Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments. Use when deploying and configure velociraptor for scalable endpoint forensic artifact collection.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments. Use when deploying and configure velociraptor for scalable endpoint forensic artifact collection.
["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"]
nist_csf
["RS.MA-01","RS.MA-02","RS.AN-03","RC.RP-01"]
Implementing Velociraptor for IR Collection
Overview
Velociraptor is an advanced open-source endpoint monitoring, digital forensics, and incident response platform developed by Rapid7. It uses the Velociraptor Query Language (VQL) to create custom artifacts that collect, query, and monitor almost any aspect of an endpoint. Velociraptor enables incident response teams to rapidly collect and examine forensic artifacts from across a network, supporting large-scale deployments with minimal performance impact. The client-server architecture with Fleetspeak communication enables real-time data collection from thousands of endpoints simultaneously, with offline endpoints picking up hunts when they reconnect.
When to Use
Trigger phrases:
"implementing velociraptor for ir collection"
"Deploy and configure Velociraptor for scalable endpoint forensic artifact collec"
When deploying or configuring implementing velociraptor for ir collection capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
Familiarity with incident response concepts and tools
Access to a test or lab environment for safe execution
Python 3.8+ with required dependencies installed
Appropriate authorization for any testing activities
Architecture
This section covers architecture for implementing velociraptor for ir collection.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Components
Velociraptor Server: Central management console with web UI and API
Velociraptor Client (Agent): Lightweight agent deployed to endpoints
Fleetspeak: Communication framework between client and server
VQL Engine: Query language engine for artifact collection
Filestore: Server-side storage for collected artifacts
Datastore: Metadata storage for hunts, flows, and client information
Supported Platforms
Windows (7+, Server 2008R2+)
Linux (Debian, Ubuntu, CentOS, RHEL)
macOS (10.13+)
Deployment
This section covers deployment for implementing velociraptor for ir collection.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Server Installation
# Download latest release
wget https://github.com/Velocidex/velociraptor/releases/latest/download/velociraptor-linux-amd64
# Generate server configuration
./velociraptor-linux-amd64 config generate -i
# Start the server
./velociraptor-linux-amd64 --config server.config.yaml frontend
# Or run as systemd servicesudocp velociraptor-linux-amd64 /usr/local/bin/velociraptor
sudo velociraptor --config /etc/velociraptor/server.config.yaml service install
Client Deployment
# Repack client MSI for Windows deployment
velociraptor --config server.config.yaml config client > client.config.yaml
velociraptor config repack --msi velociraptor-windows-amd64.msi client.config.yaml output.msi
# Deploy via Group Policy, SCCM, or Intune# Client runs as a Windows service: "Velociraptor"# Linux client deployment
velociraptor --config client.config.yaml client -v
# macOS client deployment
velociraptor --config client.config.yaml client -v
This section covers hunt operations for implementing velociraptor for ir collection.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Creating a Hunt
1. Navigate to Hunt Manager in Velociraptor Web UI
2. Click "New Hunt"
3. Configure:
- Description: "IR Triage - Case 2025-001"
- Include/Exclude labels for targeting
- Artifact selection (e.g., Windows.Forensics.Prefetch)
- Resource limits (CPU, IOPS, timeout)
4. Launch hunt
5. Monitor progress in real-time
VQL Hunt Examples
-- Hunt for specific file hash across all endpointsSELECT*FROM Artifact.Generic.Detection.HashHunter(
Hashes="e99a18c428cb38d5f260853678922e03"
)
-- Hunt for YARA signatures in memorySELECT*FROM Artifact.Windows.Detection.Yara.Process(
YaraRule='rule malware { strings: $s1 = "malicious_string" condition: $s1 }'
)
-- Hunt for Sigma rule matches in event logsSELECT*FROM Artifact.Server.Import.SigmaRules()
-- Hunt for suspicious scheduled tasksSELECT*FROM Artifact.Windows.System.TaskScheduler()
WHERE Command =~ "powershell|cmd|wscript|mshta|rundll32"
-- Hunt for processes with network connections to suspicious IPsSELECT*FROM Artifact.Windows.Network.Netstat()
WHERE RemoteAddr =~ "10\\.13\\.37\\."
Real-Time Monitoring
-- Monitor for new process creationSELECT*FROM watch_etw(guid="{22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716}")
WHERE EventData.ImageName =~ "powershell|cmd|wscript"
-- Monitor file system changesSELECT*FROM watch_directory(path="C:/Windows/Temp/")
-- Monitor registry changesSELECT*FROM watch_registry(key="HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/**")
Integration with SIEM/SOAR
This section covers integration with siem/soar for implementing velociraptor for ir collection.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Splunk Integration
Velociraptor Server --> Elastic/OpenSearch --> Splunk HEC
--> Direct syslog forwarding
--> Velociraptor API --> Custom scripts --> Splunk
Elastic Stack Integration
# Velociraptor server config for Elastic outputMonitoring:elastic:addresses:-https://elastic.local:9200username:velociraptorpassword:secure_passwordindex:velociraptor
MITRE ATT&CK Mapping
Technique
VQL Artifact
T1059 - Command Scripting
Windows.EventLogs.EvtxHunter (4104, 4688)
T1053 - Scheduled Task
Windows.System.TaskScheduler
T1547 - Boot/Logon Autostart
Windows.Persistence.PermanentWMIEvents
T1003 - OS Credential Dumping
Windows.Detection.Yara.Process
T1021 - Remote Services
Windows.EventLogs.EvtxHunter (4624 Type 3/10)
T1070 - Indicator Removal
Windows.EventLogs.Cleared
When NOT to Use
You need to test the implementation (use performing-* skills)
Task is about configuring existing tools (use configuring-* skills)
You need to analyze security events (use analyzing-* skills)
Task is about building detection rules (use building-* skills)