diff --git a/CHANGELOG.md b/CHANGELOG.md index e57880b..977c50d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ ### Artifacts +- files/applications/rustdesk.yaml: Added the collection of RustDesk access logs and screen recording files [linux, macos]. - files/applications/steam.yaml: Added the collection of Steam browser artifacts, avatar pictures, configuration and log files [linux, macos]. - files/system/netscaler.yaml: Added the collection of '/var/vpn', '/var/netscaler/logon', and '/netscaler/ns_gui' system files and directories [netscaler]. - files/system/nsconfig.yaml: Deprecated. All artifacts were moved to 'files/system/netscaler.yaml' [netscaler]. diff --git a/artifacts/files/applications/rustdesk.yaml b/artifacts/files/applications/rustdesk.yaml new file mode 100644 index 0000000..e1dd910 --- /dev/null +++ b/artifacts/files/applications/rustdesk.yaml @@ -0,0 +1,23 @@ +version: 1.0 +artifacts: + - + description: Collect access logs. + supported_os: [linux] + collector: file + path: /%user_home%/.local/share/logs/RustDesk + exclude_nologin_users: true + - + description: Collect session recording files. + supported_os: [linux] + collector: file + path: /%user_home%/Videos/RustDesk + exclude_nologin_users: true + - + description: Collect access logs. + supported_os: [macos] + collector: file + path: /%user_home%/Library/Logs/RustDesk + exclude_nologin_users: true + +# References: +# https://github.com/rustdesk/rustdesk/wiki/FAQ#access-logs \ No newline at end of file