What problem does it solve?
Incident responders need to gather forensic evidence from hundreds or thousands of endpoints quickly, but manual collection does not scale and ad-hoc scripts produce inconsistent results. This Skill guides the deployment and configuration of Velociraptor so teams can run structured, large-scale artifact collection across Windows, Linux, and macOS fleets.
Core Features & Use Cases
- Server and Client Deployment: Install the Velociraptor server, repack client installers, and roll out agents via Group Policy, SCCM, Intune, or Docker.
- VQL Artifact Collection: Run pre-built and custom VQL queries for event logs, prefetch, Shimcache, Amcache, MFT, browser history, persistence mechanisms, and Linux artifacts like auth logs and bash history.
- Hunt Operations at Scale: Create hunts with label-based targeting and resource limits, monitor flow completion states, and reconcile participation against asset inventory.
- Use Case: During a suspected breach, launch a triage hunt using Windows.KapeFiles.Targets across all endpoints to collect event logs, registry hives, and browser artifacts, then forward results to Elastic for analysis.
Quick Start
Ask the AI to help you deploy a Velociraptor server and create a triage hunt that collects event logs and prefetch data from all Windows endpoints.