## VQL - Velociraptor's magic sauce Rather than having specific analysis modules, VQL allows generic capabilities to be combined in novel creative ways * NTFS/MFT/USN/Glob file system analysis * File parsers - Grok, Sqlite etc * Built in powerful parser framework for novel binary parsers --- ## Velociraptor Artifacts Velociraptor comes with a large number of artifact types * Client Artifacts run on the endpoint * Client Event artifacts monitor the endpoint * Server Artifacts run on the server * Server Event artifacts monitor for events on the server. --- ## Velociraptor Query Language Using a query language we can string together different forensic capabilities to create novel analysis The Power of Open source! The [Velociraptor artifact exchange](https://docs.velociraptor.app/exchange/) is a place for the community to publish useful VQL artifacts for reuse --- ## The Artifact Exchange data:image/s3,"s3://crabby-images/35dc5/35dc5dc242a8dd50d9782f3426ea47265a33f69f" alt="" --- ## Automatically import Exchange data:image/s3,"s3://crabby-images/15aaa/15aaa9596fd69978bf0074d9a8d3647e697d630c" alt="" # Searching for files ## Let's start at the beginning…. --- ## Manually importing artifact packs You can manually upload an artifact pack as well (A zip file containing artifact definitions). data:image/s3,"s3://crabby-images/4b519/4b5198b3438697f76fadcad978cea5924e541e8e" alt="" --- ## Finding files DFIR is often about finding files on the endpoint * Filename is sometimes an indicator * Word documents in a temp folder may contain macros * Sometimes we need to filter by file content * File has signature of malicious macro/script --- ## Windows.Search.FileFinder
* Glob based * Time filters * Yara for Content
data:image/s3,"s3://crabby-images/9c6ba/9c6bae234c4a6fa7aade32a31a0caf70e74a8c2f" alt=""
--- ## Exercise Find all executables in the user's home directory