Endpoint forensics, ready to deploy.
A feed of Velociraptor VQL artifacts for IR and threat hunting: forensic collection + malware hunting via our YARA rules converted to VQL (the yara() function), ATT&CK-mapped. Three clear license tiers. Import into Velociraptor. DFIR bundle with the YARA pack.
What we added recently
A living feed: here is the coverage added to it, dated.
- +1 artefacts
Three tiers, one goal: IR.
A base of collection & detection artifacts (event logs, registry, persistence, timeline, applications) for Windows, Linux and macOS. What you need to triage an incident from Velociraptor.
The proprietary core: our in-house forged malware/tool YARA signatures, converted into Velociraptor artifacts that scan files via the yara() function, each artifact is self-contained (rule embedded), mapped to its ATT&CK technique. Hunt malware across the fleet, no rule files to deploy.
Every hunting artifact carries its ATT&CK technique. You cover a technique, document your IR coverage, feed a report, not just a list of artifacts.
Every hunting artifact embeds its YARA rule as a `type: yara` parameter, globs the disk then scans matches. Nothing to deploy alongside: import the artifact, run the hunt.
The aggregated forensics stays under its copyleft license (AGPL), isolated, redistributable with attribution. Our maison hunting artifacts are proprietary (EULA (c) CyberConsulting.fr, subscriber use). The permissive tier keeps its upstream license. You know exactly what’s what.
A normalized artifacts.json (name, platform, ATT&CK technique, license, tier), an index.json with the counts, and by-platform / by-technique / by-tier bundles. Filterable, scriptable, ready for Velociraptor import.
DFIR artifacts curated from open-source sources (the aggregated forensics stays under its AGPL copyleft license, isolated); our maison hunting artifacts are forged by converting our proprietary YARA rules to VQL (the yara() function) and are proprietary ((c) CyberConsulting.fr, EULA); a permissive tier rounds out coverage under its upstream license. Each ATT&CK-mapped, index.json + bundles. The curation, the YARA→VQL forge and the mapping are our value.
Anywhere Velociraptor runs.
A DFIR pack with a real moat.
The moat: our proprietary YARA signatures become ready-to-hunt Velociraptor artifacts. Content you won’t find elsewhere, ATT&CK-mapped, self-contained.
Nothing fuzzy: the AGPL forensics is isolated under its license, the maison is proprietary (EULA), the permissive keeps its own. You know what you can redistribute and what stays yours.
Hunting artifacts carry their ATT&CK technique, you drive your IR by tactic, not by artifact name, and you document coverage.
Built as a complement to the ThreatClaw YARA pack: the same signatures, file-side (YARA) and fleet-scale endpoint-side (Velociraptor). One detection chain, two deployment points.
The pack is signed; you verify its integrity before every deployment.
What is Velociraptor?
Velociraptor is the leading open-source platform for DFIR and remote threat hunting. You collect and hunt across endpoints via “artifacts” (YAML files of VQL queries). It’s the tool of IR/CERT teams. Our pack delivers curated, ATT&CK-mapped artifacts, ready to import.
What is YARA→VQL?
Velociraptor can scan files with YARA rules via its VQL yara() function. We take our proprietary malware YARA rules and generate, for each, a Velociraptor artifact that globs the disk and scans matches with the embedded rule. Result: hunting a malware across the fleet becomes an artifact to import, ATT&CK-mapped, with no rule files to deploy.
What licenses, and can I resell / MSSP?
The pack is a proprietary three-tier subscription, each tier labeled (see index.json and each artifact’s folder): the aggregated forensics tier stays under its copyleft license (AGPL), isolated, redistributable with attribution under AGPL; our maison hunting artifacts are proprietary ((c) CyberConsulting.fr, under EULA, internal use, not redistributable); the permissive tier keeps its upstream license. The curation, the YARA→VQL forge and the ATT&CK mapping are our value.
Does it combine with the YARA pack?
Yes, it’s built for it. The YARA pack covers file-side scanning; this Velociraptor pack deploys the same maison signatures endpoint-side, at fleet scale, as VQL artifacts. As a DFIR bundle you get one coherent detection chain: same intelligence, two deployment surfaces (file analysis + incident response).
Ready for your next investigation?
Annual subscription. Instant key. Cancel anytime.