Velociraptor artifact "ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793" (CLIENT type): it walks the host's file system and scans it with an embedded YARA rule. Run it on the affected host(s) — this is the DFIR collection step, self-contained (no external rule to deploy).
For each file surfaced by the artifact: