Groups
Sign in
Groups
velociraptor-discuss
Conversations
About
Send feedback
Help
velociraptor-discuss
Contact owners and managers
1–30 of 295
This is a mailing list to discuss the Velociraptor Forensic Suite. You can find the code on
https://gitlab.com/velocide
x/velociraptor
Our website can be reached at
https://docs.velociraptor.app
Mark all as read
Report group
0 selected
Xavier Mertens
,
Mike Cohen
2
Apr 10
vql: Symbol xxx not found ?
You didnt say how old the client was? What is the exact error? Thanks Mike Mike Cohen Digital
unread,
vql: Symbol xxx not found ?
You didnt say how old the client was? What is the exact error? Thanks Mike Mike Cohen Digital
Apr 10
Muhammad Muteeb armaghan
, …
Jamshid KP
3
Apr 8
Trouble in deployment on RHEL 7
Dear Mike, I have rhel 7.x with the same GLIBC support problem on the client side. so I have to use
unread,
Trouble in deployment on RHEL 7
Dear Mike, I have rhel 7.x with the same GLIBC support problem on the client side. so I have to use
Apr 8
Jamshid KP
Apr 8
Velociraptor Supported Version for Redhat 7.x or oracle Linux 7.x
Dear Team, I am getting error when I try to install the latest and n-1 Velociraptor version in Oracle
unread,
Velociraptor Supported Version for Redhat 7.x or oracle Linux 7.x
Dear Team, I am getting error when I try to install the latest and n-1 Velociraptor version in Oracle
Apr 8
Paul Siess
, …
Mike Cohen
5
Apr 4
Stale & Duplicate devices
Please see this kb article https://docs.velociraptor.app/knowledge_base/tips/plugin_not_found/ On Fri
unread,
Stale & Duplicate devices
Please see this kb article https://docs.velociraptor.app/knowledge_base/tips/plugin_not_found/ On Fri
Apr 4
Carlos Cajigas
Apr 4
Looking for LogMeIn VQL
I see that AnyDesk and TeamViewer artifacts have been created, but.... Does anyone care to share a
unread,
Looking for LogMeIn VQL
I see that AnyDesk and TeamViewer artifacts have been created, but.... Does anyone care to share a
Apr 4
Paul Siess
,
Mike Cohen
3
Apr 3
Struggling with front-end certificate issues by Microsoft PKI
Thank you! It's working with our cert now. On Wednesday, April 3, 2024 at 10:03:12 AM UTC-4 Mike
unread,
Struggling with front-end certificate issues by Microsoft PKI
Thank you! It's working with our cert now. On Wednesday, April 3, 2024 at 10:03:12 AM UTC-4 Mike
Apr 3
Eric Simpson
,
Mike Cohen
2
Mar 29
Copy File Upon Process Execution
Thanks for asking about this... The VQL function that uploads files to the server is called upload()
unread,
Copy File Upon Process Execution
Thanks for asking about this... The VQL function that uploads files to the server is called upload()
Mar 29
Loïc Castel
,
Mike Cohen
2
Mar 19
Mac OS X - Memory dump from VR
Hi Loïc, Thanks for asking about this. We very rarely if ever look at memory dumps in general - why
unread,
Mac OS X - Memory dump from VR
Hi Loïc, Thanks for asking about this. We very rarely if ever look at memory dumps in general - why
Mar 19
Xavier Mertens
,
Mike Cohen
3
Mar 11
Splunk.Events.Clients
Tx Mike! I updated my artefact, really cool! On 8 Mar 2024, at 12:59, Mike Cohen <mike@velocidex.
unread,
Splunk.Events.Clients
Tx Mike! I updated my artefact, really cool! On 8 Mar 2024, at 12:59, Mike Cohen <mike@velocidex.
Mar 11
Xavier Mertens
,
Mike Cohen
4
Mar 5
Rename host?
You could use a MAC address to uniquely identify the machine. The local IP address is also reported
unread,
Rename host?
You could use a MAC address to uniquely identify the machine. The local IP address is also reported
Mar 5
Xavier Mertens
,
Matt Green
3
Mar 1
Multiple YARA rules search?
Hi Matt, That's what I'm testing now… I pasted a big bunch of YARA rules in the Artefacts
unread,
Multiple YARA rules search?
Hi Matt, That's what I'm testing now… I pasted a big bunch of YARA rules in the Artefacts
Mar 1
Darren Appanah
, …
David Hendy
3
Feb 27
Integrating Velociraptor SSO with Active Directory Windows Server
Hi. what about if you've no ADFS any more and are hybrid/federated with Azure? Can we still use
unread,
Integrating Velociraptor SSO with Active Directory Windows Server
Hi. what about if you've no ADFS any more and are hybrid/federated with Azure? Can we still use
Feb 27
Gabe
,
Mike Cohen
2
Feb 22
Error when making packaged MSI
You probably enabled the vql plugin allow list in the config file. See this https://docs.velociraptor
unread,
Error when making packaged MSI
You probably enabled the vql plugin allow list in the config file. See this https://docs.velociraptor
Feb 22
Harmon Nine
Jan 26
Possible bug in Linux.Network.Netstat
Hello. In looking at the code for the "Linux.Network.Netstat" artifact, the first LET
unread,
Possible bug in Linux.Network.Netstat
Hello. In looking at the code for the "Linux.Network.Netstat" artifact, the first LET
Jan 26
John Foster
,
Mike Cohen
6
Jan 18
Unable to enroll client
Hi Mike, Finally identified the specific issue and have a solution. It transpires that the Azure
unread,
Unable to enroll client
Hi Mike, Finally identified the specific issue and have a solution. It transpires that the Azure
Jan 18
Xavier Mertens
,
Mike Cohen
2
12/21/23
HTTP Errors 499 after upgrade?
Did you modify the API bind address in the config file? It should be 127.0.0.1 or 0.0.0.0 On Fri, 22
unread,
HTTP Errors 499 after upgrade?
Did you modify the API bind address in the config file? It should be 127.0.0.1 or 0.0.0.0 On Fri, 22
12/21/23
racloir
,
Mike Cohen
2
12/19/23
Transitioning to new domain
If you include multiple URLs in the server_urls setting the clients will try one then the other. This
unread,
Transitioning to new domain
If you include multiple URLs in the server_urls setting the clients will try one then the other. This
12/19/23
Harmon Nine
2
12/11/23
Listing Offline Clients in Velociraptor
"clients()" does list *all* clients, offline and online. The problem I was having has to do
unread,
Listing Offline Clients in Velociraptor
"clients()" does list *all* clients, offline and online. The problem I was having has to do
12/11/23
racloir
,
Mike Cohen
8
12/7/23
Server generated msi not checking in
Thanks for spending the time to debug and report this issue. I actually think there is something
unread,
Server generated msi not checking in
Thanks for spending the time to debug and report this issue. I actually think there is something
12/7/23
Harmon Nine
12/6/23
Listing offline clients
Hello. I was wondering how to list velociraptor clients that are offline using the velociraptor api.
unread,
Listing offline clients
Hello. I was wondering how to list velociraptor clients that are offline using the velociraptor api.
12/6/23
Carlos Canto
11/10/23
CVE-2023-5950 Rapid7 Velociraptor Reflected XSS
Hello Velociraptor Community, Please take note of the following advisory related to CVE-2023-5950 and
unread,
CVE-2023-5950 Rapid7 Velociraptor Reflected XSS
Hello Velociraptor Community, Please take note of the following advisory related to CVE-2023-5950 and
11/10/23
mariem gharbi
,
Mike Cohen
10
9/30/23
I get Conncetion refused when I try to get information from the API
Next you should do the same thing on the server itself to verify it's listening on that interface
unread,
I get Conncetion refused when I try to get information from the API
Next you should do the same thing on the server itself to verify it's listening on that interface
9/30/23
Gert Koopman
,
Mike Cohen
5
9/28/23
security of velociraptor itself
Hi Gert Just circling back to this one, I was told that you can contact our risk team directly for
unread,
security of velociraptor itself
Hi Gert Just circling back to this one, I was told that you can contact our risk team directly for
9/28/23
Lili Lin
, …
Mike Cohen
10
8/31/23
Server artifact how to call client artifact
btw, could you tell me why sometimes when I launched the server artifact, it will turn down the whole
unread,
Server artifact how to call client artifact
btw, could you tell me why sometimes when I launched the server artifact, it will turn down the whole
8/31/23
Lili Lin
8/29/23
Server artifact call client artifact
Hi, I'm using velociraptor for hunting endpoints. I'm wondering if there is a way that I can
unread,
Server artifact call client artifact
Hi, I'm using velociraptor for hunting endpoints. I'm wondering if there is a way that I can
8/29/23
Lili Lin
8/29/23
how to use Server artifact to call client artifac
Hi, I'm using velociraptor for hunting endpoints. I'm wondering if there is a way that I can
unread,
how to use Server artifact to call client artifac
Hi, I'm using velociraptor for hunting endpoints. I'm wondering if there is a way that I can
8/29/23
Gaurav Banga
,
wlamb...@gmail.com
2
6/24/23
Looking for new Velociraptor artifact
Hi Gaurav, There are currently artifacts for services like Virustotal, Hybrid Analysis, and I think
unread,
Looking for new Velociraptor artifact
Hi Gaurav, There are currently artifacts for services like Virustotal, Hybrid Analysis, and I think
6/24/23
cipri zc
,
Mike Cohen
2
6/12/23
Ouput of a artifact using the API
This is covered here https://docs.velociraptor.app/docs/server_automation/server_api/#schedule-an-
unread,
Ouput of a artifact using the API
This is covered here https://docs.velociraptor.app/docs/server_automation/server_api/#schedule-an-
6/12/23
Suat Toksöz
5/26/23
connection error: desc = "transport: Error while dialing dial tcp [::1]:8001: connect: connection refused"
Hi, Just trying to set up a velociraptor server, and getting this on the admin panel. connection
unread,
connection error: desc = "transport: Error while dialing dial tcp [::1]:8001: connect: connection refused"
Hi, Just trying to set up a velociraptor server, and getting this on the admin panel. connection
5/26/23
Suat Toksöz
,
Mike Cohen
3
5/18/23
Unable to create a admin user on veleociraptor-gui
Got it. Thanks Mike. On Thu, May 18, 2023 at 11:18 AM Mike Cohen <mi...@velocidex.com> wrote:
unread,
Unable to create a admin user on veleociraptor-gui
Got it. Thanks Mike. On Thu, May 18, 2023 at 11:18 AM Mike Cohen <mi...@velocidex.com> wrote:
5/18/23