Pretty cool/convenient #velociraptor 🦖 feature, I didn't know: offline collection.
Allows to collect artifacts from "air-gapped" systems, or simply, systems with no connectivity to your Velociraptor Server.
from the backend, select the artifacts you want to collect and create the collection binaryrun the binary on the subject device --> it will collect and put the artifacts in a ZIPget the ZIP back to the analysis machine and import the artifacts to the Velociraptor backendhttps://docs.velociraptor.app/docs/deployment/offline_collections/
#dfir