Skip to content

Automatically restrict hunts #3700

Answered by scudette
bob1503 asked this question in Q&A
Aug 22, 2024 · 5 comments · 4 replies
Discussion options

You must be logged in to vote

That is correct - the hunt is created with the initial label include/exclude configurations. But labels are dynamic so if you assign a client one of the included labels after the hunt is created then it will be scheduled on it immediately.

This is normally how this feature is used - the labels represent e.g. compromised hosts or ones in scope, then analysts can assign labels to include them in the hunt. As you can see here https://docs.velociraptor.app/vql_reference/server/label/ a user only requires the LABEL_CLIENT permission to label a client, but that can trigger a larger workflow.

Replies: 5 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@bob1503
Comment options

@scudette
Comment options

Comment options

You must be logged in to vote
2 replies
@bob1503
Comment options

@scudette
Comment options

Answer selected by bob1503
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants