Endpoint visibility and collection tool for host-based state information and incident response
Other
- Go
- JavaScript
- CSS

About Velociraptor
Velociraptor is an endpoint visibility and collection tool that pulls host-based state information from machines across a fleet. It targets digital forensics, endpoint security, inventory management, and incident response, querying hosts with the Velociraptor Query Language (VQL).
VQL artifacts define exactly what to collect, from running processes and registry keys to files and event logs. Built-in artifacts cover common investigations, the Artifact Exchange adds community-contributed ones, and a web GUI drives hunts and reviews the results that come back.
Written in Go, it ships as a single binary for Windows, Linux, and macOS, so the same executable acts as server, agent, or standalone collector. That makes it quick to deploy for live response or to sweep thousands of endpoints at once.
Key features
- Collect host-based state information with VQL queries
- Built-in artifacts for common collection use cases
- Artifact Exchange for additional community artifacts
- GUI for working with collected endpoint data
- Binaries for Windows, Linux, and macOS
Details
- First released
- 2018
- Platforms
- Windows · macOS · Linux
- Language
- Golang
- Collections
- VQL artifacts
- Distribution
- Single binary
- Deployment
- Self-hosted
