Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions velociraptor/1.0.0/api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,13 @@ actions:
required: true
schema:
type: string
- name: artifact
description: Artifact, or Artifact/Source, to read (needed for artifacts with several sources, e.g. Generic.Client.Info/BasicInformation). Leave empty for the previous behaviour.
multiline: false
example: Generic.Client.Info/BasicInformation
required: false
schema:
type: string
returns:
schema:
type: string
Expand Down
17 changes: 14 additions & 3 deletions velociraptor/1.0.0/src/app.py
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
import json
import re
import grpc
import ipaddress
import time
Expand Down Expand Up @@ -123,17 +124,27 @@ def get_client_flows(self, api_config, client_id):
results = self.request(api_config, query)
return results

def get_client_flow_results(self, api_config, client_id, flow_id):
def get_client_flow_results(self, api_config, client_id, flow_id, artifact=""):
if artifact:
# Only an artifact name, optionally /Source - it becomes part of the VQL below.
if not re.fullmatch(r"[A-Za-z0-9_.]+(/[A-Za-z0-9_.]+)?", artifact):
raise ValueError("Velociraptor: invalid artifact name %r" % artifact)
state = self.get_client_flow_status(api_config, client_id, flow_id)
while (state == "RUNNING"):
state = self.get_client_flow_status(api_config, client_id, flow_id)
if state == "FINISHED":
break
else:
time.sleep(5)
query = "SELECT * FROM flow_results(flow_id='" + flow_id + "', client_id='" + client_id + "')"
query = "SELECT * FROM flow_results(flow_id='" + flow_id + "', client_id='" + client_id + "'"
if artifact:
# Artifacts with several sources return no rows unless the source is named.
query += ", artifact='" + artifact + "'"
query += ")"
results = self.request(api_config, query)
return results[0]
if artifact:
return results
return results[0] if results else []

def get_client_flow_status(self, api_config, client_id, flow_id):
query = "SELECT * FROM flows(flow_id='" + flow_id + "', client_id='" + client_id + "')"
Expand Down
Loading