VELOCIRAPTOR
Velociraptor is an advanced endpoint visibility and collection tool. Essential for DFIR, threat hunting, and endpoint monitoring.
INSTALLATION#
SERVER#
# Download from https://github.com/Velocidex/velociraptor/releases # Generate config ./velociraptor config generate -i # Start server ./velociraptor frontend -v --config server.config.yaml # GUI access: https://localhost:8889
CLIENT DEPLOYMENT#
# Generate client config ./velociraptor config client # Install on endpoint ./velociraptor service install --config client.config.yaml # Run in foreground ./velociraptor client -v --config client.config.yaml
VQL BASICS#
VQL (Velociraptor Query Language)#
# Similar to SQL but for forensics SELECT * FROM info() SELECT * FROM processes() SELECT * FROM glob(globs="/etc/*")
BASIC SYNTAX#
SELECT column1, column2 FROM plugin() WHERE condition ORDER BY column LIMIT 10
COMMON PLUGINS#
SYSTEM INFO#
SELECT * FROM info() SELECT * FROM clients()
PROCESSES#
SELECT * FROM processes() SELECT Name, Pid, Ppid, CommandLine, Username FROM processes() WHERE Name =~ "powershell" SELECT * FROM process_tracker()
FILES#
SELECT * FROM glob(globs="/home/*/.ssh/*") SELECT * FROM glob(globs="C:/Users/*/Downloads/*.exe") SELECT * FROM read_file(filename="/etc/passwd") SELECT * FROM parse_csv(filename="/path/to/file.csv")
NETWORK#
SELECT * FROM netstat() SELECT * FROM connections() SELECT Laddr, Raddr, Status, Pid FROM netstat() WHERE Status = "ESTABLISHED"
REGISTRY (WINDOWS)#
SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*") SELECT * FROM read_reg_key(globs="HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*")
HASHES#
SELECT FullPath, Size, hash(path=FullPath) as Hash FROM glob(globs="/usr/bin/*")
TIMELINE#
SELECT * FROM Artifact.Linux.Timeline() SELECT * FROM Artifact.Windows.Timeline.MFT()
ARTIFACTS#
BUILT-IN ARTIFACTS#
# Collection artifacts bundled with Velociraptor # List artifacts SELECT * FROM artifact_definitions() # Hunt across endpoints # GUI: Hunt Manager > New Hunt
COMMON ARTIFACTS#
# Windows Windows.System.Pslist Windows.System.Services Windows.Network.Netstat Windows.Registry.Run Windows.Forensics.Prefetch Windows.Forensics.SRUM Windows.Forensics.Amcache Windows.EventLogs.Evtx Windows.KapeFiles.Targets # Linux Linux.Sys.Users Linux.Sys.Crontab Linux.Network.Netstat Linux.Forensics.Journal # macOS MacOS.System.Users MacOS.System.LaunchAgents
WRITING CUSTOM ARTIFACTS#
name: Custom.MyArtifact
description: |
Description of what this collects
parameters:
- name: SearchPath
default: "C:/Users/*"
sources:
- query: |
SELECT * FROM glob(globs=SearchPath)
WHERE Name =~ ".exe$"
HUNTS#
CREATE HUNT#
# GUI: Hunt Manager > New Hunt # 1. Select artifact # 2. Configure parameters # 3. Select target labels/all # 4. Schedule hunt
HUNT RESULTS#
# GUI: Hunt results show per-client findings # Export to CSV/JSON
SCHEDULED HUNTS#
# GUI: Hunt Manager > Create > Schedule
SERVER MONITORING#
EVENT QUERIES#
# Monitor server events SELECT * FROM watch_monitoring(artifact="System.Flow.Completion")
CLIENT EVENTS#
# Monitor client events SELECT * FROM watch_monitoring(artifact="Client.Events")
THREAT HUNTING#
SUSPICIOUS PROCESSES#
SELECT Name, Pid, Ppid, CommandLine, Username FROM processes() WHERE CommandLine =~ "(?i)(powershell|cmd).*(-enc|-encoded)"
PERSISTENCE REGISTRY#
SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*") WHERE Data.value =~ "(?i)(temp|appdata)"
NETWORK ANOMALIES#
SELECT Laddr, Raddr, Pid, Name FROM netstat() WHERE Raddr.Port IN (4444, 5555, 8888)
UNSIGNED EXECUTABLES#
SELECT FullPath, authenticode(filename=FullPath) as Sig FROM glob(globs="C:/Windows/Temp/*.exe") WHERE Sig.Trusted = FALSE
RECENTLY MODIFIED FILES#
SELECT FullPath, Mtime, Size FROM glob(globs="C:/Users/*/AppData/**/*.exe") WHERE Mtime > now() - 86400
LIVE RESPONSE#
SHELL ACCESS#
# GUI: Client > Shell # Interactive PowerShell/Bash
COLLECTION#
# GUI: Client > Collected # View artifact results
QUARANTINE#
# Isolate endpoint SELECT * FROM Artifact.Admin.Client.Quarantine()
FILE COLLECTION#
# Collect specific files SELECT * FROM Artifact.Generic.Collectors.File(Globs="/etc/passwd")
EXPORT/REPORTING#
EXPORT RESULTS#
# GUI: Export to CSV, JSON # Notebook: Generate reports
NOTEBOOKS#
# GUI: Notebooks for analysis # Markdown + VQL cells
USEFUL QUERIES#
PROCESS TREE#
SELECT * FROM process_tracker() WHERE Ppid = 1234
YARA SCANNING#
SELECT * FROM yara(rules="rule test { strings: $a = \"malware\" condition: $a }",
files="C:/Users/*/Downloads/*")
SCHEDULED TASKS#
SELECT * FROM Artifact.Windows.System.TaskScheduler()
AUTORUNS#
SELECT * FROM Artifact.Windows.Sysinternals.Autoruns()
BROWSER HISTORY#
SELECT * FROM Artifact.Windows.Applications.Chrome.History()
QUICK REFERENCE#
# VQL queries SELECT * FROM processes() SELECT * FROM netstat() SELECT * FROM glob(globs="/path/*") SELECT * FROM info() # Common artifacts Windows.System.Pslist Windows.Forensics.Prefetch Windows.EventLogs.Evtx Linux.Sys.Crontab # Server velociraptor frontend --config server.yaml # Client velociraptor client --config client.yaml
VELOCIRAPTOR CHEATSHEET
=======================
Source: https://cheatsheet.johlem.net
Velociraptor is an advanced endpoint visibility and collection tool.
Essential for DFIR, threat hunting, and endpoint monitoring.
INSTALLATION
============
SERVER
------
# Download from https://github.com/Velocidex/velociraptor/releases
# Generate config
./velociraptor config generate -i
# Start server
./velociraptor frontend -v --config server.config.yaml
# GUI access: https://localhost:8889
CLIENT DEPLOYMENT
-----------------
# Generate client config
./velociraptor config client
# Install on endpoint
./velociraptor service install --config client.config.yaml
# Run in foreground
./velociraptor client -v --config client.config.yaml
VQL BASICS
==========
VQL (Velociraptor Query Language)
---------------------------------
# Similar to SQL but for forensics
SELECT * FROM info()
SELECT * FROM processes()
SELECT * FROM glob(globs="/etc/*")
BASIC SYNTAX
------------
SELECT column1, column2
FROM plugin()
WHERE condition
ORDER BY column
LIMIT 10
COMMON PLUGINS
==============
SYSTEM INFO
-----------
SELECT * FROM info()
SELECT * FROM clients()
PROCESSES
---------
SELECT * FROM processes()
SELECT Name, Pid, Ppid, CommandLine, Username
FROM processes()
WHERE Name =~ "powershell"
SELECT * FROM process_tracker()
FILES
-----
SELECT * FROM glob(globs="/home/*/.ssh/*")
SELECT * FROM glob(globs="C:/Users/*/Downloads/*.exe")
SELECT * FROM read_file(filename="/etc/passwd")
SELECT * FROM parse_csv(filename="/path/to/file.csv")
NETWORK
-------
SELECT * FROM netstat()
SELECT * FROM connections()
SELECT Laddr, Raddr, Status, Pid
FROM netstat()
WHERE Status = "ESTABLISHED"
REGISTRY (WINDOWS)
------------------
SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*")
SELECT * FROM read_reg_key(globs="HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*")
HASHES
------
SELECT FullPath, Size, hash(path=FullPath) as Hash
FROM glob(globs="/usr/bin/*")
TIMELINE
--------
SELECT * FROM Artifact.Linux.Timeline()
SELECT * FROM Artifact.Windows.Timeline.MFT()
ARTIFACTS
=========
BUILT-IN ARTIFACTS
------------------
# Collection artifacts bundled with Velociraptor
# List artifacts
SELECT * FROM artifact_definitions()
# Hunt across endpoints
# GUI: Hunt Manager > New Hunt
COMMON ARTIFACTS
----------------
# Windows
Windows.System.Pslist
Windows.System.Services
Windows.Network.Netstat
Windows.Registry.Run
Windows.Forensics.Prefetch
Windows.Forensics.SRUM
Windows.Forensics.Amcache
Windows.EventLogs.Evtx
Windows.KapeFiles.Targets
# Linux
Linux.Sys.Users
Linux.Sys.Crontab
Linux.Network.Netstat
Linux.Forensics.Journal
# macOS
MacOS.System.Users
MacOS.System.LaunchAgents
WRITING CUSTOM ARTIFACTS
------------------------
name: Custom.MyArtifact
description: |
Description of what this collects
parameters:
- name: SearchPath
default: "C:/Users/*"
sources:
- query: |
SELECT * FROM glob(globs=SearchPath)
WHERE Name =~ ".exe$"
HUNTS
=====
CREATE HUNT
-----------
# GUI: Hunt Manager > New Hunt
# 1. Select artifact
# 2. Configure parameters
# 3. Select target labels/all
# 4. Schedule hunt
HUNT RESULTS
------------
# GUI: Hunt results show per-client findings
# Export to CSV/JSON
SCHEDULED HUNTS
---------------
# GUI: Hunt Manager > Create > Schedule
SERVER MONITORING
=================
EVENT QUERIES
-------------
# Monitor server events
SELECT * FROM watch_monitoring(artifact="System.Flow.Completion")
CLIENT EVENTS
-------------
# Monitor client events
SELECT * FROM watch_monitoring(artifact="Client.Events")
THREAT HUNTING
==============
SUSPICIOUS PROCESSES
--------------------
SELECT Name, Pid, Ppid, CommandLine, Username
FROM processes()
WHERE CommandLine =~ "(?i)(powershell|cmd).*(-enc|-encoded)"
PERSISTENCE REGISTRY
--------------------
SELECT * FROM glob(globs="HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*")
WHERE Data.value =~ "(?i)(temp|appdata)"
NETWORK ANOMALIES
-----------------
SELECT Laddr, Raddr, Pid, Name
FROM netstat()
WHERE Raddr.Port IN (4444, 5555, 8888)
UNSIGNED EXECUTABLES
--------------------
SELECT FullPath, authenticode(filename=FullPath) as Sig
FROM glob(globs="C:/Windows/Temp/*.exe")
WHERE Sig.Trusted = FALSE
RECENTLY MODIFIED FILES
-----------------------
SELECT FullPath, Mtime, Size
FROM glob(globs="C:/Users/*/AppData/**/*.exe")
WHERE Mtime > now() - 86400
LIVE RESPONSE
=============
SHELL ACCESS
------------
# GUI: Client > Shell
# Interactive PowerShell/Bash
COLLECTION
----------
# GUI: Client > Collected
# View artifact results
QUARANTINE
----------
# Isolate endpoint
SELECT * FROM Artifact.Admin.Client.Quarantine()
FILE COLLECTION
---------------
# Collect specific files
SELECT * FROM Artifact.Generic.Collectors.File(Globs="/etc/passwd")
EXPORT/REPORTING
================
EXPORT RESULTS
--------------
# GUI: Export to CSV, JSON
# Notebook: Generate reports
NOTEBOOKS
---------
# GUI: Notebooks for analysis
# Markdown + VQL cells
USEFUL QUERIES
==============
PROCESS TREE
------------
SELECT * FROM process_tracker()
WHERE Ppid = 1234
YARA SCANNING
-------------
SELECT * FROM yara(rules="rule test { strings: $a = \"malware\" condition: $a }",
files="C:/Users/*/Downloads/*")
SCHEDULED TASKS
---------------
SELECT * FROM Artifact.Windows.System.TaskScheduler()
AUTORUNS
--------
SELECT * FROM Artifact.Windows.Sysinternals.Autoruns()
BROWSER HISTORY
---------------
SELECT * FROM Artifact.Windows.Applications.Chrome.History()
QUICK REFERENCE
---------------
# VQL queries
SELECT * FROM processes()
SELECT * FROM netstat()
SELECT * FROM glob(globs="/path/*")
SELECT * FROM info()
# Common artifacts
Windows.System.Pslist
Windows.Forensics.Prefetch
Windows.EventLogs.Evtx
Linux.Sys.Crontab
# Server
velociraptor frontend --config server.yaml
# Client
velociraptor client --config client.yaml
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.