Velociraptor overview and deployment
Aside from commercial platforms, there are open source tools that incident response teams can use that provide at least some of the functionality found in EDR platforms. One of these is Velociraptor. This tool uses a combination of a central server that endpoint agents connect to, as seen in Figure 7.1. These endpoint agents, called clients, manage the search of artifacts on remote systems. This places the load for searching and evidence acquisition on the endpoint, reducing the load on the server, and allowing for concurrent searches across multiple remote clients.
Velociraptor documentation
This chapter can only cover a limited portion of the features of Velociraptor. For a full breakdown of the features, including additional digital forensic use cases, review the Velociraptor documentation at https://docs.velociraptor.app/.
Figure 7.1 – Velociraptor setup
To demonstrate some of the functionality of Velociraptor...