +
                      • +
                  • - -
                    - - -
                    + +
                  • @@ -5754,40 +6414,49 @@ Generated by the config wizard!!!
                    autoexec > artifact_definitions > [0] > sources > [0] > notebook > [0] > template
                    Text here
                  • +
                    + + + +
                    +
              • +
          • +
      • +
  • +
    +
    + - -
    - - -
    + +
  • @@ -5797,20 +6466,14 @@ Generated by the config wizard!!!
    server_type
    linux
  • -
    - This is used to obfuscate artifact names when sending to the - client. NOTE: This is currently not very robust - i.e. it does not - hide the artifact names very well - you should not name artifacts - in a sensitive way. - This value is server-only and is NOT distributed to client - configuration files. Do not confuse it with Client.nonce, - which is a different value that IS sent to clients for org - grouping.
    +
    + +
  • @@ -5820,12 +6483,22 @@ Generated by the config wizard!!!
    obfuscation_nonce
    zKJDb3KcWh8=
  • -
    - Path to store autocert certificates. + This is used to obfuscate artifact names when sending to the + client. NOTE: This is currently not very robust - i.e. it does not + hide the artifact names very well - you should not name artifacts + in a sensitive way. + + This value is server-only and is NOT distributed to client + configuration files. Do not confuse it with Client.nonce, + which is a different value that IS sent to clients for org + grouping.
    +
    + +
  • @@ -5835,22 +6508,39 @@ Generated by the config wizard!!!
    autocert_cert_cache
    /tmp/
  • -
    - Various defaults used by various things. + Path to store autocert certificates.
    +
    + +
  • +
    + + Various defaults used by various things. + +
    defaults
      +
      +
    • + + + +
      defaults > notebook_cell_timeout_min
      +
      10
      +
    • Normally notebook queries timeout in 10 minutes (can not be @@ -5859,16 +6549,18 @@ Generated by the config wizard!!! change this.
      -
    • +
    • + +
      +
    • -
      defaults > notebook_cell_timeout_min
      -
      10
      +
      defaults > notebook_default_new_cell_rows
      +
      50
    • -
      By default new cells only list 50 rows if there is no custom @@ -5878,16 +6570,18 @@ Generated by the config wizard!!! default 50 rows.
      -
    • +
    • + +
      +
    • -
      defaults > notebook_default_new_cell_rows
      -
      50
      +
      defaults > notebook_memory_low_water_mark
      +
      0
    • -
      When running on a shared server notebook calculations can @@ -5899,16 +6593,18 @@ Generated by the config wizard!!! process memory is smaller than the low memory mark.
      -
    • +
    • + +
      +
    • -
      defaults > notebook_memory_low_water_mark
      +
      defaults > notebook_memory_high_water_mark
      0
    • -
      When the process memory exceeds the high water mark, we actively @@ -5916,16 +6612,18 @@ Generated by the config wizard!!! down.
      -
    • +
    • + +
      +
    • -
      defaults > notebook_memory_high_water_mark
      -
      0
      +
      defaults > notebook_number_of_local_workers
      +
      5
    • -
      Since Version 0.7.1, notebook queries are run in separate worker @@ -5938,22 +6636,9 @@ Generated by the config wizard!!! Minion.notebook_number_of_local_workers to 5.
      -
    • - - - -
      defaults > notebook_number_of_local_workers
      -
      5
      -
    • - -
      - - Wait this long for a worker to become available before giving - up. The default is 10 seconds. -
      + +
    • @@ -5963,13 +6648,15 @@ Generated by the config wizard!!!
      defaults > notebook_wait_time_for_worker_ms
      10000
    • -
      - The default priority of notebook processors (Higher priority will - receive jobs over lower priority). + Wait this long for a worker to become available before giving + up. The default is 10 seconds.
      +
      + +
    • @@ -5979,14 +6666,15 @@ Generated by the config wizard!!!
      defaults > notebook_worker_priority
      10
    • -
      - When exporting to CSV from the GUI the usual separator is comma - (`,`). This setting allows to change the default to any single - character. + The default priority of notebook processors (Higher priority will + receive jobs over lower priority).
      +
      + +
    • @@ -5996,13 +6684,16 @@ Generated by the config wizard!!!
      defaults > csv_delimiter
      ,
    • -
      - By default hunts expire in 7 days but you can change this using - this setting. + When exporting to CSV from the GUI the usual separator is comma + (`,`). This setting allows to change the default to any single + character.
      +
      + +
    • @@ -6012,13 +6703,15 @@ Generated by the config wizard!!!
      defaults > hunt_expiry_hours
      168
    • -
      - Default value of max_wait and relevant jitter for new event - queries the GUI creates. + By default hunts expire in 7 days but you can change this using + this setting.
      +
      + +
    • @@ -6028,12 +6721,15 @@ Generated by the config wizard!!!
      defaults > event_max_wait
      100
    • -
      + Default value of max_wait and relevant jitter for new event + queries the GUI creates. -
      +
      + +
    • @@ -6043,17 +6739,14 @@ Generated by the config wizard!!!
      defaults > event_max_wait_jitter
      30
    • -
      - If set we actively notify all clients as soon as event table is - changed. This causes a lot of load on large deployments so it is - off by default. It means that you will need to wait for the client - to reconnect before it receives updates to its event table - (usually about 5 min). When running `velociraptor gui` we set this - to true in order to get a responsive GUI. + +
      + +
    • @@ -6063,45 +6756,54 @@ Generated by the config wizard!!!
      defaults > event_change_notify_all_clients
      false
    • -
      - Additional directories to load artifacts from on start up. + If set we actively notify all clients as soon as event table is + changed. This causes a lot of load on large deployments so it is + off by default. It means that you will need to wait for the client + to reconnect before it receives updates to its event table + (usually about 5 min). When running `velociraptor gui` we set this + to true in order to get a responsive GUI.
      +
      + +
    • - -
      defaults > artifact_definitions_directories
      -
        -
        - + Additional directories to load artifacts from on start up.
        + +
        defaults > artifact_definitions_directories
        +
          + +
        • /etc/artifacts/
          defaults > artifact_definitions_directories
        • +
          + + + +
          +
    • - -
      - - The number of rows to keep in memory during a group by - operation. Once this is exceeded we switch to disk mode which - is a lot slower but has no memory limitations. Default 30000 -
      + +
    • @@ -6111,12 +6813,16 @@ Generated by the config wizard!!!
      defaults > max_in_memory_group_by
      30000
    • -
      - How long to cache ACL policies (default 60 sec) + The number of rows to keep in memory during a group by + operation. Once this is exceeded we switch to disk mode which + is a lot slower but has no memory limitations. Default 30000
      +
      + +
    • @@ -6126,13 +6832,14 @@ Generated by the config wizard!!!
      defaults > acl_lru_timeout_sec
      60
    • -
      - Ignore messages from unauthenticated clients for this long - gives - them a chance to enrol first (default 10 sec). + How long to cache ACL policies (default 60 sec)
      +
      + +
    • @@ -6142,16 +6849,15 @@ Generated by the config wizard!!!
      defaults > unauthenticated_lru_timeout_sec
      10
    • -
      - Controls how exports work (creating hunt or collection exports to a - zip file). On slow filesystems, increase the number of worker - threads to increase parallelism. You can also increase the timeout - if the filesystem is too slow to build large hunt zip files within - the default 10 minute timeout. + Ignore messages from unauthenticated clients for this long - gives + them a chance to enrol first (default 10 sec).
      +
      + +
    • @@ -6161,12 +6867,18 @@ Generated by the config wizard!!!
      defaults > export_concurrency
      10
    • -
      + Controls how exports work (creating hunt or collection exports to a + zip file). On slow filesystems, increase the number of worker + threads to increase parallelism. You can also increase the timeout + if the filesystem is too slow to build large hunt zip files within + the default 10 minute timeout. -
      +
      + +
    • @@ -6176,15 +6888,14 @@ Generated by the config wizard!!!
      defaults > export_max_timeout_sec
      600
    • -
      - The server maintains an index of all hunts in order to quickly - allow the GUI to filter/sort them. This setting controls how often - to rebuild the hunt index (default 600 sec). You probably don't - need to change it. + +
      + +
    • @@ -6194,14 +6905,17 @@ Generated by the config wizard!!!
      defaults > hunt_dispatcher_refresh_sec
      600
    • -
      - The hunt dispatcher index rebuild is rate limited to reduce load - on the server. This sets how fast it should go (in flows per - second). You probably do not want to change this. + The server maintains an index of all hunts in order to quickly + allow the GUI to filter/sort them. This setting controls how often + to rebuild the hunt index (default 600 sec). You probably don't + need to change it.
      +
      + +
    • @@ -6211,12 +6925,16 @@ Generated by the config wizard!!!
      defaults > hunt_dispatcher_refresh_rate
      10
    • -
      - Total number of cell versions we keep for undo/redo support. + The hunt dispatcher index rebuild is rate limited to reduce load + on the server. This sets how fast it should go (in flows per + second). You probably do not want to change this.
      +
      + +
    • @@ -6226,13 +6944,14 @@ Generated by the config wizard!!!
      defaults > notebook_versions
      5
    • -
      - Watch plugin frequency sleep time in seconds: How often - watch_syslog() will check for changes (default 3). + Total number of cell versions we keep for undo/redo support.
      +
      + +
    • @@ -6242,12 +6961,15 @@ Generated by the config wizard!!!
      defaults > watch_plugin_frequency
      3
    • -
      - Maximum length of the line that will be parsed (16kb) + Watch plugin frequency sleep time in seconds: How often + watch_syslog() will check for changes (default 3).
      +
      + +
    • @@ -6257,15 +6979,14 @@ Generated by the config wizard!!!
      defaults > watch_plugin_buffer_size
      16384
    • -
      - Period in seconds when to produce a backup. Velociraptor will - generate a backup of important metadata about the server. By - default this happens daily but you can change it here (set to -1) - to disable backups. + Maximum length of the line that will be parsed (16kb)
      +
      + +
    • @@ -6275,15 +6996,17 @@ Generated by the config wizard!!!
      defaults > backup_period_seconds
      86400
    • -
      - The server's client info manager runs housekeeping tasks - periodically to determine if clients need to be notified. This - setting controls how often to run the client info's house keeping - thread in seconds (default 60 sec) + Period in seconds when to produce a backup. Velociraptor will + generate a backup of important metadata about the server. By + default this happens daily but you can change it here (set to -1) + to disable backups.
      +
      + +
    • @@ -6293,16 +7016,17 @@ Generated by the config wizard!!!
      defaults > client_info_housekeeping_period
      60
    • -
      - Disable unicode usernames. By default Velociraptor allows - usernames to consist of any Unicode character for i8n support, - however this opens the possibility for Homoglyph attacks. Setting - the following to true will restrict usernames to the set a-z and - 0-9 + The server's client info manager runs housekeeping tasks + periodically to determine if clients need to be notified. This + setting controls how often to run the client info's house keeping + thread in seconds (default 60 sec)
      +
      + +
    • @@ -6312,13 +7036,18 @@ Generated by the config wizard!!!
      defaults > disable_unicode_usernames
      false
    • -
      - How often to refresh the search index (default 5 min). This - rebuilds the search index periodically to avoid inconsistencies. + Disable unicode usernames. By default Velociraptor allows + usernames to consist of any Unicode character for i8n support, + however this opens the possibility for Homoglyph attacks. Setting + the following to true will restrict usernames to the set a-z and + 0-9
      +
      + +
    • @@ -6328,7 +7057,21 @@ Generated by the config wizard!!!
      defaults > reindex_period_seconds
      300
    • +
      + + How often to refresh the search index (default 5 min). This + rebuilds the search index periodically to avoid inconsistencies. + +
      +
      +
      +
    • +
      + +
      The client metadata is an arbitrary key/value store that holds @@ -6351,39 +7094,30 @@ Generated by the config wizard!!! client metadata.
      -
    • -
      - -
      defaults > indexed_client_metadata
        -
        - - - -
        +
      • department
        defaults > indexed_client_metadata
      • +
        + + + +
        +
    • - -
      - - If this is set we do not actively check the status of in-flight - collections. This is a new feature to 0.73 and may need to be - disabled in some large deployments due to additional overheads. -
      + +
    • @@ -6393,15 +7127,16 @@ Generated by the config wizard!!!
      defaults > disable_active_inflight_checks
      false
    • -
      - Normally internal event artifacts are not written to disk but - passed internally. For debugging it is useful to have a written - record though. Enabling this will also write them to - disk. Probably only useful for debugging. + If this is set we do not actively check the status of in-flight + collections. This is a new feature to 0.73 and may need to be + disabled in some large deployments due to additional overheads.
      +
      + +
    • @@ -6411,14 +7146,17 @@ Generated by the config wizard!!!
      defaults > write_internal_events
      false
    • -
      - Defaults for client communication limits. Decrease those if - your clients are behind a proxy that only accepts very small - POST messages. If not set we use client defaults. + Normally internal event artifacts are not written to disk but + passed internally. For debugging it is useful to have a written + record though. Enabling this will also write them to + disk. Probably only useful for debugging.
      +
      + +
    • @@ -6428,12 +7166,16 @@ Generated by the config wizard!!!
      defaults > max_rows
      0
    • -
      - + Defaults for client communication limits. Decrease those if + your clients are behind a proxy that only accepts very small + POST messages. If not set we use client defaults.
      +
      + +
    • @@ -6443,12 +7185,14 @@ Generated by the config wizard!!!
      defaults > max_row_buffer_size
      0
    • -
      +
      + +
    • @@ -6458,14 +7202,14 @@ Generated by the config wizard!!!
      defaults > max_batch_wait
      0
    • -
      - Maximum default value for log messages sent by the client for each - flow. Once this is reached, the client stops sending log messages - in the current collection. +
      +
      + +
    • @@ -6475,21 +7219,21 @@ Generated by the config wizard!!!
      defaults > max_logs
      100000
    • +
      + + Maximum default value for log messages sent by the client for each + flow. Once this is reached, the client stops sending log messages + in the current collection. + +
      +
  • - -
    - - The Velociraptor server may be placed into "lockdown" mode. While in - lockdown mode certain permissions are denied - even for - administrators. This additional protection mode helps to mitigate - the case when a Velociraptor administrator's account is - compromised. The server can be taken out of lockdown mode by setting - lockdown to false and restarting the server. -
    + +
  • @@ -6499,12 +7243,19 @@ Generated by the config wizard!!!
    lockdown
    false
  • -
    - This will be set when Velociraptor is started with the --debug flag. + The Velociraptor server may be placed into "lockdown" mode. While in + lockdown mode certain permissions are denied - even for + administrators. This additional protection mode helps to mitigate + the case when a Velociraptor administrator's account is + compromised. The server can be taken out of lockdown mode by setting + lockdown to false and restarting the server.
    +
    + +
  • @@ -6514,31 +7265,34 @@ Generated by the config wizard!!!
    debug_mode
    false
  • -
    - This configuration applies for minions. On minions this will - override the settings elsewhere in the config file allowing an easy - way to manage the difference between minions and master nodes. - This override occurs at config load times so you can see the final configuration using - velociraptor --minion --config server.config.yaml config show + This will be set when Velociraptor is started with the --debug flag.
    +
    + +
  • - -
    Minion
    -
      -
      - Used to override Defaults.notebook_number_of_local_workers + This configuration applies for minions. On minions this will + override the settings elsewhere in the config file allowing an easy + way to manage the difference between minions and master nodes. + This override occurs at config load times so you can see the final configuration using + velociraptor --minion --config server.config.yaml config show
      + +
      Minion
      +
        + +
      • @@ -6548,14 +7302,14 @@ Generated by the config wizard!!!
        Minion > notebook_number_of_local_workers
        4
      • -
        - Used to override Defaults.notebook_worker_priority. By default - minion workers have higher priority than the master node allowing - minions to take over notebook calculations most of he time. + Used to override Defaults.notebook_number_of_local_workers
        +
        + +
      • @@ -6565,26 +7319,43 @@ Generated by the config wizard!!!
        Minion > notebook_worker_priority
        10
      • +
        + + Used to override Defaults.notebook_worker_priority. By default + minion workers have higher priority than the master node allowing + minions to take over notebook calculations most of he time. + +
        +
  • - -
    - - -
    + +
  • +
    + + + +
    security
      +
      +
    • +
      + +
      A list of path prefixes allowed for the 'file' accessor. If @@ -6596,32 +7367,36 @@ Generated by the config wizard!!! to preserve the defaults.
      -
    • -
      - -
      security > allowed_file_accessor_prefix
        -
        - - - -
        +
      • /tmp/
        security > allowed_file_accessor_prefix
      • +
        + + + +
        +
    • +
    • +
      +
    • +
      + +
      Deny takes precedent over allow. The below shows the default list, @@ -6629,32 +7404,36 @@ Generated by the config wizard!!! the entire list to preserve the defaults.
      -
    • -
      - -
      security > denied_file_accessor_prefix
        -
        - - - -
        +
      • /bin/
        security > denied_file_accessor_prefix
      • +
        + + + +
        +
    • +
    • +
      +
    • +
      + +
      A list of prefixes allowed for the fs accessor. All other prefixes @@ -6663,150 +7442,172 @@ Generated by the config wizard!!! to preserve the defaults.
      -
    • -
      - -
      security > allowed_fs_accessor_prefix
        -
        - - - -
        +
      • artifact_definitions
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • clients
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • downloads
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • notebooks
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • public
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • temp
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • server_artifacts
        security > allowed_fs_accessor_prefix
      • -
        +
        + +
      • server_artifacts_logs
        security > allowed_fs_accessor_prefix
      • +
        + + + +
        +
    • - -
      - - Deny takes precedent over allow. IMPORTANT: Setting this list replaces - the built-in deny list (acl, backups, config, orgs, secrets, users) - rather than merging with it. If you add custom prefixes here, you must - also include any of the built-in prefixes you want to keep. -
      + +
    • - -
      security > denied_fs_accessor_prefix
      -
        -
        - + Deny takes precedent over allow. IMPORTANT: Setting this list replaces + the built-in deny list (acl, backups, config, orgs, secrets, users) + rather than merging with it. If you add custom prefixes here, you must + also include any of the built-in prefixes you want to keep.
        +
    • +
      security > denied_fs_accessor_prefix
      +
        + +
      • config
        security > denied_fs_accessor_prefix
      • +
        + + + +
        +
    • +
      +
      +
    • +
      + +
      If these are set we enforce VQL to only have the specified allowed @@ -6817,94 +7618,106 @@ Generated by the config wizard!!! restricted.
      -
    • -
      - -
      security > allowed_plugins
        -
        - - - -
        +
      • glob
        security > allowed_plugins
      • -
      -
      -
      -
    • -
      +
    • +
    +
    +
    +
  • +
    + +
  • - -
    security > allowed_functions
    -
      -
      + +
      security > allowed_functions
      +
        + +
      • dict
        security > allowed_functions
      • -
      -
      -
    -
  • -
    +
    + +
    + + +
    + +
  • - -
    security > allowed_accessors
    -
      -
      + +
      security > allowed_accessors
      +
        + +
      • auto
        security > allowed_accessors
      • +
        + + + +
        +
  • +
    +
    +
  • +
    + +
    Alternatively, it might be easier to deny specific plugins and @@ -6913,94 +7726,106 @@ Generated by the config wizard!!! denied.
    -
  • -
    - -
    security > denied_plugins
      -
      - - - -
      +
    • execve
      security > denied_plugins
    • -
    -
    -
    -
  • -
    +
  • + + + + + + +
  • - -
    security > denied_functions
    -
      -
      + +
      security > denied_functions
      +
        + +
      • rm
        security > denied_functions
      • -
      -
      -
    -
  • -
    +
    + + + + + + +
  • - -
    security > denied_accessors
    -
      -
      + +
      security > denied_accessors
      +
        + +
      • s3
        security > denied_accessors
      • +
        + + + +
        +
  • +
    +
    +
  • +
    + +
    When the server is in lockdown mode the following permissions will @@ -7009,110 +7834,114 @@ Generated by the config wizard!!! modify the entire list to preserve the defaults.
    -
  • -
    - -
    security > lockdown_denied_permissions
      -
      - - - -
      +
    • ARTIFACT_WRITER
      security > lockdown_denied_permissions
    • -
      +
      + +
    • SERVER_ARTIFACT_WRITER
      security > lockdown_denied_permissions
    • -
      +
      + +
    • EXECVE
      security > lockdown_denied_permissions
    • -
      +
      + +
    • SERVER_ADMIN
      security > lockdown_denied_permissions
    • -
      +
      + +
    • FILESYSTEM_WRITE
      security > lockdown_denied_permissions
    • -
      +
      + +
    • FILESYSTEM_READ
      security > lockdown_denied_permissions
    • -
      +
      + +
    • MACHINE_STATE
      security > lockdown_denied_permissions
    • +
      + + + +
      +
  • - -
    - - Default expiry of certificate issuance (default 365 days). This - will apply for e.g. rotating certificates or issuing an api cert. -
    + +
  • @@ -7122,13 +7951,15 @@ Generated by the config wizard!!!
    security > certificate_validity_days
    365
  • -
    - Normally the inventory service attempts to download tools in - its own but if this is set, we prevent any external access. + Default expiry of certificate issuance (default 365 days). This + will apply for e.g. rotating certificates or issuing an api cert.
    +
    + +
  • @@ -7138,7 +7969,24 @@ Generated by the config wizard!!!
    security > disable_inventory_service_external_access
    false
  • +
    + + Normally the inventory service attempts to download tools in + its own but if this is set, we prevent any external access. + +
    +
    +
    +
  • + + + +
    security > secrets_dek
    +
    +
  • The Data Encryptions Key to use for protecting the secrets in @@ -7155,16 +8003,18 @@ Generated by the config wizard!!! http://docs.velociraptor.app/docs/deployment/security/#protecting-stored-secrets
    -
  • +
  • + +
    +
  • -
    security > secrets_dek
    -
    +
    security > vql_must_use_secrets
    +
    false
  • -
    This controls VQL plugins that may accept secrets as well full @@ -7174,16 +8024,15 @@ Generated by the config wizard!!! plugins work without disabling them completely.
    -
  • - - - -
    security > vql_must_use_secrets
    -
    false
    -
  • +
    +
    +
  • +
    + +
    Prevent VQL from having access to these environment @@ -7191,34 +8040,32 @@ Generated by the config wizard!!! confidential information.
    -
  • -
    - -
    security > shadowed_env_vars
      -
      - - - -
      +
    • VELOCIRAPTOR_CONFIG
      security > shadowed_env_vars
    • +
      + + + +
      +
  • +
  • + diff --git a/content/docs/deployment/resources/index.md b/content/docs/deployment/resources/index.md index 0443cc7b5cf2..e8f63458ba8d 100644 --- a/content/docs/deployment/resources/index.md +++ b/content/docs/deployment/resources/index.md @@ -1,5 +1,6 @@ --- title: Server Performance and Monitoring +date: 2021-06-10 menutitle: Performance weight: 50 summary: | diff --git a/content/docs/deployment/security/index.md b/content/docs/deployment/security/index.md index db8094a065ee..0fd8bde6ee3c 100644 --- a/content/docs/deployment/security/index.md +++ b/content/docs/deployment/security/index.md @@ -1,6 +1,7 @@ --- menutitle: Security title: Velociraptor Security Configuration +date: 2024-01-17 weight: 46 summary: | Velociraptor is a highly privileged service with elevated access to thousands diff --git a/content/docs/deployment/server/multifrontend/index.md b/content/docs/deployment/server/multifrontend/index.md index 6f4fd504283a..016c380648e3 100644 --- a/content/docs/deployment/server/multifrontend/index.md +++ b/content/docs/deployment/server/multifrontend/index.md @@ -1,6 +1,7 @@ --- menutitle: Multi-Frontend title: Multi-Frontend Configuration +date: 2022-01-02 draft: false weight: 40 summary: | diff --git a/content/docs/file_collection/_index.md b/content/docs/file_collection/_index.md index 3ffb69feee8a..1db590440669 100644 --- a/content/docs/file_collection/_index.md +++ b/content/docs/file_collection/_index.md @@ -1,4 +1,5 @@ --- +icon: folder-open title: "File Acquisition" date: 2021-06-27T04:31:24Z last_reviewed: 2026-01-29 diff --git a/content/docs/forensic/_index.md b/content/docs/forensic/_index.md index 637e2b78c005..6eb570728467 100644 --- a/content/docs/forensic/_index.md +++ b/content/docs/forensic/_index.md @@ -1,4 +1,5 @@ --- +icon: finger-print title: "Forensic Analysis" date: 2021-06-12 draft: false diff --git a/content/docs/forensic/binary/index.md b/content/docs/forensic/binary/index.md index 91f5624812de..4654a49fa1da 100644 --- a/content/docs/forensic/binary/index.md +++ b/content/docs/forensic/binary/index.md @@ -1,5 +1,6 @@ --- title: "Binary parsing" +date: 2022-01-08 summary: | Velociraptor uses VQL to provide the flexibility for users to be able to craft a VQL query in order to retrieve valuable machine state diff --git a/content/docs/gui/_index.md b/content/docs/gui/_index.md index b062ba400044..116eba344419 100644 --- a/content/docs/gui/_index.md +++ b/content/docs/gui/_index.md @@ -1,5 +1,7 @@ --- +icon: view-boards title: "The Admin GUI" +date: 2021-06-10 last_reviewed: 2025-09-29 weight: 15 description: | diff --git a/content/docs/hunting/_index.md b/content/docs/hunting/_index.md index 2d6e6133cb96..0790cec16453 100644 --- a/content/docs/hunting/_index.md +++ b/content/docs/hunting/_index.md @@ -1,4 +1,5 @@ --- +icon: cursor-click title: "Hunting" date: 2021-06-09T04:13:25Z last_reviewed: 2025-12-29 diff --git a/content/docs/notebooks/_index.md b/content/docs/notebooks/_index.md index 7b09e1e0c3ac..c301fd8fe7a1 100644 --- a/content/docs/notebooks/_index.md +++ b/content/docs/notebooks/_index.md @@ -1,4 +1,5 @@ --- +icon: book-open title: Notebooks date: 2021-06-11T15:32:04Z last_reviewed: 2026-06-10 diff --git a/content/docs/overview/_index.md b/content/docs/overview/_index.md index 26d852b77a7b..e52a6a66e388 100644 --- a/content/docs/overview/_index.md +++ b/content/docs/overview/_index.md @@ -4,6 +4,7 @@ menutitle = "Velociraptor Overview" date = 2021-06-09T02:33:37Z weight = 5 chapter = false +icon = "globe" +++ > [!NOTE] diff --git a/content/docs/overview/support/index.md b/content/docs/overview/support/index.md index 439548dd5418..53c1be5d6e9d 100644 --- a/content/docs/overview/support/index.md +++ b/content/docs/overview/support/index.md @@ -1,6 +1,7 @@ --- menutitle: "Support Policy" title: "The Velociraptor Support Policy" +date: 2021-12-20 weight: 10 draft: false description: | diff --git a/content/docs/server_automation/_index.md b/content/docs/server_automation/_index.md index 8f3efeec2f89..10795fc968bb 100644 --- a/content/docs/server_automation/_index.md +++ b/content/docs/server_automation/_index.md @@ -1,4 +1,5 @@ --- +icon: cog title: "Server Automation" date: 2021-06-30T12:31:08Z draft: false diff --git a/content/docs/sigma/index.md b/content/docs/sigma/index.md index 6f54cc8f6d34..c7f7762a6459 100644 --- a/content/docs/sigma/index.md +++ b/content/docs/sigma/index.md @@ -1,4 +1,5 @@ --- +icon: shield-check menutitle: "Sigma rules" title: "Sigma rules" date: 2025-05-12 diff --git a/content/docs/troubleshooting/_index.md b/content/docs/troubleshooting/_index.md index 26fa2ae5be2a..bc340de93355 100644 --- a/content/docs/troubleshooting/_index.md +++ b/content/docs/troubleshooting/_index.md @@ -1,4 +1,5 @@ --- +icon: adjustments title: Troubleshooting Guide menutitle: Troubleshooting date: 2025-02-18 diff --git a/content/docs/troubleshooting/debugging/client/_index.md b/content/docs/troubleshooting/debugging/client/_index.md index 283a25661178..eb52006e6fd8 100644 --- a/content/docs/troubleshooting/debugging/client/_index.md +++ b/content/docs/troubleshooting/debugging/client/_index.md @@ -1,5 +1,6 @@ --- title: "Client" +date: 2025-03-28 description: "Profiles present only on the client" weight: 20 aliases: diff --git a/content/docs/troubleshooting/debugging/client/client_flows/index.md b/content/docs/troubleshooting/debugging/client/client_flows/index.md index 75d110d4321c..1188f8371f3d 100644 --- a/content/docs/troubleshooting/debugging/client/client_flows/index.md +++ b/content/docs/troubleshooting/debugging/client/client_flows/index.md @@ -1,5 +1,6 @@ --- title: "Flows" +date: 2025-03-28 description: Report the state of the client's flow manager weight: 50 aliases: diff --git a/content/docs/troubleshooting/debugging/client/client_monitoring/index.md b/content/docs/troubleshooting/debugging/client/client_monitoring/index.md index 69f801913e3e..c61570741ef6 100644 --- a/content/docs/troubleshooting/debugging/client/client_monitoring/index.md +++ b/content/docs/troubleshooting/debugging/client/client_monitoring/index.md @@ -1,5 +1,6 @@ --- title: "Monitoring" +date: 2025-03-28 weight: 10 description: Report stats on client monitoring artifacts aliases: diff --git a/content/docs/troubleshooting/debugging/global/_index.md b/content/docs/troubleshooting/debugging/global/_index.md index 4ba4dc1b465f..26ba358fb250 100644 --- a/content/docs/troubleshooting/debugging/global/_index.md +++ b/content/docs/troubleshooting/debugging/global/_index.md @@ -1,5 +1,6 @@ --- title: "Global" +date: 2025-09-29 description: "Profiles present on the server or client" weight: 20 --- diff --git a/content/docs/troubleshooting/debugging/global/datastore/_index.md b/content/docs/troubleshooting/debugging/global/datastore/_index.md index 9ffbed1980ec..3b01865e2c67 100644 --- a/content/docs/troubleshooting/debugging/global/datastore/_index.md +++ b/content/docs/troubleshooting/debugging/global/datastore/_index.md @@ -1,5 +1,6 @@ --- title: "Datastore" +date: 2025-09-29 weight: 20 description: Profiles related to the server's datastore. --- diff --git a/content/docs/troubleshooting/debugging/global/datastore/replication/index.md b/content/docs/troubleshooting/debugging/global/datastore/replication/index.md index 825d106afa2f..c43103a22987 100644 --- a/content/docs/troubleshooting/debugging/global/datastore/replication/index.md +++ b/content/docs/troubleshooting/debugging/global/datastore/replication/index.md @@ -1,5 +1,6 @@ --- title: "Replication" +date: 2025-09-29 weight: 10 description: Report current replication connections between master and minion. --- diff --git a/content/docs/troubleshooting/debugging/global/services/_index.md b/content/docs/troubleshooting/debugging/global/services/_index.md index 765a2594d469..f5c45e90c485 100644 --- a/content/docs/troubleshooting/debugging/global/services/_index.md +++ b/content/docs/troubleshooting/debugging/global/services/_index.md @@ -1,5 +1,6 @@ --- title: "Services" +date: 2025-03-28 weight: 50 description: "Velociraptor global services" aliases: diff --git a/content/docs/troubleshooting/debugging/global/services/export/index.md b/content/docs/troubleshooting/debugging/global/services/export/index.md index 8f2fc02c6c81..cbc3a4eccf04 100644 --- a/content/docs/troubleshooting/debugging/global/services/export/index.md +++ b/content/docs/troubleshooting/debugging/global/services/export/index.md @@ -1,5 +1,6 @@ --- title: "ExportContainers" +date: 2025-03-28 weight: 10 description: Report the state of current exports aliases: diff --git a/content/docs/troubleshooting/debugging/global/services/open_close/index.md b/content/docs/troubleshooting/debugging/global/services/open_close/index.md index f79447d6e64d..67f12458a29f 100644 --- a/content/docs/troubleshooting/debugging/global/services/open_close/index.md +++ b/content/docs/troubleshooting/debugging/global/services/open_close/index.md @@ -1,5 +1,6 @@ --- title: "Open-close" +date: 2025-09-29 weight: 40 description: Track open items that should be closed. aliases: diff --git a/content/docs/troubleshooting/debugging/global/services/tempfiles/index.md b/content/docs/troubleshooting/debugging/global/services/tempfiles/index.md index 2c6171937f70..27ab91ab2999 100644 --- a/content/docs/troubleshooting/debugging/global/services/tempfiles/index.md +++ b/content/docs/troubleshooting/debugging/global/services/tempfiles/index.md @@ -1,5 +1,6 @@ --- title: "tempfiles" +date: 2025-03-28 weight: 50 description: Track tempfiles used by the process. --- diff --git a/content/docs/troubleshooting/debugging/global/services/throttler/index.md b/content/docs/troubleshooting/debugging/global/services/throttler/index.md index a5834d2b76e4..715e864fc00d 100644 --- a/content/docs/troubleshooting/debugging/global/services/throttler/index.md +++ b/content/docs/troubleshooting/debugging/global/services/throttler/index.md @@ -1,5 +1,6 @@ --- title: "Throttler" +date: 2025-03-28 weight: 20 description: Track operations of the Throttler aliases: diff --git a/content/docs/troubleshooting/debugging/global/services/user_manager/index.md b/content/docs/troubleshooting/debugging/global/services/user_manager/index.md index 31cb15411452..b76e1fb1f786 100644 --- a/content/docs/troubleshooting/debugging/global/services/user_manager/index.md +++ b/content/docs/troubleshooting/debugging/global/services/user_manager/index.md @@ -1,5 +1,6 @@ --- title: "User Manager" +date: 2025-09-29 weight: 30 description: Reporting information about current users registered on the system. --- diff --git a/content/docs/troubleshooting/debugging/global/services/worker/index.md b/content/docs/troubleshooting/debugging/global/services/worker/index.md index afbd40219a92..d3d4a0b274f0 100644 --- a/content/docs/troubleshooting/debugging/global/services/worker/index.md +++ b/content/docs/troubleshooting/debugging/global/services/worker/index.md @@ -1,5 +1,6 @@ --- title: "worker" +date: 2025-09-29 weight: 60 description: Reporting information about current worker tasks. --- diff --git a/content/docs/troubleshooting/debugging/global/vql/_index.md b/content/docs/troubleshooting/debugging/global/vql/_index.md index da6e862d6b56..2a1a01d9e919 100644 --- a/content/docs/troubleshooting/debugging/global/vql/_index.md +++ b/content/docs/troubleshooting/debugging/global/vql/_index.md @@ -1,5 +1,6 @@ --- title: "VQL" +date: 2025-09-29 weight: 50 description: Track state of various VQL plugins and queries. aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/_index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/_index.md index f010711043d4..681bc17986bb 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/_index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/_index.md @@ -1,5 +1,6 @@ --- title: "Plugins" +date: 2025-09-29 description: See plugin-specific information for certain VQL plugins. weight: 20 aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/etw/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/etw/index.md index 41aea137cf7e..29f02ec5ca32 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/etw/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/etw/index.md @@ -1,5 +1,6 @@ --- title: "ETW" +date: 2025-03-29 weight: 10 description: Shows the current state of the ETW subsystem on Windows aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/glob/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/glob/index.md index fed9629f617d..edec6e18373a 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/glob/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/glob/index.md @@ -1,5 +1,6 @@ --- title: Glob +date: 2025-03-28 description: Track current Glob operations weight: 20 aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/ntfs/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/ntfs/index.md index f01e00642a52..c1487e1aa9c1 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/ntfs/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/ntfs/index.md @@ -1,5 +1,6 @@ --- title: NTFS Cache +date: 2025-09-29 description: Track NTFS caches weight: 30 --- diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/process/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/process/index.md index 48105888fd12..19953cae692c 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/process/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/process/index.md @@ -1,5 +1,6 @@ --- title: Process Tracker +date: 2025-09-29 description: Report process tracker stats weight: 70 --- diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/sigma/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/sigma/index.md index 51c0b9b2d5d5..0a6f1160d7ae 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/sigma/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/sigma/index.md @@ -1,5 +1,6 @@ --- title: Sigma Tracker +date: 2025-03-28 description: Track current Sigma operations weight: 40 aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/sqlite/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/sqlite/index.md index c1cdcab9701f..09f242e8c88a 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/sqlite/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/sqlite/index.md @@ -1,5 +1,6 @@ --- title: Sqlite +date: 2025-03-29 description: Track SQLite handles used by the process. weight: 70 aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/windows_event/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/windows_event/index.md index 047ad0c3e115..242a9b39e4fe 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/windows_event/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/windows_event/index.md @@ -1,5 +1,6 @@ --- title: Windows Event Log Watcher +date: 2025-03-28 weight: 50 description: Records Statistics about the Windows Event Log Watcher Subsystem. aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/plugins/zip/index.md b/content/docs/troubleshooting/debugging/global/vql/plugins/zip/index.md index 2f1eaa3ce333..4d8d050fb9b8 100644 --- a/content/docs/troubleshooting/debugging/global/vql/plugins/zip/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/plugins/zip/index.md @@ -1,5 +1,6 @@ --- title: "Zip" +date: 2025-09-29 description: Reference counting for open Zip files. weight: 60 --- diff --git a/content/docs/troubleshooting/debugging/global/vql/queries/_index.md b/content/docs/troubleshooting/debugging/global/vql/queries/_index.md index 38457a1f3623..2693b1e0682b 100644 --- a/content/docs/troubleshooting/debugging/global/vql/queries/_index.md +++ b/content/docs/troubleshooting/debugging/global/vql/queries/_index.md @@ -1,5 +1,6 @@ --- title: "Queries" +date: 2025-09-29 description: See currently and recently running VQL queries. weight: 10 aliases: diff --git a/content/docs/troubleshooting/debugging/global/vql/queries/active_queries/index.md b/content/docs/troubleshooting/debugging/global/vql/queries/active_queries/index.md index c8c31f66a329..2e781d75b46a 100644 --- a/content/docs/troubleshooting/debugging/global/vql/queries/active_queries/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/queries/active_queries/index.md @@ -1,5 +1,6 @@ --- title: "Active Queries" +date: 2025-09-29 description: Report Currently Active queries. weight: 10 --- diff --git a/content/docs/troubleshooting/debugging/global/vql/queries/plugin_monitor/index.md b/content/docs/troubleshooting/debugging/global/vql/queries/plugin_monitor/index.md index c0344df90a55..52a104fa6adc 100644 --- a/content/docs/troubleshooting/debugging/global/vql/queries/plugin_monitor/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/queries/plugin_monitor/index.md @@ -1,5 +1,6 @@ --- title: "Plugin Monitor" +date: 2025-03-28 description: See currently running VQL plugins. weight: 10 --- diff --git a/content/docs/troubleshooting/debugging/global/vql/queries/recent_queries/index.md b/content/docs/troubleshooting/debugging/global/vql/queries/recent_queries/index.md index 41cf04d065ea..5faa80ce9f52 100644 --- a/content/docs/troubleshooting/debugging/global/vql/queries/recent_queries/index.md +++ b/content/docs/troubleshooting/debugging/global/vql/queries/recent_queries/index.md @@ -1,5 +1,6 @@ --- title: "Recent Queries" +date: 2025-09-29 description: Report Currently Active queries. weight: 30 --- diff --git a/content/docs/troubleshooting/debugging/internal/_index.md b/content/docs/troubleshooting/debugging/internal/_index.md index 9938b2aec469..c873190b3ef7 100644 --- a/content/docs/troubleshooting/debugging/internal/_index.md +++ b/content/docs/troubleshooting/debugging/internal/_index.md @@ -1,5 +1,6 @@ --- title: "Internal" +date: 2025-03-28 description: "Profiles provided by Golang" weight: 10 aliases: diff --git a/content/docs/troubleshooting/debugging/internal/go_profiles/index.md b/content/docs/troubleshooting/debugging/internal/go_profiles/index.md index 9461cf91e94c..ab8cb2f541c0 100644 --- a/content/docs/troubleshooting/debugging/internal/go_profiles/index.md +++ b/content/docs/troubleshooting/debugging/internal/go_profiles/index.md @@ -1,5 +1,6 @@ --- title: "Golang" +date: 2025-03-28 weight: 20 description: Show built in Go Profiles aliases: diff --git a/content/docs/troubleshooting/debugging/internal/metrics/index.md b/content/docs/troubleshooting/debugging/internal/metrics/index.md index 8386cdba6483..df3e4334ff33 100644 --- a/content/docs/troubleshooting/debugging/internal/metrics/index.md +++ b/content/docs/troubleshooting/debugging/internal/metrics/index.md @@ -1,5 +1,6 @@ --- title: "Metrics" +date: 2025-03-28 weight: 10 description: Report all the current process running metrics. aliases: diff --git a/content/docs/troubleshooting/debugging/org/_index.md b/content/docs/troubleshooting/debugging/org/_index.md index 9c44f2d360d5..d56885ff2498 100644 --- a/content/docs/troubleshooting/debugging/org/_index.md +++ b/content/docs/troubleshooting/debugging/org/_index.md @@ -1,5 +1,6 @@ --- title: Org +date: 2025-09-29 description: Profiles associated with org services. weight: 20 --- diff --git a/content/docs/troubleshooting/debugging/org/services/_index.md b/content/docs/troubleshooting/debugging/org/services/_index.md index a0caf4599b9f..bcf78fecf3ee 100644 --- a/content/docs/troubleshooting/debugging/org/services/_index.md +++ b/content/docs/troubleshooting/debugging/org/services/_index.md @@ -1,5 +1,6 @@ --- title: "Services" +date: 2025-09-29 weight: 10 summary: "" --- diff --git a/content/docs/troubleshooting/debugging/org/services/broadcast_service/index.md b/content/docs/troubleshooting/debugging/org/services/broadcast_service/index.md index 5e34842121c6..9998db3157e4 100644 --- a/content/docs/troubleshooting/debugging/org/services/broadcast_service/index.md +++ b/content/docs/troubleshooting/debugging/org/services/broadcast_service/index.md @@ -1,5 +1,6 @@ --- title: "Broadcast" +date: 2025-09-29 weight: 10 description: Track generators installed via the generator() plugin. --- diff --git a/content/docs/troubleshooting/debugging/org/services/notifier/index.md b/content/docs/troubleshooting/debugging/org/services/notifier/index.md index c437c46a268a..33e273210e3d 100644 --- a/content/docs/troubleshooting/debugging/org/services/notifier/index.md +++ b/content/docs/troubleshooting/debugging/org/services/notifier/index.md @@ -1,5 +1,6 @@ --- title: "Notifier" +date: 2025-09-29 weight: 40 description: Information about directly connected clients. --- diff --git a/content/docs/troubleshooting/debugging/org/services/queue_manager/index.md b/content/docs/troubleshooting/debugging/org/services/queue_manager/index.md index cc75b918a168..18eac8792a6a 100644 --- a/content/docs/troubleshooting/debugging/org/services/queue_manager/index.md +++ b/content/docs/troubleshooting/debugging/org/services/queue_manager/index.md @@ -1,5 +1,6 @@ --- title: "QueueManager" +date: 2025-09-29 weight: 20 description: Report the current states of server artifact event queues. --- diff --git a/content/docs/troubleshooting/debugging/org/services/vfs_service/index.md b/content/docs/troubleshooting/debugging/org/services/vfs_service/index.md index f2a79b0491f9..8bcee75b947b 100644 --- a/content/docs/troubleshooting/debugging/org/services/vfs_service/index.md +++ b/content/docs/troubleshooting/debugging/org/services/vfs_service/index.md @@ -1,5 +1,6 @@ --- title: "VFS" +date: 2025-09-29 weight: 20 description: The VFS service post processes results from VFS operations. --- diff --git a/content/docs/vql/_index.md b/content/docs/vql/_index.md index 05df82a73a91..0ff4dc9e4b9f 100644 --- a/content/docs/vql/_index.md +++ b/content/docs/vql/_index.md @@ -1,4 +1,5 @@ --- +icon: code title: "VQL" date: 2021-06-11T05:55:46Z draft: false diff --git a/content/docs/vql/vql_reference/index.md b/content/docs/vql/vql_reference/index.md index 5070b73f85ea..3e6d33243e45 100644 --- a/content/docs/vql/vql_reference/index.md +++ b/content/docs/vql/vql_reference/index.md @@ -8,7 +8,6 @@ noDisqus: true no_edit: true disableToc: false chapter: false -pre: --- {{% include-page "/vql_reference/" %}} diff --git a/content/downloads/_index.md b/content/downloads/_index.md index 04b5fc0796f0..ff8e0d5318e9 100644 --- a/content/downloads/_index.md +++ b/content/downloads/_index.md @@ -9,7 +9,6 @@ date: 2021-06-23T08:29:57Z draft: false weight: 25 no_children: true -pre: release: 0.77.2 base_release: 0.77.2 arches: diff --git a/content/downloads/previous_downloads/index.md b/content/downloads/previous_downloads/index.md index 28a7854a53b7..c3a5c0eba529 100644 --- a/content/downloads/previous_downloads/index.md +++ b/content/downloads/previous_downloads/index.md @@ -1,10 +1,10 @@ --- +type: wide title: "Downloads" date: 2021-06-23T08:29:57Z draft: false weight: 25 no_children: true -pre: release: 0.76.7 base_release: 0.76.7 arches: diff --git a/content/downloads/rc_downloads/index.md b/content/downloads/rc_downloads/index.md index c0e6efd3a95c..05ef3f2c0b51 100644 --- a/content/downloads/rc_downloads/index.md +++ b/content/downloads/rc_downloads/index.md @@ -1,10 +1,10 @@ --- +type: wide title: "Release Candidates" date: 2021-06-23T08:29:57Z draft: false weight: 25 no_children: true -pre: release: 0.77.1-rc1 base_release: 0.77.1-rc1 arches: diff --git a/content/exchange/_index.md b/content/exchange/_index.md index cf55a1b849e5..1c3745e6ba2d 100644 --- a/content/exchange/_index.md +++ b/content/exchange/_index.md @@ -8,7 +8,6 @@ date: 2021-06-12T14:03:59Z last_reviewed: 2026-07-26 draft: false weight: 150 -pre: no_edit: true sitemap: disable: true diff --git a/content/knowledge_base/_index.md b/content/knowledge_base/_index.md index e94dd0c9bd10..a60307d9eaa3 100644 --- a/content/knowledge_base/_index.md +++ b/content/knowledge_base/_index.md @@ -4,9 +4,9 @@ cascade: type: docs menutitle: "Knowledge Base" title: "Knowledge Base" +date: 2022-03-21 draft: false weight: 250 -pre: no_edit: true disableToc: false no_children: true diff --git a/content/presentations/_index.md b/content/presentations/_index.md index eb0f0c0d5b08..f83b57ef85d8 100644 --- a/content/presentations/_index.md +++ b/content/presentations/_index.md @@ -4,7 +4,6 @@ title: "Presentations" weight: 270 no_children: true no_edit: true -pre: description: | The following are various presentations and events that featured Velociraptor in some way. diff --git a/content/rss/index.md b/content/rss/index.md index a7c1f03cc48a..715a2b81b1c7 100644 --- a/content/rss/index.md +++ b/content/rss/index.md @@ -3,6 +3,7 @@ sidebar: exclude: true menutitle: "RSS" title: "RSS Feeds" +date: 2022-03-26 draft: false weight: 250 no_edit: true diff --git a/content/search/index.md b/content/search/index.md index bca81d0e5ff9..888c519a40f6 100644 --- a/content/search/index.md +++ b/content/search/index.md @@ -8,7 +8,6 @@ draft: false noDisqus: true noTitle: true weight: 400 -pre: "" --- {{< search >}} diff --git a/content/training/_index.md b/content/training/_index.md index d735e308b4b7..6f8348a247be 100644 --- a/content/training/_index.md +++ b/content/training/_index.md @@ -5,7 +5,6 @@ title: "Training Resources" date: 2021-06-12T14:03:59Z draft: false weight: 260 -pre: description: | ## Scheduled courses --- diff --git a/content/training/comparisons/_index.md b/content/training/comparisons/_index.md index 2c458a0e8cf2..526ab40dd756 100644 --- a/content/training/comparisons/_index.md +++ b/content/training/comparisons/_index.md @@ -1,5 +1,6 @@ --- title: "Comparisons" +date: 2026-03-26 description: | Velociraptor is a powerful forensic tool. These pages compare Velociraptor to other popular tools. @@ -45,4 +46,4 @@ The following pages serve a number of goals: ## Tool comparison -{{% children %}} +{{% children grid-cols=1 %}} diff --git a/content/training/comparisons/eztools/index.md b/content/training/comparisons/eztools/index.md index 09c68cf6b460..bb1ac7238bb3 100644 --- a/content/training/comparisons/eztools/index.md +++ b/content/training/comparisons/eztools/index.md @@ -1,5 +1,7 @@ --- + +icon: cursor-click title: "EZ Tools" menutitle: EZ Tools --- diff --git a/content/training/comparisons/raw_copy/index.md b/content/training/comparisons/raw_copy/index.md index b5cbf387a674..945cd345ada4 100644 --- a/content/training/comparisons/raw_copy/index.md +++ b/content/training/comparisons/raw_copy/index.md @@ -1,5 +1,7 @@ --- + +icon: copy title: "RawCopy" menutitle: RawCopy --- diff --git a/content/training/playbooks/_index.md b/content/training/playbooks/_index.md index daa234e12b50..620e541f3377 100644 --- a/content/training/playbooks/_index.md +++ b/content/training/playbooks/_index.md @@ -4,7 +4,6 @@ title: "Playbooks" date: 2024-06-12T14:03:59Z draft: false weight: 150 -pre: no_edit: true disableToc: false no_children: true @@ -24,4 +23,4 @@ to know where to start. This page aims to help newcomers to Velociraptor by presenting a set of playbooks to use when faced with certain tasks. -{{% children description=true style="h2" %}} +{{% children description=true grid-cols=1 %}} diff --git a/content/training/playbooks/finding_files/index.md b/content/training/playbooks/finding_files/index.md index 659d90bb628a..b9700af64719 100644 --- a/content/training/playbooks/finding_files/index.md +++ b/content/training/playbooks/finding_files/index.md @@ -1,4 +1,5 @@ --- +icon: search title: "Finding Files" date: 2025-03-29 weight: 50 diff --git a/content/training/playbooks/preservation/index.md b/content/training/playbooks/preservation/index.md index c846391d544f..762886626d58 100644 --- a/content/training/playbooks/preservation/index.md +++ b/content/training/playbooks/preservation/index.md @@ -1,4 +1,5 @@ --- +icon: archive title: "Preserving Forensic Evidence" date: 2024-08-08 summary: | diff --git a/content/training/playbooks/triage-logs/index.md b/content/training/playbooks/triage-logs/index.md index 651e506f4614..bea577688a9d 100644 --- a/content/training/playbooks/triage-logs/index.md +++ b/content/training/playbooks/triage-logs/index.md @@ -1,4 +1,5 @@ --- +icon: document-text title: "Triaging Logs" date: 2024-08-08 summary: | diff --git a/content/vql_reference/_index.md b/content/vql_reference/_index.md index c6743c930288..c235279c50bc 100644 --- a/content/vql_reference/_index.md +++ b/content/vql_reference/_index.md @@ -14,7 +14,6 @@ no_edit: true disableToc: false noTitle: true chapter: false -pre: head:
    description: | {{% expand "This page lists all the plugins, functions and accessors which are available in Velociraptor." %}} diff --git a/layouts/_partials/scripts.html b/layouts/_partials/scripts.html index 3faeabb28ef6..6e56039865e0 100644 --- a/layouts/_partials/scripts.html +++ b/layouts/_partials/scripts.html @@ -18,6 +18,12 @@ {{/* Hover-based link prefetching */}} {{- partial "scripts/prefetch.html" . -}} +{{/* Heading-permalink copy: clicking a heading anchor copies the section URL. */}} +{{- partial "scripts/heading-anchor-copy.html" . -}} + +{{/* Collapsible right TOC column: reader toggle (persists in localStorage). */}} +{{- partial "scripts/toc-collapse.html" . -}} + {{/* Mermaid */}} {{- if (.Store.Get "hasMermaid") -}} {{- partial "scripts/mermaid.html" . -}} diff --git a/layouts/_partials/scripts/heading-anchor-copy.html b/layouts/_partials/scripts/heading-anchor-copy.html new file mode 100644 index 000000000000..a51e33787e9a --- /dev/null +++ b/layouts/_partials/scripts/heading-anchor-copy.html @@ -0,0 +1,7 @@ +{{- /* Heading-permalink copy (assets/js/heading-anchor-copy.js): clicking a + .subheading-anchor copies the page URL including the section fragment. */ -}} +{{- $jsHeadingCopy := resources.Get "js/heading-anchor-copy.js" -}} +{{- if hugo.IsProduction -}} + {{- $jsHeadingCopy = $jsHeadingCopy | minify | fingerprint -}} +{{- end -}} + \ No newline at end of file diff --git a/layouts/_partials/scripts/reference-filter.html b/layouts/_partials/scripts/reference-filter.html index 9cac0c8ca45a..b07811e9beba 100644 --- a/layouts/_partials/scripts/reference-filter.html +++ b/layouts/_partials/scripts/reference-filter.html @@ -32,18 +32,17 @@ return false; } - /* The generator emits each item's documentation comment as a - .item-comment div immediately before its .ref-item li, so hiding an - item must hide the orphaned comment with it. */ - function itemComment(el) { - var sib = el.previousElementSibling; - return sib && sib.classList.contains('item-comment') ? sib : null; + /* The generator wraps each item and its documentation comment in a + single .ref-block div (item first, comment inside the same block), + so hiding an item hides its own block. */ + function refBlock(el) { + var p = el.parentElement; + return p && p.classList.contains('ref-block') ? p : null; } function setFiltered(el, filtered) { - el.classList.toggle('filtered-out', filtered); - var c = itemComment(el); - if (c) c.classList.toggle('filtered-out', filtered); + var b = refBlock(el); + (b || el).classList.toggle('filtered-out', filtered); } function applyFilter() { diff --git a/layouts/_partials/scripts/toc-collapse.html b/layouts/_partials/scripts/toc-collapse.html new file mode 100644 index 000000000000..f054d91fdef7 --- /dev/null +++ b/layouts/_partials/scripts/toc-collapse.html @@ -0,0 +1,9 @@ +{{- /* Collapsible right TOC column (assets/js/toc-collapse.js): the reader + toggle hides the "On this page" column. The persisted state is applied + before paint by an inline script in head-end.html; this only wires up the + click handlers and keeps aria-expanded in sync. */ -}} +{{- $jsTocCollapse := resources.Get "js/toc-collapse.js" -}} +{{- if hugo.IsProduction -}} + {{- $jsTocCollapse = $jsTocCollapse | minify | fingerprint -}} +{{- end -}} + \ No newline at end of file diff --git a/layouts/_partials/section-exclusions.html b/layouts/_partials/section-exclusions.html new file mode 100644 index 000000000000..bcc7b2603a9e --- /dev/null +++ b/layouts/_partials/section-exclusions.html @@ -0,0 +1,6 @@ +{{- /* Top-level content section keys excluded from the search index and the + /search/ page's "Filter by Section" accordion. Shared by baseof.html + (which emits data-pagefind-ignore for these) and the search shortcode + (which skips them in its per-section tally). One source of truth so the + indexed section set always matches the pill list. */ -}} +{{- return (slice "discord" "golang" "search" "youtube") -}} \ No newline at end of file diff --git a/layouts/_partials/section-names.html b/layouts/_partials/section-names.html new file mode 100644 index 000000000000..5b2c0630e67d --- /dev/null +++ b/layouts/_partials/section-names.html @@ -0,0 +1,20 @@ +{{- /* Top-level content section keys -> display names. Shared by baseof.html + (Pagefind "section" filter values) and the /search/ page shortcode (which + renders the "Filter by Section" accordion). Keys not listed here fall back + to the titlecased path segment. */ -}} +{{- return (dict + "announcements" "Announcements" + "artifact_references" "Artifact Reference" + "blog" "Blog" + "dev" "Developer" + "docs" "Documentation" + "downloads" "Downloads" + "exchange" "Exchange" + "golang" "Golang" + "knowledge_base" "Knowledge Base" + "presentations" "Presentations" + "rss" "RSS" + "search" "Search" + "training" "Training" + "vql_reference" "VQL Reference" +) -}} \ No newline at end of file diff --git a/layouts/_partials/toc.html b/layouts/_partials/toc.html index a4f640c75840..29623bcb948a 100644 --- a/layouts/_partials/toc.html +++ b/layouts/_partials/toc.html @@ -7,8 +7,11 @@ {{- $backToTop := (T "backToTop") | default "Scroll to top" -}} +{{/* Floating collapse/expand controls: overlay buttons parked at the + article column's top-right corner, just below the navbar. Each is shown + in the matching state - the right-facing chevron collapses the column, + the left-facing one reopens it. They live outside the nav (a display:none + column would hide them along with the rest of the column) and float over + the article's edge via fixed positioning, so they stay reachable + mid-scroll. Styling is in assets/css/custom.css. */}} + + + {{/* TOC subheadings component. This is a recursive component that renders a list of headings. */}} {{- define "toc-subheading" -}} {{- $headings := .headings -}} diff --git a/layouts/baseof.html b/layouts/baseof.html index 44ca8a817f21..2ade8c836f26 100644 --- a/layouts/baseof.html +++ b/layouts/baseof.html @@ -9,22 +9,7 @@ each data-pagefind-filter attribute as ONE capture, so one hidden element per tag (see the captures below the body tag). The /search/ page's Tags accordion toggles these as result filters. */}} - {{- $sectionNames := dict - "announcements" "Announcements" - "artifact_references" "Artifact Reference" - "blog" "Blog" - "dev" "Developer" - "docs" "Documentation" - "downloads" "Downloads" - "exchange" "Exchange" - "golang" "Golang" - "knowledge_base" "Knowledge Base" - "presentations" "Presentations" - "rss" "RSS" - "search" "Search" - "training" "Training" - "vql_reference" "VQL Reference" - -}} + {{- $sectionNames := partial "section-names.html" . -}} {{- $rel := strings.TrimSuffix "/" .RelPermalink -}} {{- /* Strip the deploy base path (empty on a root-mounted site, e.g. /velociraptor-docs/ on the gh-pages preview) so the first segment @@ -64,8 +49,12 @@ exclude them from the search index (they would add a bogus "Tags" value to the section filter and duplicate search results). The 404 page has no section (its path is just /404.html), so it would - appear as a bogus "404.html" section filter value - skip it too. */}} - {{- $indexable := not (or (eq .Kind "taxonomy") (eq .Kind "term") (eq $rel "/404.html")) -}} + appear as a bogus "404.html" section filter value - skip it too. + Also skip the sections that must never appear in search results: + standalone redirect pages (Discord, YouTube), the search page itself, + and the golang library docs (section-exclusions.html holds the keys). */}} + {{- $sectionExclusions := partial "section-exclusions.html" . -}} + {{- $indexable := not (or (eq .Kind "taxonomy") (eq .Kind "term") (eq $rel "/404.html") (in $sectionExclusions $sectionKey)) -}} {{- /* One hidden capture element per tag -> Pagefind filter "tags". diff --git a/layouts/partials/custom/head-end.html b/layouts/partials/custom/head-end.html index 98e79dcb7dc4..6867397d72a3 100644 --- a/layouts/partials/custom/head-end.html +++ b/layouts/partials/custom/head-end.html @@ -38,4 +38,22 @@ if (!window.__sidebarScrollInit) d.classList.remove("sidebar-loading"); }, 2000); })(); + + +{{- /* Collapsed right TOC column (assets/js/toc-collapse.js): apply the + reader's persisted state before the page paints, so the column is + already hidden on first sight - the deferred script only handles clicks + from then on. localStorage reads are not available during + rendering (Hugo does not evaluate them), so this must live in an inline + script. */ -}} + \ No newline at end of file diff --git a/layouts/shortcodes/children.html b/layouts/shortcodes/children.html index dddb68724e7f..b22219d75be9 100644 --- a/layouts/shortcodes/children.html +++ b/layouts/shortcodes/children.html @@ -1,6 +1,8 @@ {{- /* Port of the learn-theme children shortcode: lists child pages of the current section. Default style renders Hextra-style link cards; - style="hN" preserves the old heading-based rendering (used for TOC). */ -}} + style="hN" preserves the old heading-based rendering (used for TOC). + Cards may show an icon taken from each child page's `icon:` front + matter parameter (a name from the theme's data/icons.yaml set). */ -}} {{- $_hugo_config := `{ "version": 1 }` -}} {{- $showhidden := .Get "showhidden" -}} {{- $style := .Get "style" | default "li" -}} @@ -45,6 +47,11 @@
    + {{- with .Params.icon -}} + + {{- partial "utils/icon.html" (dict "name" . "attributes" "height=1.5rem") -}} + + {{- end -}} {{ .Title }} {{ partial "utils/icon.html" (dict "name" "chevron-right") }} diff --git a/layouts/shortcodes/search.html b/layouts/shortcodes/search.html index c2f0528e2065..70076c11129c 100644 --- a/layouts/shortcodes/search.html +++ b/layouts/shortcodes/search.html @@ -1,15 +1,51 @@ {{/* Site-wide search page backed by Pagefind (built by `pagefind --site public`). - The "Tags" accordion below mirrors the /tags/ taxonomy listing (same data, - rendered server-side as a collapsible block like the Section filter panel). - Unlike /tags/ pills elsewhere, each pill here is a *filter toggle*: clicking - it narrows the results to that tag (assets/js/search.js flips the matching - checkbox in Pagefind's hidden "tags" filter block) instead of navigating. - assets/js/search.js relocates it to sit directly under the Section filter. */}} + The "Filter by Section" and "Filter by Tag" accordions below are rendered + server-side so the full lists are visible before any query is typed. They + sit OUTSIDE the PagefindUI mount: PagefindUI's own per-query filter panel is + hidden (custom.css) and used only as a source of truth - assets/js/search.js + prunes each accordion's pills to the values present in the current results, + updates the Section counts to be result-relative, and toggles the underlying + native checkboxes when a pill is clicked. Data values must match the + Pagefind "section:" / "tags" filter values exactly. */}} +{{- $sectionNames := partial "section-names.html" . -}} +{{- $sectionExclusions := partial "section-exclusions.html" . -}} +{{- /* Mirror baseof.html's per-page section derivation (same base-path strip, + first-segment key, name fallback) and tally indexable pages so the idle + Section list matches the Pagefind index. Excluded section keys never + appear. */ -}} +{{- $sections := dict -}} +{{- range site.Pages -}} + {{- if or (eq .Kind "taxonomy") (eq .Kind "term") }}{{ continue }}{{ end -}} + {{- $rel := strings.TrimSuffix "/" .RelPermalink -}} + {{- if eq $rel "/404.html" }}{{ continue }}{{ end -}} + {{- $base := relURL "" | strings.TrimSuffix "/" | strings.TrimPrefix "/" -}} + {{- if $base }}{{ $rel = strings.TrimPrefix (printf "/%s" $base) $rel }}{{ end -}} + {{- $parts := split $rel "/" -}} + {{- $key := "" -}} + {{- if gt (len $parts) 1 }}{{ $key = index $parts 1 }}{{ end -}} + {{- if in $sectionExclusions $key }}{{ continue }}{{ end -}} + {{- $name := index $sectionNames $key -}} + {{- if not $name }}{{ $name = strings.Title (strings.Replace $key "_" " " -1) }}{{ end -}} + {{- if $name }}{{ $sections = merge $sections (dict $name (add (index $sections $name | default 0) 1)) }}{{ end -}} +{{- end -}} +{{- $sectionList := slice -}} +{{- range $name, $count := $sections }}{{ $sectionList = $sectionList | append (dict "name" $name "count" $count) }}{{ end -}} +{{- $sectionList = sort $sectionList "name" -}}