Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
velociraptor-discuss
Conversations
About
Groups keyboard shortcuts have been updated
Dismiss
See shortcuts
velociraptor-discuss
Contact owners and managers
1–30 of 321
This is a mailing list to discuss the Velociraptor Forensic Suite. You can find the code on
https://gitlab.com/velocide
x/velociraptor
Our website can be reached at
https://docs.velociraptor.app
Mark all as read
Report group
0 selected
Xavier Mertens
,
Mike Cohen
16
Feb 5
Simple JSON log?
Here is the full solution ``` LET Parameter <= "Foo" LET artifacts_to_watch = SELECT
unread,
Simple JSON log?
Here is the full solution ``` LET Parameter <= "Foo" LET artifacts_to_watch = SELECT
Feb 5
Daniel D'Angeli
,
Mike Cohen
6
Jan 27
Is the Windows.Forensics.LocalHashes.Usn artifact broken?
Yeah it's probably worth testing the latest head build You get one of those but following the
unread,
Is the Windows.Forensics.LocalHashes.Usn artifact broken?
Yeah it's probably worth testing the latest head build You get one of those but following the
Jan 27
Daniel D'Angeli
,
Mike Cohen
3
Jan 24
What am i doing wrong with artifacts here?
I am not sure about the load - i guess this is something that should be looked into in testing. Maybe
unread,
What am i doing wrong with artifacts here?
I am not sure about the load - i guess this is something that should be looked into in testing. Maybe
Jan 24
Daniel D'Angeli
,
Mike Cohen
2
Jan 23
Is it possible to forward Windows.ETW.FileCreation events to a remote syslog server?
Hi Daniel, syslog is not a particularly good format to forward logs because it is not structured. We
unread,
Is it possible to forward Windows.ETW.FileCreation events to a remote syslog server?
Hi Daniel, syslog is not a particularly good format to forward logs because it is not structured. We
Jan 23
Xavier Mertens
,
Mike Cohen
3
Jan 15
Timeout when preparing download
Hi Mike, Worked perfectly, tx! On 14 Jan 2025, at 21:08, Mike Cohen <mi...@velocidex.com> wrote:
unread,
Timeout when preparing download
Hi Mike, Worked perfectly, tx! On 14 Jan 2025, at 21:08, Mike Cohen <mi...@velocidex.com> wrote:
Jan 15
Paul Kotila
,
Mike Cohen
6
11/18/24
Velociraptor Logs to SIEM
Thank you, Mike. On Monday, November 18, 2024 at 9:06:22 AM UTC-6 Mike Cohen wrote: The Velociraptor
unread,
Velociraptor Logs to SIEM
Thank you, Mike. On Monday, November 18, 2024 at 9:06:22 AM UTC-6 Mike Cohen wrote: The Velociraptor
11/18/24
Paolo Leoni Work
,
Michael Cohen
3
10/10/24
Run a scheduled hunt
That's perfect for my goal. Thank you Mike. ~p On Wed, Oct 9, 2024 at 11:34 PM Michael Cohen <
unread,
Run a scheduled hunt
That's perfect for my goal. Thank you Mike. ~p On Wed, Oct 9, 2024 at 11:34 PM Michael Cohen <
10/10/24
Paolo Leoni Work
,
Mike Cohen
2
9/20/24
RPM/DEB agent creation from API
Hi Paolo, We had similar questions recently around creating MSI/RPM from the API. Although you can do
unread,
RPM/DEB agent creation from API
Hi Paolo, We had similar questions recently around creating MSI/RPM from the API. Although you can do
9/20/24
Carlos Cajigas
,
Mike Cohen
3
9/15/24
File Finder Glob Table
Mike, That helped. I got it now! Thanks so much! Carlos On Mon, Sep 16, 2024 at 12:48 AM Mike Cohen
unread,
File Finder Glob Table
Mike, That helped. I got it now! Thanks so much! Carlos On Mon, Sep 16, 2024 at 12:48 AM Mike Cohen
9/15/24
Vishva Patel
,
Mike Cohen
5
9/11/24
Cannot connect to API Server
Awesome. That worked. Thanks for your support. On Wednesday, September 11, 2024 at 9:45:04 AM UTC-4
unread,
Cannot connect to API Server
Awesome. That worked. Thanks for your support. On Wednesday, September 11, 2024 at 9:45:04 AM UTC-4
9/11/24
Bruce
, …
Mike Cohen
4
9/6/24
Documentation/recommendations on deployment
I'm not familiar with the exact technologies you mention but generally velociraptor clients
unread,
Documentation/recommendations on deployment
I'm not familiar with the exact technologies you mention but generally velociraptor clients
9/6/24
Paolo Leoni Work
,
Mike Cohen
6
8/27/24
Upload tool and artifact collection from cli
Thank you Mike, that was exactly what I needed. Paolo L. On Tue, Aug 27, 2024 at 4:30 AM Mike Cohen
unread,
Upload tool and artifact collection from cli
Thank you Mike, that was exactly what I needed. Paolo L. On Tue, Aug 27, 2024 at 4:30 AM Mike Cohen
8/27/24
Doraemon Nobi
,
Mike Cohen
2
8/23/24
Passing arguments using pyvelociraptor API.
It looks like you are using the wrappers.py from here https://github.com/Velocidex/pyvelociraptor/
unread,
Passing arguments using pyvelociraptor API.
It looks like you are using the wrappers.py from here https://github.com/Velocidex/pyvelociraptor/
8/23/24
albatr0ss
,
Mike Cohen
2
8/23/24
Using multiple deaddisks
Hi The best way is to make your dead disk image appear like a client and connect to a proper
unread,
Using multiple deaddisks
Hi The best way is to make your dead disk image appear like a client and connect to a proper
8/23/24
Seif Eddine Ammar
8/14/24
Creating a Hunt via CLI
Hi Sir Mike, I hope you're doing well. I am a cybersecurity graduating engineer I'm currently
unread,
Creating a Hunt via CLI
Hi Sir Mike, I hope you're doing well. I am a cybersecurity graduating engineer I'm currently
8/14/24
Ben McDaniel
,
Mike Cohen
3
8/2/24
Velociraptor NAT Environment Question
Awesome, thanks for the info! On Fri, Aug 2, 2024 at 9:37 PM Mike Cohen <mi...@velocidex.com>
unread,
Velociraptor NAT Environment Question
Awesome, thanks for the info! On Fri, Aug 2, 2024 at 9:37 PM Mike Cohen <mi...@velocidex.com>
8/2/24
Paolo Leoni Work
,
Mike Cohen
5
7/22/24
VQL and API - MSI creation
Now It's ok. Thank you Mike for your great support. ~p On Mon, Jul 22, 2024 at 3:19 PM Mike Cohen
unread,
VQL and API - MSI creation
Now It's ok. Thank you Mike for your great support. ~p On Mon, Jul 22, 2024 at 3:19 PM Mike Cohen
7/22/24
Assane Aw
,
Mike Cohen
2
6/13/24
I can't create a hunt velociraptor with artifacts like: CLIENT EVENT
client events are used for client monitoring - you can only run hunts with artifacts of type client
unread,
I can't create a hunt velociraptor with artifacts like: CLIENT EVENT
client events are used for client monitoring - you can only run hunts with artifacts of type client
6/13/24
Jason Ostrom
5/20/24
Bootstrap server to add custom artifact to server monitoring table
Hi All, I'm trying to bootstrap a velociraptor server to add a custom artifact to the server
unread,
Bootstrap server to add custom artifact to server monitoring table
Hi All, I'm trying to bootstrap a velociraptor server to add a custom artifact to the server
5/20/24
Jim Meyer
,
Mike Cohen
3
5/16/24
CLI user creation - works up to release 0.7.1
Hi Mike, Thanks! Restarting the 'velociraptor_service' successfully resolved the issue. The
unread,
CLI user creation - works up to release 0.7.1
Hi Mike, Thanks! Restarting the 'velociraptor_service' successfully resolved the issue. The
5/16/24
Amy Whyte
,
Mike Cohen
2
5/15/24
Contributor Contest
This is an excellent question. We really would like to encourage more artifact contributions but
unread,
Contributor Contest
This is an excellent question. We really would like to encourage more artifact contributions but
5/15/24
Amy Whyte
,
Mike Cohen
3
5/15/24
Making artifacts available for Offline Collection
Thank you Mike. I think it was something else going on as artifacts I would expect to be available
unread,
Making artifacts available for Offline Collection
Thank you Mike. I think it was something else going on as artifacts I would expect to be available
5/15/24
Max
,
Mike Cohen
4
5/11/24
Cyrillic Support
Hi Max, I just confirmed this works on my system because powershell is outputing in utf8. It is
unread,
Cyrillic Support
Hi Max, I just confirmed this works on my system because powershell is outputing in utf8. It is
5/11/24
Paul Kotila
,
Mike Cohen
3
5/11/24
New install
Thank you, Mike! On Fri, May 10, 2024, 8:54 AM Mike Cohen <mi...@velocidex.com> wrote: Hi Paul,
unread,
New install
Thank you, Mike! On Fri, May 10, 2024, 8:54 AM Mike Cohen <mi...@velocidex.com> wrote: Hi Paul,
5/11/24
Anmol Moudgil
,
Mike Cohen
10
5/6/24
Collect client not working
Hey Mike Could you please provide me with an update on this item's progress? Any logs or configs
unread,
Collect client not working
Hey Mike Could you please provide me with an update on this item's progress? Any logs or configs
5/6/24
Harshal Gosalia
,
Mike Cohen
2
4/26/24
Velociraptor install issue..
When you install the MSI it installs a client on windows. If you want to run a demo server try
unread,
Velociraptor install issue..
When you install the MSI it installs a client on windows. If you want to run a demo server try
4/26/24
Xavier Mertens
,
Mike Cohen
2
4/10/24
vql: Symbol xxx not found ?
You didnt say how old the client was? What is the exact error? Thanks Mike Mike Cohen Digital
unread,
vql: Symbol xxx not found ?
You didnt say how old the client was? What is the exact error? Thanks Mike Mike Cohen Digital
4/10/24
Muhammad Muteeb armaghan
, …
Jamshid KP
3
4/8/24
Trouble in deployment on RHEL 7
Dear Mike, I have rhel 7.x with the same GLIBC support problem on the client side. so I have to use
unread,
Trouble in deployment on RHEL 7
Dear Mike, I have rhel 7.x with the same GLIBC support problem on the client side. so I have to use
4/8/24
Jamshid KP
4/8/24
Velociraptor Supported Version for Redhat 7.x or oracle Linux 7.x
Dear Team, I am getting error when I try to install the latest and n-1 Velociraptor version in Oracle
unread,
Velociraptor Supported Version for Redhat 7.x or oracle Linux 7.x
Dear Team, I am getting error when I try to install the latest and n-1 Velociraptor version in Oracle
4/8/24
Paul Siess
, …
Mike Cohen
5
4/4/24
Stale & Duplicate devices
Please see this kb article https://docs.velociraptor.app/knowledge_base/tips/plugin_not_found/ On Fri
unread,
Stale & Duplicate devices
Please see this kb article https://docs.velociraptor.app/knowledge_base/tips/plugin_not_found/ On Fri
4/4/24