ir-velociraptor

Analyze endpoint telemetry and artifacts for incident response with Velociraptor VQL workflows.

183|35|Updated Nov 19, 2025
One-click install
npx skills add https://github.com/AgentSecOps/SecOpsAgentKit --skill ir-velociraptor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ir-velociraptor
Source: https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/incident-response/ir-velociraptor
Command: npx skills add https://github.com/AgentSecOps/SecOpsAgentKit --skill ir-velociraptor

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

Velociraptor-based incident response provides endpoint visibility, live-response data, and digital-forensics artifacts to accelerate containment and timeline reconstruction.

Core Features & Use Cases

  • Endpoint visibility: gather process lists, network connections, registry activity, and filesystem timelines across hosts to identify suspicious activity.
  • Forensics and threat hunting: collect evidence, perform timeline analyses, and run targeted VQL-based hunts across endpoints.
  • Live response and artifact development: enable rapid evidence collection and custom artifact creation with Velociraptor.

Quick Start

Install Velociraptor and begin incident-response collection across your endpoints.

Frequently Asked Questions about ir-velociraptor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I collect endpoint telemetry for live-response incident investigations?

Endpoint forensics and threat hunting are performed by collecting evidence, running targeted VQL-based hunts, and analyzing filesystem timelines across enterprise endpoints. This supports offline collectors and custom artifact creation for incident response.

How do I use VQL for artifact development and threat hunting?

VQL workflows support artifact development and threat hunting by enabling custom artifact creation and targeted hunts across enterprise endpoints. This allows investigators to collect specific digital-forensics artifacts and apply MITRE ATT&CK mappings during incident response.

Can I map endpoint forensic findings to MITRE ATT&CK techniques?

Endpoint telemetry and artifacts can be mapped to MITRE ATT&CK techniques to identify suspicious activity. This mapping correlates process lists, network connections, and registry activity with known adversary tactics during forensic investigations.

Does this approach support offline collectors for enterprise endpoint investigations?

Offline collectors are supported to gather digital-forensics artifacts and endpoint telemetry across enterprise hosts. This enables incident-response workflows and timeline reconstruction even when continuous live-response connectivity is unavailable.

What is the best way to perform timeline reconstruction during a forensic investigation?

Timeline reconstruction is performed by collecting filesystem timelines, process lists, and registry activity across enterprise endpoints. This evidence collection accelerates containment and supports forensic investigations and threat hunting campaigns.