The CLI gives you access to the full range of Velociraptor’s features from your terminal. Whether you are running VQL queries, managing artifacts, mounting disk images or collection containers, or configuring the server, the CLI gives you a direct way to work with Velociraptor without the graphical interface.
Browse the command groups listed below to find the documentation for
each command and its subcommands. You can also run
velociraptor --help from your terminal for a quick overview of
the available commands.
Manipulate ACLs (access control lists).
Commands for working with artifacts
Build an offline collector
Commands for working with the config
Create a deaddisk configuration
Run filesystem commands.
Mount collection containers on folders.
Run VQL queries on the command line.
Manipulate the Velociraptor server service on Windows.
Manipulate the Velociraptor client service on Windows and macOS.
Commands for working with the tools inventory.
Commands for working with users
All other commands not previously covered.