#velociraptor — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #velociraptor, aggregated by home.social.
-
----------------
🛠️ Tool
===================Velociraptor Skills is a public GitHub repository (ig-labs/velociraptor-skills) providing reusable Codex skills and DFIR tooling for Velociraptor operations. It covers setup, collection, hunting, and host analysis workflows.
Key Features
The repository includes eight distinct skills:
• prep-dfir-tools - prepares DFIR tooling environment
• velociraptor-artifact-selection - artifact selection guidance
• velociraptor-collection - evidence collection workflows
• velociraptor-engagement-setup - engagement configuration
• velociraptor-host-analysis - host-level forensic analysis
• velociraptor-hunting - hunt-based detection operations
• velociraptor-live-api-client - live API interaction
• velociraptor-mapped-client - mapped evidence handlingA shared ./vraptor runtime supports all skills, along with bounded custom-agent templates and installation helpers.
Technical Implementation
The default setup connects to an existing live Velociraptor server and uses the OpenAI API for analysis. Prerequisites include Python 3.11+, Git, a server administrator's API-client YAML, and an OpenAI API key. Credentials are stored outside the checkout directory.
Multiple server connections are supported within a single installation. Each server gets its own reference name and API-client YAML path. The --server-profile flag selects the connection per command.
For live-remote mode, the setup command vraptor setup start --mode live-remote --id ir1234 --server-profile "<SERVER REFERENCE>" handles server maintenance or hunt review without requiring a hostname or visible client.
Codex and Claude Code Integration
Skills are linked separately via ./utils/link-codex-skills.sh for Codex and ./utils/link-claude-skills.sh for Claude Code. The linking creates symlinks, so the checkout must remain available. Existing symlinks are updated; real files are preserved and reported as conflicts.
Limitations
Remote API access requires no local Velociraptor binary, SSH connection, or Codex login. However, offline checks do not prove live authentication. Explicit connection and AI tests are documented in the installation guide. The repository includes a public release review covering import scope, sanitization, and validation results.
The --no-configure flag skips the setup wizard during upgrades, and --no-path handles dependency-only installation or CI environments.