Lead Image © Valentyn Ihnatkin, 123RF.com

Lead Image © Valentyn Ihnatkin, 123RF.com

Incident response with Velociraptor

The Hunter

Article from ADMIN 78/2023
By
The software incarnation of the feared predator in the Jurassic Park movies has been on the hunt for clues to cyberattacks and indicators of compromise. We show you how to tame the beast and use it for your own purposes.

From the IT department's point of view, it always makes sense to have an overview of your company's IT infrastructure – or at least be able to create one in a timely manner. In the immediate aftermath of an IT security incident, you need information quickly about which systems an attacker may have accessed and which systems are still operational. Department staff can then look specifically for indicators of compromise (IoCs) with the help of Velociraptor [1].

The developers cite two well-known tools as the basic idea for their own software: the GRR Rapid Response (GRR) [2] incident response tool and the OSQuery [3] monitoring tool. GRR lets you hunt for IoCs and run them over a period of time on all clients connected to your network. The reports are sent to a centralized server where they are available to admins. OSQuery, on the other hand, lets you query information from your clients in a language similar to SQL. The tool provides information in more than 275 tables – from CPU data to network settings (e.g, DNS or static routes) to installed Chrome extensions – you can find out pretty much everything about your systems.

Velociraptor now aims to combine the capabilities of GRR and OSQuery into one tool, while being faster, smaller, more scalable, and easier to install. Like GRR and OSQuery, the software works independent of the selected operating system and comes with virtually no dependencies. Beyond the functionality of GRR and OSQuery, it is possible for defined events to trigger queries and to use the Velociraptor Query Language (VQL), both to execute queries in the sense of OSQuery and to transfer files, modify systems and settings, and control the entire client-server infrastructure.

Quick Install

The

...
Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

comments powered by Disqus
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs



Support Our Work

ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.

Learn More”>
	</a>

<hr>		    
			</div>
		    		</div>

		<div class=