High Definition Standard Definition Theater
Video id : EA40rztSOd4
ImmersiveAmbientModecolor: #fafaf9 (color 1)
Video Format : 22 (720p) openh264 ( https://github.com/cisco/openh264) mp4a.40.2 | 44100Hz
Audio Format: Opus - Normalized audio
PokeTubeEncryptID: 65e4ca217d47ebee61a4c0215ff242deb674aad5ab37855e89fcb5e3439e74e6f581729035586150a88b675f30c5e407
Proxy : eu-proxy.poketube.fun - refresh the page to change the proxy location
Date : 1715643450730 - unknown on Apple WebKit
Mystery text : RUE0MHJ6dFNPZDQgaSAgbG92ICB1IGV1LXByb3h5LnBva2V0dWJlLmZ1bg==
143 : true
Starting with Velociraptor Incident Response
Jump to Connections
16,166 Views β€’ Sep 13, 2022 β€’ Click to toggle off description
Velociraptor IR (Incident Response) is an open-source endpoint visibility tool. You can monitor many clients across networks, conduct hunts on all clients, or define subsets of relevant systems based on tags. Use Velociraptor IR for client monitoring, threat hunting, response tasks, and digital forensic triage.

We talk about how to set up Velociraptor IR in a test environment to familiarize you with its layout and features. Specifically, how to add, monitor, and hunt with clients.

Thank you to our Members and Patrons, but especially to TheRantingGeek, Kuek Dekuek, Wilson L, Steven Lorenz, Steffen Luithardt, pjs, Lorie Hermesdorf, Carlos E Gallo Monteiro, Roman! Thank you so much!

00:00 Velociraptor Incident Response
00:44 WARNING
01:02 Downloading Velociraptor IR
02:36 Verify Velociraptor IR binaries (IMPORTANT)
03:17 Download Velociraptor IR developer key
04:53 Setting binary run permissions in Linux
05:32 Velociraptor IR first run
06:33 Creating a client a server config
12:42 Client config file - set server local IP address
13:36 Copy client config to clients
14:01 Start the Velociraptor IR server GUI
14:54 Velociraptor IR interface first run
15:25 Start and enroll the Velociraptor IR client
18:17 Velociraptor IR search clients
20:04 Velociraptor IR add client labels
21:45 Velociraptor IR client management interface
22:01 Velociraptor IR client - Interrogate
22:22 Velociraptor IR client - Virtual File System (VFS)
24:34 Velociraptor IR client - Collected
24:57 A quick look at Velociraptor data store structure
26:14 Velociraptor IR client - Quarantine Host
26:51 Velociraptor IR client - Overview
26:55 Velociraptor IR client - VQL Drilldown
27:11 Velociraptor IR client - Shell
28:05 Left Menu Feature Tour
28:20 Hunts
28:35 Create a hunt
30:46 Select hunt artifacts
31:01 Velociraptor IR Artifact Exchange
31:33 Linux.Search.FileFinder
32:41 Configure artifact parameters
33:18 Regular expressions
36:34 Specify Resources
37:21 Review
37:31 Launch hunt
38:10 View hunt results
39:59 View/Edit Artifacts
40:48 Server Events
41:33 Create a new server monitor
42:07 Server Artifacts
42:13 Notebooks
43:03 Host Information
43:13 Host Specific Options
43:26 Host Monitoring
43:36 Create a new client monitor
46:01 Main Features Review
46:49 Where to find more resources
48:17 Thank you for your support!

πŸš€ Full Digital Forensic Courses β†’ learn.dfir.science/

Links:
* Velociraptor IR Docs: docs.velociraptor.app/
* Download Velociraptor IR: github.com/Velocidex/velociraptor/releases
* Velociraptor IR Blog: velociraptor.velocidex.com/

Related book:
* Incident Response in the Age of Cloud (amzn.to/3QsY7cf)
* Cybersecurity Masters Guides (amzn.to/3B207CL)

#incidentresponse #forensics #velociraptor #dfir #infosec
010001000100011001010011011000110110100101100101011011100110001101100101
Get more Digital Forensic Science
πŸ‘ Subscribe β†’ bit.ly/2Ij9Ojc
❀️ YT Member β†’ bit.ly/DFIRSciMember
❀️ Patreon β†’ www.patreon.com/dfirscience

πŸ•ΈοΈ Blog β†’ DFIR.Science/
πŸ€– Code β†’ github.com/DFIRScience
🐦 Follow β†’ www.twitter.com/DFIRScience
πŸ“° DFIR Newsletter β†’ bit.ly/DFIRNews
010100110111010101100010011100110110001101110010011010010110001001100101

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are
Metadata And Engagement

Views : 16,166
Genre: Science & Technology
Date of upload: Sep 13, 2022 ^^


Rating : 4.944 (4/281 LTDR)
RYD date created : 2024-03-28T02:33:56.463225Z
See in json
Tags
Connections
Nyo connections found on the description ;_; report a issue lol

YouTube Comments - 8 Comments

Top Comments of this video!! :3

@mohamedaltairy3570

1 year ago

Outstanding walkthrough, can’t wait for the rest of the series in addition to explanation on implementation and operation within a working environment.keep the awesome work up, folks you are a true legends.

1 |

@NetworkITguy

1 year ago

A great presentation! Thank you.

1 |

@arsalananwar8265

1 year ago

Nice information

|

@NetSeChef

1 year ago

Thank you this was awesome! Assuming you enable port forwarding for clients outside of your network, which ip should you use in the configuration.yml?

|

@MohamedAltairy

1 year ago

how to perform installation of configuration file on windows machine , Please ?

|

@christophertharp7763

2 months ago

if your server is linux and your client is windows, can you create the client config file on the linux server and copy the config file to the windows device and execute the windows binaries with the linux built client config file/

|

@NeutralHumanKing

1 year ago

how can i buy your course?

|

Go To Top