Endpoint forensics, ready to deploy.

A feed of Velociraptor VQL artifacts for IR and threat hunting: forensic collection + malware hunting via our YARA rules converted to VQL (the yara() function), ATT&CK-mapped. Three clear license tiers. Import into Velociraptor. DFIR bundle with the YARA pack.

460+
VQL artifacts
ATT&CK
every hunt mapped
YARA→VQL
in-house malware hunt
3 tiers
clear licensing

What we added recently

A living feed: here is the coverage added to it, dated.

  • +1 artefacts

Three tiers, one goal: IR.

Forensic artifacts

A base of collection & detection artifacts (event logs, registry, persistence, timeline, applications) for Windows, Linux and macOS. What you need to triage an incident from Velociraptor.

YARA→VQL malware hunt (maison)

The proprietary core: our in-house forged malware/tool YARA signatures, converted into Velociraptor artifacts that scan files via the yara() function, each artifact is self-contained (rule embedded), mapped to its ATT&CK technique. Hunt malware across the fleet, no rule files to deploy.

ATT&CK-mapped

Every hunting artifact carries its ATT&CK technique. You cover a technique, document your IR coverage, feed a report, not just a list of artifacts.

Self-contained (embedded rule)

Every hunting artifact embeds its YARA rule as a `type: yara` parameter, globs the disk then scans matches. Nothing to deploy alongside: import the artifact, run the hunt.

Licensing: 3 clear tiers

The aggregated forensics stays under its copyleft license (AGPL), isolated, redistributable with attribution. Our maison hunting artifacts are proprietary (EULA (c) CyberConsulting.fr, subscriber use). The permissive tier keeps its upstream license. You know exactly what’s what.

index.json + bundles

A normalized artifacts.json (name, platform, ATT&CK technique, license, tier), an index.json with the counts, and by-platform / by-technique / by-tier bundles. Filterable, scriptable, ready for Velociraptor import.

DFIR artifacts curated from open-source sources (the aggregated forensics stays under its AGPL copyleft license, isolated); our maison hunting artifacts are forged by converting our proprietary YARA rules to VQL (the yara() function) and are proprietary ((c) CyberConsulting.fr, EULA); a permissive tier rounds out coverage under its upstream license. Each ATT&CK-mapped, index.json + bundles. The curation, the YARA→VQL forge and the mapping are our value.

Anywhere Velociraptor runs.

Velociraptorartifact import, fleet-scale hunts
Offline collectorstandalone triage on an isolated host
Hunttargeted ATT&CK hunt + evidence collection
DFIR bundlecombined with the ThreatClaw YARA pack for IR

A DFIR pack with a real moat.

01
The maison YARA→VQL hunt

The moat: our proprietary YARA signatures become ready-to-hunt Velociraptor artifacts. Content you won’t find elsewhere, ATT&CK-mapped, self-contained.

02
License, tier by tier

Nothing fuzzy: the AGPL forensics is isolated under its license, the maison is proprietary (EULA), the permissive keeps its own. You know what you can redistribute and what stays yours.

03
ATT&CK-mapped

Hunting artifacts carry their ATT&CK technique, you drive your IR by tactic, not by artifact name, and you document coverage.

04
Bundle with YARA

Built as a complement to the ThreatClaw YARA pack: the same signatures, file-side (YARA) and fleet-scale endpoint-side (Velociraptor). One detection chain, two deployment points.

05
Ed25519-signed

The pack is signed; you verify its integrity before every deployment.

What is Velociraptor?

Velociraptor is the leading open-source platform for DFIR and remote threat hunting. You collect and hunt across endpoints via “artifacts” (YAML files of VQL queries). It’s the tool of IR/CERT teams. Our pack delivers curated, ATT&CK-mapped artifacts, ready to import.

What is YARA→VQL?

Velociraptor can scan files with YARA rules via its VQL yara() function. We take our proprietary malware YARA rules and generate, for each, a Velociraptor artifact that globs the disk and scans matches with the embedded rule. Result: hunting a malware across the fleet becomes an artifact to import, ATT&CK-mapped, with no rule files to deploy.

What licenses, and can I resell / MSSP?

The pack is a proprietary three-tier subscription, each tier labeled (see index.json and each artifact’s folder): the aggregated forensics tier stays under its copyleft license (AGPL), isolated, redistributable with attribution under AGPL; our maison hunting artifacts are proprietary ((c) CyberConsulting.fr, under EULA, internal use, not redistributable); the permissive tier keeps its upstream license. The curation, the YARA→VQL forge and the ATT&CK mapping are our value.

Does it combine with the YARA pack?

Yes, it’s built for it. The YARA pack covers file-side scanning; this Velociraptor pack deploys the same maison signatures endpoint-side, at fleet scale, as VQL artifacts. As a DFIR bundle you get one coherent detection chain: same intelligence, two deployment surfaces (file analysis + incident response).

Ready for your next investigation?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax
Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.