velociraptor

Velociraptor DFIR integration for LimaCharlie. List available VQL artifacts, view artifact definitions, launch forensic collections on endpoints. Find raw collection data in Artifacts (type:velociraptor, source:SID). Query processed JSON events from the 'velociraptor' sensor (tag:ext:ext-velociraptor). Build D&R rules for velociraptor_collection events. Use for: forensic triage, incident response, threat hunting, VQL artifact collection.

$ 安裝

git clone https://github.com/refractionPOINT/documentation /tmp/documentation && cp -r /tmp/documentation/marketplace/plugins/lc-essentials/skills/velociraptor ~/.claude/skills/documentation

// tip: Run this command in your terminal to install the skill

Repository

refractionPOINT
refractionPOINT
Author
refractionPOINT/documentation/marketplace/plugins/lc-essentials/skills/velociraptor
2
Stars
1
Forks
Updated2d ago
Added1w ago