Starting with Velociraptor Incident Response

  Рет қаралды 19,172

DFIRScience

DFIRScience

Күн бұрын

Velociraptor IR (Incident Response) is an open-source endpoint visibility tool. You can monitor many clients across networks, conduct hunts on all clients, or define subsets of relevant systems based on tags. Use Velociraptor IR for client monitoring, threat hunting, response tasks, and digital forensic triage.
We talk about how to set up Velociraptor IR in a test environment to familiarize you with its layout and features. Specifically, how to add, monitor, and hunt with clients.
Thank you to our Members and Patrons, but especially to TheRantingGeek, Kuek Dekuek, Wilson L, Steven Lorenz, Steffen Luithardt, pjs, Lorie Hermesdorf, Carlos E Gallo Monteiro, Roman! Thank you so much!
00:00 Velociraptor Incident Response
00:44 WARNING
01:02 Downloading Velociraptor IR
02:36 Verify Velociraptor IR binaries (IMPORTANT)
03:17 Download Velociraptor IR developer key
04:53 Setting binary run permissions in Linux
05:32 Velociraptor IR first run
06:33 Creating a client a server config
12:42 Client config file - set server local IP address
13:36 Copy client config to clients
14:01 Start the Velociraptor IR server GUI
14:54 Velociraptor IR interface first run
15:25 Start and enroll the Velociraptor IR client
18:17 Velociraptor IR search clients
20:04 Velociraptor IR add client labels
21:45 Velociraptor IR client management interface
22:01 Velociraptor IR client - Interrogate
22:22 Velociraptor IR client - Virtual File System (VFS)
24:34 Velociraptor IR client - Collected
24:57 A quick look at Velociraptor data store structure
26:14 Velociraptor IR client - Quarantine Host
26:51 Velociraptor IR client - Overview
26:55 Velociraptor IR client - VQL Drilldown
27:11 Velociraptor IR client - Shell
28:05 Left Menu Feature Tour
28:20 Hunts
28:35 Create a hunt
30:46 Select hunt artifacts
31:01 Velociraptor IR Artifact Exchange
31:33 Linux.Search.FileFinder
32:41 Configure artifact parameters
33:18 Regular expressions
36:34 Specify Resources
37:21 Review
37:31 Launch hunt
38:10 View hunt results
39:59 View/Edit Artifacts
40:48 Server Events
41:33 Create a new server monitor
42:07 Server Artifacts
42:13 Notebooks
43:03 Host Information
43:13 Host Specific Options
43:26 Host Monitoring
43:36 Create a new client monitor
46:01 Main Features Review
46:49 Where to find more resources
48:17 Thank you for your support!
🚀 Full Digital Forensic Courses → learn.dfir.science
Links:
* Velociraptor IR Docs: docs.velociraptor.app/
* Download Velociraptor IR: github.com/Velocidex/velocira...
* Velociraptor IR Blog: velociraptor.velocidex.com
Related book:
* Incident Response in the Age of Cloud (amzn.to/3QsY7cf)
* Cybersecurity Masters Guides (amzn.to/3B207CL)
#incidentresponse #forensics #velociraptor #dfir #infosec
010001000100011001010011011000110110100101100101011011100110001101100101
Get more Digital Forensic Science
👍 Subscribe → bit.ly/2Ij9Ojc
❤️ YT Member → bit.ly/DFIRSciMember
❤️ Patreon → / dfirscience
🕸️ Blog → DFIR.Science
🤖 Code → github.com/DFIRScience
🐦 Follow → / dfirscience
📰 DFIR Newsletter → bit.ly/DFIRNews
010100110111010101100010011100110110001101110010011010010110001001100101
Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are doing.

Пікірлер: 8
@mohamedaltairy3570
@mohamedaltairy3570 Жыл бұрын
Outstanding walkthrough, can’t wait for the rest of the series in addition to explanation on implementation and operation within a working environment.keep the awesome work up, folks you are a true legends.
@NetworkITguy
@NetworkITguy Жыл бұрын
A great presentation! Thank you.
@DFIRScience
@DFIRScience Жыл бұрын
Glad it was helpful!
@NetSeChef
@NetSeChef Жыл бұрын
Thank you this was awesome! Assuming you enable port forwarding for clients outside of your network, which ip should you use in the configuration.yml?
@arsalananwar8265
@arsalananwar8265 Жыл бұрын
Nice information
@MohamedAltairy
@MohamedAltairy Жыл бұрын
how to perform installation of configuration file on windows machine , Please ?
@christophertharp7763
@christophertharp7763 5 ай бұрын
if your server is linux and your client is windows, can you create the client config file on the linux server and copy the config file to the windows device and execute the windows binaries with the linux built client config file/
@NeutralHumanKing
@NeutralHumanKing Жыл бұрын
how can i buy your course?
Live Incident Response with Velociraptor
1:09:18
Recon InfoSec
Рет қаралды 24 М.
Topic  01   Velociraptor Installation and Overview
2:14:03
Velocidex Enterprises
Рет қаралды 41 М.
마시멜로우로 체감되는 요즘 물가
00:20
진영민yeongmin
Рет қаралды 33 МЛН
DEFINITELY NOT HAPPENING ON MY WATCH! 😒
00:12
Laro Benz
Рет қаралды 59 МЛН
Самый Молодой Актёр Без Оскара 😂
00:13
Глеб Рандалайнен
Рет қаралды 10 МЛН
Gym belt !! 😂😂  @kauermtt
00:10
Tibo InShape
Рет қаралды 14 МЛН
Incident Response: Azure Log Analysis
19:15
John Hammond
Рет қаралды 64 М.
how did I NOT know about this?
23:06
NetworkChuck
Рет қаралды 902 М.
Introduction to Memory Forensics with Volatility 3
32:00
DFIRScience
Рет қаралды 62 М.
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 94 М.
Secure Your Self-Hosted Network with Wazuh
21:49
Techdox
Рет қаралды 95 М.
Investigating WMI Attacks
1:00:43
SANS Digital Forensics and Incident Response
Рет қаралды 26 М.
SOC 101: Real-time Incident Response Walkthrough
12:30
Exabeam
Рет қаралды 194 М.
Mass Digital Forensics & Incident Response with Velociraptor
34:54
John Hammond
Рет қаралды 14 М.
Data Artifacts, Analysis Results and Reporting in Autopsy 4.19+
33:54
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 59 МЛН
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 4,3 МЛН
Что делать если в телефон попала вода?
0:17
Лена Тропоцел
Рет қаралды 2,4 МЛН
Телефон-електрошокер
0:43
RICARDO 2.0
Рет қаралды 1,3 МЛН