# Automating Artifact Collection Upon Waking Sleeper Agents

**URL:** https://community.limacharlie.com/t/automating-artifact-collection-upon-waking-sleeper-agents/21
**Category:** Detection & Response Rules
**Tags:** detection, windows
**Created:** [February 14, 2025, 6:24am UTC](https://community.limacharlie.com/t/automating-artifact-collection-upon-waking-sleeper-agents/21 "2025-02-14T06:24:09Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![eric\_capuano](https://yyz1.discourse-cdn.com/flex033/user_avatar/community.limacharlie.com/eric_capuano/32/4_2.png) [@eric\_capuano](https://community.limacharlie.com/u/eric_capuano)
#### Post date: [February 14, 2025, 6:24am UTC](https://community.limacharlie.com/t/automating-artifact-collection-upon-waking-sleeper-agents/21/1 "2025-02-14T06:24:09Z")

</div>

**Rule Description**  
This rule is designed for SLEEPER MODE deployments, where all agents are put to sleep and are only awakened in an IR scenario. It can easily be expanded upon to grab additional artifacts or even to initiate a Velociraptor acquisition.

Order of operations

1. watches for an agent to send a `STARTING_UP` event (happens when coming out of sleep)
2. checks that `evidence_acquired` tag has not already been set on the sensor
3. acquires all specified artifacts from the endpoint immediately
4. sets the `evidence_acquired` tag so that the rule does not apply to the same system twice

**Detect**

```yaml
event: STARTING_UP
op: is tagged 
tag: evidence_acquired
not: true

```

**Respond**

```yaml
- action: report
  name: Sleeper Activated - Get Evidence
- action: task
  command: >-
    artifact_get --file 'C:\\Windows\\System32\\winevt\\logs\\Security.evtx'
    --days-retention 30 --type wel
- action: task
  command: >-
    artifact_get --file 'C:\\Windows\\System32\\winevt\\logs\\System.evtx'
    --days-retention 30 --type wel
- action: task
  command: >-
    artifact_get --file 'C:\\Windows\\System32\\winevt\\logs\\Application.evtx'
    --days-retention 30 --type wel
- action: task
  command: >-
    artifact_get --file 'C:\\Windows\\System32\\winevt\\logs\\Windows
    PowerShell.evtx' --days-retention 30 --type wel
- action: add tag
  tag: evidence_acquired

```
