Rapid7 recently observed threat actors misusing @velocidex. ⚠️ No vulnerability exists in the tool itself—the risk is in how attackers abuse it.
To help org's detect misuse, Velociraptor deliberately creates easy to detect IOCs. Learn what to look for 👉 https://t.co/V45jsZYmOY
At @AusCERT conference we presented "Sigma and Detection Engineering with @velocidex Velociraptor". Learn how to implement real time Sigma detection with forensic enhancements.
Full presentation https://t.co/G2PNgg3DMt and slides https://t.co/xuHSuguIB5
Looking forward to speaking on a panel at the @rapid7 Take Command Summit.
Register for free below as we talk about between pen testing, red teaming and the benefits of running regular security exercises.
https://t.co/TCNeRQBAAM
I've recently built a @velocidex#velociraptor VQL artifact to support Linux forensics. This artifact collects metadata about open file descriptors (other files, sockets, etc) from active processes on a Linux system. #dfir
https://t.co/Zl7A7xZLCr
Do you use @velocidex? 😎🦖 Want to learn more?
Our course is for security analysts, SOC team members, incident responders, and cybersecurity professionals looking to enhance their threat hunting skills 🔥
Register for THVR @WWHackinFest here: https://t.co/VwU4t3BcsV
🚀 I’ve done lot of work on LNK file collection and automated analysis, and I recently updated the publicly available LNK parser in Velociraptor - Windows.Forensics.Lnk.
This post Walks through the structure of LNK files and demonstrates some advanced analysis techniques. Hopefully there is some capabilities you may find useful 🙂
👉 LINK: https://t.co/HBoCFWRvRn
#DFIR #CTI @velocidex
Analysts can overlook lesser-known data points during LNK forensics for cyber threat intelligence, missing valuable insights. 🔍
Explore the structure of LNK files using @velocidex with analysis techniques used by Rapid7 Labs ⤵️ https://t.co/Gb6YE9t08y
Wrapping up day 2 of THVR @WWHackinFest 😎
Every time, @eric_capuano makes this stuff look like a breeze
Fun side effects of running our @velocidex trainings - they almost always result in our team contributing back to Velociraptor 🔥🦖💙 PRs incoming!
Velociraptor release 0.73 is now available for testing! Read about all the cool new features here https://t.co/dARJQU6rF4 .
An exciting new feature is built in timelining capability. Check the blog post here https://t.co/7gRIVEHSpB
I recently conducted a Rapid incident Response utilizing @velocidex session. Here is the session notes with some VQLs that can be utilized in IR cases
https://t.co/PlloDyC9g4
#IncidentResponse#Velociraptor#ThreatHunting
The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which @yoroisecurity documented almost exactly three years ago [1].
We also found the exact same code as in the blog on the corresponding client in the customer's network. For three years, this and other code could have gone unnoticed in the network.
Another reason for regular compromise assessments and hunting in the internal network.
[1] https://t.co/zPbsPlIrcg
For any velociraptor users - I have been messing around with plyara over the last week and created a few bulk yara artifacts using Yara-Forge - https://t.co/R8rPMsKvyt.
Velociraptor artifacts:
File - https://t.co/t7Qan6h7vP
Process
https://t.co/f1nq0dbyI9
https://t.co/uvlHbHAxuv
https://t.co/2E1ZA35Kz0
Webshell - https://t.co/8lq0UMtpzi
My automation takes Yara-Forge full ruleset, then seperates rules into buckets to optimise deployment. Updated each week to keep the rules up to date.
#dfir @velocidex
I was so excited about the new 0.72 release of Velociraptor I just could not wait to make a quick video to show you all the new features!
#velociraptor#dfir#digitalforensics
Check it out here
https://t.co/Vg1mIlQJdj
📣 Velociraptor v0.7.2 is now live!
The long-awaited release is highlighted by EWF support, dynamic DNS, improved SSH access, secrets management & much more.
Read up on all the exciting new features and download it today: https://t.co/m3pG1EpJhW
If you are a regular user, you'll no doubt have noticed new features since v0.7.1 that extend forensic capabilities on various systems. Nathanael Ndong shows us how to leverage those new features to perform forensic analysis of a VMware ESXi hypervisor.
https://t.co/gSIcCkEmTi