Overview
There is no way we can cover all of the capabilities Velociraptor offers in the time today!
- This workshop will give a taste to how modern threat hunting is done
at scale
- We will look at some of the common scenarios and attacks and some of
the modern detection techniques we can employ to find these.
- This workshop will be a "Follow Along" workshop - please try these
exercises on your own machine!
Prerequisites
In order to follow along with this workshop you will need to use a
windows VM with administrator level access. You can grab a free VM
from Microsoft
- Please ensure your VM has .NET version 4+ with MSBuild -
dotNetFx40_Full_x86_x64.exe
- You can also get the latest Velociraptor for Windows Binary from the
GitHub releases page
- Exercise setup scripts if preferred