Welcome to velociraptor_artifacts repository! We made these tools to help with incidents. This collection is a set of carefully developed artifacts designed to improve digital forensics and incident response procedures by extracting important evidence data. Our team recognized the need for specific artifacts that does not exist on Velociraptor tool and we developed this collection, It's our way of trying to fill a gap and make things a bit easier for everyone.
-
Artifacts: Each folder in this repository represents a Velociraptor artifact, composed of one or more VQL files tailored for the extraction process.
-
Metadata:
- name: Name of the artifact example
Windows.Forensics.MRU
- author: Author's name we use email address
- description: Brief description of the artifact and its significance in incident response.
- name: Name of the artifact example
- Clone this repository to your local machine.
- Navigate to the desired artifact folder.
- Review the VQL file(s) for the artifact's specific extraction process then imported to Velociraptor
This project is licensed under the Apache-2.0 license.
We would like to express our gratitude to the Velociraptor community for their support and inspiration.