Главная
Study mode:
on
1
Velociraptor Incident Response
2
WARNING
3
Downloading Velociraptor IR
4
Verify Velociraptor IR binaries IMPORTANT
5
Download Velociraptor IR developer key
6
Setting binary run permissions in Linux
7
Velociraptor IR first run
8
Creating a client a server config
9
Client config file - set server local IP address
10
Copy client config to clients
11
Start the Velociraptor IR server GUI
12
Velociraptor IR interface first run
13
Start and enroll the Velociraptor IR client
14
Velociraptor IR search clients
15
Velociraptor IR add client labels
16
Velociraptor IR client management interface
17
Velociraptor IR client - Interrogate
18
Velociraptor IR client - Virtual File System VFS
19
Velociraptor IR client - Collected
20
A quick look at Velociraptor data store structure
21
Velociraptor IR client - Quarantine Host
22
Velociraptor IR client - Overview
23
Velociraptor IR client - VQL Drilldown
24
Velociraptor IR client - Shell
25
Left Menu Feature Tour
26
Hunts
27
Create a hunt
28
Select hunt artifacts
29
Velociraptor IR Artifact Exchange
30
Linux.Search.FileFinder
31
Configure artifact parameters
32
Regular expressions
33
Specify Resources
34
Review
35
Launch hunt
36
View hunt results
37
View/Edit Artifacts
38
Server Events
39
Create a new server monitor
40
Server Artifacts
41
Notebooks
42
Host Information
43
Host Specific Options
44
Host Monitoring
45
Create a new client monitor
46
Main Features Review
47
Where to find more resources
48
Thank you for your support!
Description:
Learn how to set up and use Velociraptor IR, an open-source endpoint visibility tool for incident response and digital forensic triage. Explore client monitoring, threat hunting, and response tasks across networks. Set up a test environment to understand Velociraptor's layout and features, including adding and monitoring clients, conducting hunts, and utilizing the Artifact Exchange. Dive into the client management interface, virtual file system, data store structure, and various functionalities like quarantine host and VQL drilldown. Create hunts, configure artifacts, and use regular expressions for effective searches. Discover how to set up server and client monitors, work with notebooks, and manage host-specific options. Gain practical insights into Velociraptor IR's main features and find additional resources for further learning.

Starting with Velociraptor Incident Response

DFIRScience
Add to list
0:00 / 0:00