← All cheat sheets

VELOCIRAPTOR

Plain-text reference · 6 KB. Read it, search it (Ctrl-F) or print it.

Velociraptor is an advanced endpoint visibility and collection tool.
Essential for DFIR, threat hunting, and endpoint monitoring.

INSTALLATION#


            

SERVER#

# Download from https://github.com/Velocidex/velociraptor/releases

# Generate config
./velociraptor config generate -i

# Start server
./velociraptor frontend -v --config server.config.yaml

# GUI access: https://localhost:8889

CLIENT DEPLOYMENT#

# Generate client config
./velociraptor config client

# Install on endpoint
./velociraptor service install --config client.config.yaml

# Run in foreground
./velociraptor client -v --config client.config.yaml

VQL BASICS#


            

VQL (Velociraptor Query Language)#

# Similar to SQL but for forensics
SELECT * FROM info()
SELECT * FROM processes()
SELECT * FROM glob(globs="/etc/*")

BASIC SYNTAX#

SELECT column1, column2
FROM plugin()
WHERE condition
ORDER BY column
LIMIT 10

COMMON PLUGINS#


            

SYSTEM INFO#

SELECT * FROM info()
SELECT * FROM clients()

PROCESSES#

SELECT * FROM processes()
SELECT Name, Pid, Ppid, CommandLine, Username
FROM processes()
WHERE Name =~ "powershell"

SELECT * FROM process_tracker()

FILES#

SELECT * FROM glob(globs="/home/*/.ssh/*")
SELECT * FROM glob(globs="C:/Users/*/Downloads/*.exe")

SELECT * FROM read_file(filename="/etc/passwd")
SELECT * FROM parse_csv(filename="/path/to/file.csv")

NETWORK#

SELECT * FROM netstat()
SELECT * FROM connections()
SELECT Laddr, Raddr, Status, Pid
FROM netstat()
WHERE Status = "ESTABLISHED"

REGISTRY (WINDOWS)#

SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*")
SELECT * FROM read_reg_key(globs="HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*")

HASHES#

SELECT FullPath, Size, hash(path=FullPath) as Hash
FROM glob(globs="/usr/bin/*")

TIMELINE#

SELECT * FROM Artifact.Linux.Timeline()
SELECT * FROM Artifact.Windows.Timeline.MFT()

ARTIFACTS#


            

BUILT-IN ARTIFACTS#

# Collection artifacts bundled with Velociraptor

# List artifacts
SELECT * FROM artifact_definitions()

# Hunt across endpoints
# GUI: Hunt Manager > New Hunt

COMMON ARTIFACTS#

# Windows
Windows.System.Pslist
Windows.System.Services
Windows.Network.Netstat
Windows.Registry.Run
Windows.Forensics.Prefetch
Windows.Forensics.SRUM
Windows.Forensics.Amcache
Windows.EventLogs.Evtx
Windows.KapeFiles.Targets

# Linux
Linux.Sys.Users
Linux.Sys.Crontab
Linux.Network.Netstat
Linux.Forensics.Journal

# macOS
MacOS.System.Users
MacOS.System.LaunchAgents

WRITING CUSTOM ARTIFACTS#

name: Custom.MyArtifact
description: |
  Description of what this collects
parameters:
  - name: SearchPath
    default: "C:/Users/*"
sources:
  - query: |
      SELECT * FROM glob(globs=SearchPath)
      WHERE Name =~ ".exe$"

HUNTS#


            

CREATE HUNT#

# GUI: Hunt Manager > New Hunt
# 1. Select artifact
# 2. Configure parameters
# 3. Select target labels/all
# 4. Schedule hunt

HUNT RESULTS#

# GUI: Hunt results show per-client findings
# Export to CSV/JSON

SCHEDULED HUNTS#

# GUI: Hunt Manager > Create > Schedule

SERVER MONITORING#


            

EVENT QUERIES#

# Monitor server events
SELECT * FROM watch_monitoring(artifact="System.Flow.Completion")

CLIENT EVENTS#

# Monitor client events
SELECT * FROM watch_monitoring(artifact="Client.Events")

THREAT HUNTING#


            

SUSPICIOUS PROCESSES#

SELECT Name, Pid, Ppid, CommandLine, Username
FROM processes()
WHERE CommandLine =~ "(?i)(powershell|cmd).*(-enc|-encoded)"

PERSISTENCE REGISTRY#

SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*")
WHERE Data.value =~ "(?i)(temp|appdata)"

NETWORK ANOMALIES#

SELECT Laddr, Raddr, Pid, Name
FROM netstat()
WHERE Raddr.Port IN (4444, 5555, 8888)

UNSIGNED EXECUTABLES#

SELECT FullPath, authenticode(filename=FullPath) as Sig
FROM glob(globs="C:/Windows/Temp/*.exe")
WHERE Sig.Trusted = FALSE

RECENTLY MODIFIED FILES#

SELECT FullPath, Mtime, Size
FROM glob(globs="C:/Users/*/AppData/**/*.exe")
WHERE Mtime > now() - 86400

LIVE RESPONSE#


            

SHELL ACCESS#

# GUI: Client > Shell
# Interactive PowerShell/Bash

COLLECTION#

# GUI: Client > Collected
# View artifact results

QUARANTINE#

# Isolate endpoint
SELECT * FROM Artifact.Admin.Client.Quarantine()

FILE COLLECTION#

# Collect specific files
SELECT * FROM Artifact.Generic.Collectors.File(Globs="/etc/passwd")

EXPORT/REPORTING#


            

EXPORT RESULTS#

# GUI: Export to CSV, JSON
# Notebook: Generate reports

NOTEBOOKS#

# GUI: Notebooks for analysis
# Markdown + VQL cells

USEFUL QUERIES#


            

PROCESS TREE#

SELECT * FROM process_tracker()
WHERE Ppid = 1234

YARA SCANNING#

SELECT * FROM yara(rules="rule test { strings: $a = \"malware\" condition: $a }",
                   files="C:/Users/*/Downloads/*")

SCHEDULED TASKS#

SELECT * FROM Artifact.Windows.System.TaskScheduler()

AUTORUNS#

SELECT * FROM Artifact.Windows.Sysinternals.Autoruns()

BROWSER HISTORY#

SELECT * FROM Artifact.Windows.Applications.Chrome.History()

QUICK REFERENCE#

# VQL queries
SELECT * FROM processes()
SELECT * FROM netstat()
SELECT * FROM glob(globs="/path/*")
SELECT * FROM info()

# Common artifacts
Windows.System.Pslist
Windows.Forensics.Prefetch
Windows.EventLogs.Evtx
Linux.Sys.Crontab

# Server
velociraptor frontend --config server.yaml
# Client
velociraptor client --config client.yaml

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.