Velociraptor
以查詢語言驅動的端點鑑識平台,能同時對上千台主機提問「你身上有沒有這個跡證」並在數分鐘內收到答案。A query-driven endpoint forensics platform that asks thousands of hosts "do you have this artefact" at once and answers within minutes.
這是什麼What it is
資安通報最常見的結尾是「請假設已遭入侵並進行盤查」。問題是——怎麼盤查? 對五台主機可以手動看,對五千台就不行了。
Velociraptor 解決的正是這個規模問題。它在端點上部署輕量代理程式,伺服器端用 VQL(Velociraptor Query Language,類 SQL 的查詢語言)對整個機群同時發問。要找的東西寫成查詢:某個雜湊值的檔案、某個登錄檔鍵值、某條排程工作、某個網路連線、瀏覽器歷史、Windows 事件記錄裡的特定模式。回應在數分鐘內彙整回來。
它也能做持續性的獵捕(hunt)與資料採集,把結果匯出給後續分析。內建大量社群維護的 artifact 定義,常見的鑑識項目不必自己從頭寫。
Security advisories routinely end with "assume compromise and hunt for evidence". The problem is — hunt how? Five hosts you can inspect by hand; five thousand you cannot.
Velociraptor addresses exactly that scale problem. A lightweight agent runs on endpoints, and the server queries the whole fleet at once using VQL (Velociraptor Query Language, a SQL-like language). Whatever you are looking for becomes a query: a file with a given hash, a registry key, a scheduled task, a network connection, browser history, a pattern in Windows event logs. Answers aggregate back within minutes.
It also runs continuous hunts and collection, exporting results for downstream analysis, and ships a large community-maintained library of artefact definitions so common forensic checks need not be written from scratch.
什麼時候用得上When to use it
- 通報後的全機群盤查:本期多則通報的處置建議都是「檢查有無非預期的檔案寫入、新增帳號、排程工作」——這正是一條 VQL 查詢就能對全機群完成的事
- 入侵範圍界定:確認某個跡證出現在哪些主機上,劃出受影響邊界
- 證據保全:在重灌之前把記憶體、日誌、檔案系統時間軸採集下來
- 持續獵捕:把已知的攻擊行為寫成 artifact,定期在機群中巡查
先從單一 artifact、單一測試群組開始,熟悉 VQL 之後再擴大範圍。
- Fleet-wide hunting after an advisory: several advisories this issue say to check for unexpected file writes, new accounts, and scheduled tasks — precisely what one VQL query answers across the whole fleet
- Scoping an intrusion: find which hosts carry a given artefact and draw the boundary
- Evidence preservation: collect memory, logs, and filesystem timelines before a machine is reimaged
- Continuous hunting: encode known attacker behaviour as artefacts and sweep the fleet on a schedule
Start with one artefact against one test group, then widen once VQL is familiar.
注意事項Caveats
授權為 AGPL-3.0,具網路著作傳染性。自用與內部部署沒有問題,但若您計畫將它包裝成對外提供的服務,須先確認合規義務——這一點在商業評估階段就要釐清。
技術面則要注意:代理程式具備讀取端點上幾乎所有資料的能力,等同一個高權限的存取管道,其伺服器本身就是高價值目標,存取控制與稽核要比照特權系統辦理。大範圍採集也會產生可觀的網路流量與儲存量,導入前先估算。
Licensed AGPL-3.0, which carries network copyleft. Internal use and self-hosted deployment are fine, but if you plan to wrap it into a service offered to others, settle the compliance obligations first — resolve this during commercial evaluation, not after.
Technically: the agent can read almost anything on an endpoint, making it a high-privilege access path, so the server itself is a high-value target and deserves the access control and auditing you give privileged systems. Broad collection also generates substantial network traffic and storage; size it before rollout.
安裝Install
brew install velociraptor
# 或自 GitHub Releases 取得單一執行檔(無相依套件)
# or grab the single static binary from GitHub Releases
快速上手Quick start
# 以單機模式啟動,開啟本機介面熟悉操作
velociraptor gui
# 不部署伺服器,直接在單一主機上採集
velociraptor artifacts collect Windows.Sys.Users
# 列出可用的 artifact 定義
velociraptor artifacts list