provocativo_
back to the arsenal
// arsenal·Blue TeamAdvancedFOSS

Velociraptor

Rapid7's open-source endpoint visibility + collection tool — DFIR at fleet scale.

Blue Team

$ velociraptor --help

Velociraptor

// what it is

Description

Mike Cohen's open-source DFIR collection tool that runs VQL (Velociraptor Query Language) hunts across thousands of endpoints in parallel. The free spiritual successor to GRR.

// use cases

What people use it for

  • Fleet-wide DFIR hunts
  • Live endpoint forensic collection

// commands

The commands you'll type

Start server

$ velociraptor --config server.yaml frontend

// facts

category
Blue Team
platforms
LIN · WIN · MAC
license
FOSS
difficulty
Advanced

// related in Blue Team