🦖Day 89 of the @velocidex #velociraptor #ArtifactsOfAutumn series
Artifact: Exchange.Server.Import.DetectRaptor
Author: @mgreen27, with content references to @svch0st and #Sigma.
Link: https://docs.velociraptor.app/exchange/artifacts/pages/detectraptor
----
DetectRaptor is a collection of publicly available Velociraptor detection content. Most content is managed by a series of CSV files and artifacts are automatically updated.
https://github.com/mgreen27/DetectRaptor
This artifact will import the latest DetectRaptor bundle into the current server.
----
DetectRaptor currently includes the following artifacts:
Windows.Detection.Applications Windows.Detection.BinaryRename
Windows.Detection.Evtx
Windows.Detection.MFT
Windows.Detection.NamedPipes
Windows.Detection.Webhistory
Windows.Detection.ZoneIdentifier
Server.StartHunts
----
Most of these artifacts contain content in CSV files that provide for bulk detection capability.
The CSVs can be updated as needed to add new detections.
The artifacts are generated from a VQL template, and the associated CSV via their own Python script.
----
The Server.StartHunts artifact is useful for kicking off hunts for the artifacts within the DetectRaptor hundle.
We can leverage the DetectRaptor bundle in a hunt or single client collection to cast a wide net, then review detection hits for items of interest.
----
That's it for now! Stay tuned to learn about more artifacts! 🦖
