Playbooks

Velociraptor is an incredibly powerful tool, but sometimes it is hard to know where to start. This page aims to help newcomers to Velociraptor by presenting a set of playbooks to use when faced with certain tasks.

  • Preserving Forensic Evidence
  • A compromised endpoint is likely to be destroyed. You want to preserve raw files until you have an opportunity to analyse them later.

  • Triaging Logs
  • An endpoint is suspected of being compromised but you dont know exactly what happened. You want to get an initial idea by examining the logs on the actual endpoint.