Lab 1 of 6

GUI mode and lab setup

Run Velociraptor in GUI mode and import additional artifact content.

2023 workshop archive · Version details

Migrated from the original Notion material. Commands and examples are preserved from 2023 and have not been retested against current releases. Screenshots and lab behaviour may differ with newer versions.

On this page

Objective #

This lab is a guided walk-through for running Velociraptor in GUI mode.

GUI mode will be used throughout the workshop.

We also walk through importing additional content into Velociraptor.

The Velociraptor GUI is configured to open automatically upon boot, but the credentials are available below:

Dependencies #

Windows 10+ VM with administrator level access.

  • UEFI enabled for UEFI use cases (detail later)

Internet access if you would like to do content import.

Tasks #

Task 1 · Download and run Velociraptor in GUI mode

  1. Download latest velociraptor release

    0.7.0-3 at time of writing.

    https://github.com/Velocidex/velociraptor/releases

GUI mode and lab setup: Download and run Velociraptor in GUI mode (01)
Select screenshot to view full size in a new tab.

Please copy the downloaded exe to the desktop and rename to velociraptor.exe

  1. Open cmd.exe as administrator and cd to your desktop. Run velociraptor.exe -h to scope options via help

GUI mode and lab setup: Download and run Velociraptor in GUI mode (02)
Select screenshot to view full size in a new tab.

Many velociraptor features are available via the cli and at any level you can view help to understand what switches are available.

As we are running GUI mode run: velociraptor.exe gui -h

GUI mode and lab setup: Download and run Velociraptor in GUI mode (03)
Select screenshot to view full size in a new tab.

By default Velociraptor will use a datastore in the temp folder. This may not be desired as the OS may purge temp folders and we may loose our work. We can use the datastore switch to specify a path.

  1. Create VRdata folder and run Velociraptor

mkdir VRdata

velociraptor.exe gui --datastore=./VRdata -v

GUI mode and lab setup: Download and run Velociraptor in GUI mode (04)
Select screenshot to view full size in a new tab.

Running -v enables us to review verbose mode in Stdout. Take a moment to scroll up through the output to see what the velociraptor gui mode is doing.

By default a web browser will also load and automatically log into the local velociraptor instance.

NOTE: In windows 11 this feature was not working with Edge only default installs and manual load is required.

Open a browser and goto:

GUI mode and lab setup: Download and run Velociraptor in GUI mode (05)
Select screenshot to view full size in a new tab.

  1. Explore GUI and follow demo.

Ensure you familiarise yourself with items important for detection development.

  • VFS
  • Collection
  • Artifacts
  • Notebook

Task 2 · Import additional content

  1. Open server collection view and run Server.Import.ArtifactExchange

GUI mode and lab setup: Import additional content (06)
Select screenshot to view full size in a new tab.

GUI mode and lab setup: Import additional content (07)
Select screenshot to view full size in a new tab.

We can configure a prefix to add to each imported artifact, but in this case we will keep as default.

GUI mode and lab setup: Import additional content (08)
Select screenshot to view full size in a new tab.

When imported you can see all artifacts have this prefix.

GUI mode and lab setup: Import additional content (09)
Select screenshot to view full size in a new tab.

You should now have several Exchange prefixed artifacts in your artifact view.

GUI mode and lab setup: Import additional content (10)
Select screenshot to view full size in a new tab.

We will use several of these artifacts later 🙂

  1. Run the same import process for Exchange.Server.Import.DetectRaptor

GUI mode and lab setup: Import additional content (11)
Select screenshot to view full size in a new tab.

GUI mode and lab setup: Import additional content (12)
Select screenshot to view full size in a new tab.