• Announcements
    • Security Advisories
      • CVE-2025-0914
      • CVE-2024-10526
      • CVE-2023-5950
      • CVE-2023-2226
      • CVE-2023-0242
      • CVE-2023-0290
  • Documentation
    • Velociraptor Overview
      • History
      • Support Policy
    • Deployment
      • Quickstart
      • Server Deployment
        • Key Concepts
        • Key Decisions
        • Deployment Example
        • Multi-Frontend
        • Upgrades
      • Organizations
      • Deploying Clients
      • Security
      • Performance
      • Troubleshooting
      • Config Reference
    • The Admin GUI
      • Debugging
        • Internal
          • Metrics
          • Golang
        • Client
          • Monitoring
          • Flows
        • Services
          • Export
          • Throttler
          • Tempfiles
        • VQL
          • Queries
          • Plugins
            • ETW
            • Glob
            • Evtx
            • Sigma
            • Sqlite
    • Managing Clients
      • Searching for clients
      • Interrogation
      • Collecting Artifacts
      • Labels
      • Metadata
      • Quarantine
      • Virtual File System
      • Shell Commands
      • Monitoring
      • Troubleshooting
    • VQL
      • VQL Fundamentals
      • Event Queries
      • JOIN in VQL
      • Extending VQL
      • VQL Reference
    • Artifacts
      • Security
      • Artifact Reference
      • Artifact Exchange
    • Notebooks
    • Hunting
    • Forensic Analysis
      • Searching Filenames
        • Velociraptor Paths
        • Remapping Accessors
      • Searching Content
      • NTFS Analysis
      • Binary parsing
      • Evidence Of Execution
      • Event Logs
      • Volatile State
    • Triage and acquisition
      • Remote Uploads
    • Server Automation
      • Server API
      • Server Monitoring
  • Downloads

  • VQL Reference
    • Frequently Used ✨
    • Windows-only
    • Linux-only
    • Server-only
    • Parsers
    • Encode/Decode
    • Event Plugins
    • Experimental
    • Developer
    • Other
    • Accessors
  • Training
    • Playbooks
  • Blog
  • Presentations
    • Linux Conf Au 2022
    • Auscert 2022
    • SANS Summit 2022
    • Velocon 2022
    • DFRWS APAC 2022
    • EverythingOpen 2023
    • VeloCON 2023
    • Auscert 2024
    • Auscert 2024 Talk
  • Artifact Exchange
  • Artifact Reference
  • Knowledge Base
  • Search

  • Github
  • Discord
  • YouTube
  • Mailing List
  • RSS
  • Rapid7 Docs
Brought to you by
2024
Client Event Artifact

tag :: Client Event Artifact

  • Demo.Plugins.Fifo
  • Generic.Client.LocalLogs
  • Generic.Client.Stats
  • Linux.Events.DNS
  • Linux.Events.EBPF
  • Linux.Events.HTTPConnections
  • Linux.Events.Journal
  • Linux.Events.ProcessExecutions
  • Linux.Events.SSHBruteforce
  • Linux.Events.SSHLogin
  • Linux.Events.TrackProcesses
  • System.Flow.Archive
  • System.Flow.Completion
  • System.Hunt.Archive
  • System.Upload.Completion
  • Windows.Detection.ProcessCreation
  • Windows.Detection.PsexecService
  • Windows.Detection.PsexecService.Kill
  • Windows.Detection.Registry
  • Windows.Detection.Service.Upload
  • Windows.Detection.Thumbdrives.List
  • Windows.Detection.Thumbdrives.OfficeKeywords
  • Windows.Detection.Thumbdrives.OfficeMacros
  • Windows.Detection.Usn
  • Windows.Detection.WMIProcessCreation
  • Windows.ETW.DNS
  • Windows.ETW.DNSQueriesServer
  • Windows.ETW.EdgeURLs
  • Windows.ETW.ETWSessions
  • Windows.ETW.FileCreation
  • Windows.ETW.KernelFile
  • Windows.ETW.KernelNetwork
  • Windows.ETW.KernelProcess
  • Windows.ETW.Registry
  • Windows.ETW.WMIProcessCreate
  • Windows.Events.EventLogModifications
  • Windows.Events.FailedLogBeforeSuccess
  • Windows.Events.Kerberoasting
  • Windows.Events.Kerbroasting
  • Windows.Events.Mutants
  • Windows.Events.ProcessCreation
  • Windows.Events.ServiceCreation
  • Windows.Events.Trackaccount
  • Windows.Events.TrackProcesses
  • Windows.Events.TrackProcessesBasic
  • Windows.Forensics.LocalHashes.Usn
  • Windows.Remediation.QuarantineMonitor
  • Windows.Sysinternals.SysmonLogForward