MSI package

191 views
Skip to first unread message

Carlos Cajigas

unread,
Jun 2, 2020, 7:16:18 PM6/2/20
to velociraptor-discuss
Folks, Good morning.  
I see that Velociraptor 0.4.4 has been released, but no MSI is available for this version as well as version 0.4.3.  
Does anyone know if releasing a signed MSI will be released again?
Thanks
Carlos Cajigas

--

Carlos Cajigas
MSc, GCFA, GCFE, EnCE, 
CCPA, CCLO, CFCE, ACE
www.mashthatkey.com
Twitter: @carlos_cajigas

Mike Cohen

unread,
Jun 2, 2020, 9:32:23 PM6/2/20
to Carlos Cajigas, velociraptor-discuss
Hi Carlos,
I am happy to release an MSI - I was just wondering how useful it is? We typically always build out own MSI with the scripts in the docs/wix/ directory (using build_custom.bat) because it packages the config file with the binary in the same MSI and makes it much easier to actually deploy.

Do you find that the previously released MSI was useful? Since we could not distribute the config file, previously you need to place the config file separately into the c:\program files\velociraptor\ directory and this seems more complex than just including it. Is it the MSI signing which makes a difference to your deployment processes?

Thanks
Mike


On Tue, 2020-06-02 at 23:16 +0000, Carlos Cajigas wrote:
Folks, Good morning.  
I see that Velociraptor 0.4.4 has been released, but no MSI is available for this version as well as version 0.4.3.  
Does anyone know if releasing a signed MSI will be released again?
Thanks
Carlos Cajigas

-- 
Mike Cohen
Digital Paleontologist

Velocidex Enterprises



Carlos Cajigas

unread,
Jun 2, 2020, 11:03:50 PM6/2/20
to velocirapt...@googlegroups.com
Hi Mike,
I guess I just got used to installing via the distributed MSI, and it is easy for testing.
I guess I just now have to get used to creating my own.
Thanks
--
Carlos Cajigas, CTO
www.CovertBitForensics.com

Mike Cohen

unread,
Jun 2, 2020, 11:15:52 PM6/2/20
to Carlos Cajigas, velocirapt...@googlegroups.com
If you just want to upgrade an existing testing deployment you can just stop the service:

sc stop velociraptor

then copy the new binary over the top of the old one and restart the service

sc start velociraptor

The MSI just places the binaries in the c:\program files\velociraptor directory and creates a service.

You can also use this procedure to copy the windows binary built at each commit point from the ci pipeline.

Thanks
Mike

Eric

unread,
Jun 3, 2020, 9:18:20 AM6/3/20
to velociraptor-discuss
Mike,

I just wanted to note that I find the signed MSI incredibly useful as it simplifies the deployment process for our use case. Signing the MSI would require us to involve another area in the deployment process as we are not setup to sign. I am concerned with AV flagging an unsigned MSI with many of our own tools. 

Thanks,
Eric

Ryan Brisbin

unread,
Jun 3, 2020, 11:02:25 AM6/3/20
to Eric, velociraptor-discuss
I like using the msi as well.  

--
You received this message because you are subscribed to the Google Groups "velociraptor-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to velociraptor-dis...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/velociraptor-discuss/296bd1e8-32ce-46ef-a72b-2d145c700271%40googlegroups.com.

Mike Cohen

unread,
Jun 3, 2020, 6:53:52 PM6/3/20
to Ryan Brisbin, Eric, velociraptor-discuss
Thanks everyone for your feedback! 

Excellent - we will continue publishing MSI packages then. I just uploaded an MSI for 0.4.4

Thanks again
Mike

martinl...@gmail.com

unread,
Apr 8, 2021, 12:39:19 AM4/8/21
to velociraptor-discuss
Hi all,

I've always used the MSI to install Velociraptor, but I'm not seeing any MSI in the latest artifacts on Github. Are MSIs no longer provided? If so, are there instructions anywhere on how to do it manually?

Thanks,
Martin. 

Mike Cohen

unread,
Apr 8, 2021, 12:43:16 AM4/8/21
to martinl...@gmail.com, velociraptor-discuss
Yes instructions are here for building your own MSI

But MSI are still distributed for the full releases (I expected release candidates to be changing fast so I did not build an msi for it). When the 0.5.8-rc2 qualifies I will make a proper 0.5.8 release (with an msi) and shortly after promote the 0.5.9 to an RC.

Thanks
Mike


Mike Cohen 
Digital Paleontologist, 
Velocidex Enterprises
M  ‭+61 470 238 491‬ 
mi...@velocidex.com 


--
You received this message because you are subscribed to the Google Groups "velociraptor-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to velociraptor-dis...@googlegroups.com.

martinl...@gmail.com

unread,
Apr 8, 2021, 12:45:18 AM4/8/21
to velociraptor-discuss
Ah, that makes sense. Thanks for clearing that up :-)
Reply all
Reply to author
Forward
0 new messages