ThreatClaw · Investigation Playbook

DFIR collection: ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793

VelociraptorRule ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793T1068
  1. Deploy the collection artifact

    Velociraptor artifact "ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793" (CLIENT type): it walks the host's file system and scans it with an embedded YARA rule. Run it on the affected host(s) — this is the DFIR collection step, self-contained (no external rule to deploy).

  2. Triage the matches

    For each file surfaced by the artifact:

    • SHA256 hash, full path, creation date
    • Process that wrote it; was it executed afterwards?
    • Pivot to the EDR and the host's process logs