Hurukai - Get All Artifacts
Build a global archive with: - MFT (Windows) - Hives (Windows) - USN logs (Windows) - Prefetch files (Windows) - EVT/EVTX files (Windows) - Log files (Linux) - Filesystem content (Linux)
HarfangLab EDR · 7 tasks · 1 input · 0 outputs
Details
| ID | Hurukai - Get All Artifacts |
|---|---|
| From Version | 6.2.0 |
| Tasks | 7 |
README
Build a global archive with:
- MFT (Windows)
- Hives (Windows)
- USN logs (Windows)
- Prefetch files (Windows)
- EVT/EVTX files (Windows)
- Log files (Linux)
- Filesystem content (Linux)
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- GenericPolling
Integrations
- Hurukai
Scripts
This playbook does not use any scripts.
Commands
- harfanglab-result-artifact-all
- harfanglab-job-artifact-all
- harfanglab-get-endpoint-info
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| agentid | Required |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
agentid—
Commands used
harfanglab-get-endpoint-info
harfanglab-job-artifact-all
harfanglab-result-artifact-all
Flowchart
contentitemexportablefields: contentitemfields: propagationLabels: - all description: |- Build a global archive with: - MFT (Windows) - Hives (Windows) - USN logs (Windows) - Prefetch files (Windows) - EVT/EVTX files (Windows) - Log files (Linux) - Filesystem content (Linux) id: Hurukai - Get All Artifacts inputs: - description: '' key: agentid playbookInputQuery: required: true value: {} name: Hurukai - Get All Artifacts outputs: [] starttaskid: '0' tasks: '0': id: '0' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false nexttasks: '#none#': - '9' note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: '' id: 9c19c423-f7df-4468-8862-0cfd2ab407d5 iscommand: false name: '' version: -1 description: '' taskid: 9c19c423-f7df-4468-8862-0cfd2ab407d5 timertriggers: [] type: start view: |- { "position": { "x": 600, "y": -980 } } '3': id: '3' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false loop: exitCondition: '' iscommand: false max: 0 wait: 1 nexttasks: '#none#': - '7' note: false quietmode: 0 scriptarguments: Ids: simple: ${Harfanglab.Job.ID} Interval: simple: '1' PollingCommandArgName: simple: ids PollingCommandName: simple: harfanglab-job-info Timeout: simple: '60' dt: simple: Harfanglab.Job.Info(val.Status !== 'finished').ID separatecontext: true skipunavailable: false task: brand: '' description: |- Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete. This playbook implements polling by continuously running the command in Step \#2 until the operation completes. The remote action should have the following structure: 1. Initiate the operation. 2. Poll to check if the operation completed. 3. (optional) Get the results of the operation. id: 87d60db4-cb16-4b50-82e7-2ed196a40ec1 iscommand: false name: GenericPolling playbookId: GenericPolling type: playbook version: -1 taskid: 87d60db4-cb16-4b50-82e7-2ed196a40ec1 timertriggers: [] type: playbook view: |- { "position": { "x": 700, "y": -260 } } '5': id: '5' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: '' id: d9e8ae42-ae1f-421b-8f54-6acfa3a6f95d iscommand: false name: Done type: title version: -1 description: '' taskid: d9e8ae42-ae1f-421b-8f54-6acfa3a6f95d timertriggers: [] type: title view: |- { "position": { "x": 550, "y": 100 } } '6': id: '6' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false nexttasks: '#none#': - '3' note: false quietmode: 0 scriptarguments: agent_id: simple: ${inputs.agentid} separatecontext: false skipunavailable: false task: brand: Hurukai description: Start a job to download all artifacts from a host (Windows MFT, Hives, evt/evtx, Prefetch, USN, Linux logs and file list) id: 97d0710e-746f-42f6-840c-ae2356893e1d iscommand: true name: harfanglab-job-artifact-all script: Hurukai|||harfanglab-job-artifact-all type: regular version: -1 taskid: 97d0710e-746f-42f6-840c-ae2356893e1d timertriggers: [] type: regular view: |- { "position": { "x": 700, "y": -450 } } '7': evidencedata: customfields: {} description: simple: Global artifact package id: '7' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false nexttasks: '#none#': - '5' note: false quietmode: 0 scriptarguments: job_id: simple: ${Harfanglab.Job.ID} separatecontext: false skipunavailable: false task: brand: Hurukai description: Get all artifacts from a hostname from job results id: 23e678fb-aae0-45a1-8bbc-16659c3fef09 iscommand: true name: harfanglab-result-artifact-all script: Hurukai|||harfanglab-result-artifact-all type: regular version: -1 taskid: 23e678fb-aae0-45a1-8bbc-16659c3fef09 timertriggers: [] type: regular view: |- { "position": { "x": 700, "y": -90 } } '8': conditions: - condition: - - left: iscontext: true value: complex: accessor: Agent root: Harfanglab transformers: - args: field: value: simple: ostype operator: getField operator: isEqualString right: value: simple: windows - left: iscontext: true value: complex: accessor: Agent root: Harfanglab transformers: - args: field: value: simple: ostype operator: getField operator: isEqualString right: value: simple: linux label: windows/linux id: '8' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false nexttasks: '#default#': - '5' windows/linux: - '6' note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: '' id: 85c2518a-4bd2-43e4-88d4-d33c2a304390 iscommand: false name: Which platform is the agent running on ? description: '' type: condition version: -1 taskid: 85c2518a-4bd2-43e4-88d4-d33c2a304390 timertriggers: [] type: condition view: |- { "position": { "x": 600, "y": -670 } } '9': id: '9' ignoreworker: false isautoswitchedtoquietmode: false isoversize: false nexttasks: '#none#': - '8' note: false quietmode: 0 scriptarguments: agent_id: simple: ${inputs.agentid} separatecontext: false skipunavailable: false task: brand: Hurukai description: Get endpoint information from agent_id id: eecff41f-71c4-410c-80f2-601497ac01ff iscommand: true name: harfanglab-get-endpoint-info script: Hurukai|||harfanglab-get-endpoint-info type: regular version: -1 taskid: eecff41f-71c4-410c-80f2-601497ac01ff timertriggers: [] type: regular view: |- { "position": { "x": 600, "y": -845 } } version: -1 view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1145, "width": 530, "x": 550, "y": -980 } } } tests: - No tests (auto formatted) fromversion: 6.2.0