Velocidex / velociraptor

Digging Deeper....
https://docs.velociraptor.app/
Other
2.8k stars 469 forks source link

Getting `ERROR client_repack: config file is too large to embed.` with some artifacts when trying to use the offline collector #3588

Closed certrik closed 2 weeks ago

certrik commented 2 weeks ago

When trying to use Windows.Hayabusa.Rules or some artifacts from DetectRaptor.Windows.Detection.* to create an offline collector, I get the error ERROR client_repack: config file is too large to embed. . Is this really on purpose? It would be great if artifacts that do have baked in configurations/IOCs/rules could be used to create an offline collector.

scudette commented 2 weeks ago

This is known limitation of repacking inside the exe which has limited space. For larger artifacts use the Generic collector type in the GUI