Files
Anthropic-Cybersecurity-Skills/skills/fleet-hunting-with-velociraptor/references/api-reference.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

75 lines
2.5 KiB
Markdown

# Velociraptor Command and VQL Reference
The same `velociraptor` binary is server, client, and CLI. Behavior depends on the subcommand and `--config`.
## Core subcommands
| Command | Description |
|---------|-------------|
| `velociraptor config generate` | Print a default server config to stdout |
| `velociraptor config generate -i` | Interactive config wizard |
| `velociraptor --config server.config.yaml config client` | Derive client config |
| `velociraptor --config server.config.yaml user add <name> --role administrator` | Create GUI admin |
| `velociraptor --config server.config.yaml frontend -v` | Start server frontend + GUI |
| `velociraptor gui` | All-in-one local lab (server + frontend + local client) |
| `velociraptor --config client.config.yaml client -v` | Run as agent |
| `velociraptor --config client.config.yaml service install` | Install agent service (Windows) |
| `velociraptor query "<VQL>"` | Run an ad-hoc VQL query |
| `velociraptor artifacts list` | List artifacts |
| `velociraptor artifacts collect <Name> --output results.zip` | Collect an artifact locally |
| `velociraptor artifacts show <Name>` | Show an artifact definition |
## Useful global flags
| Flag | Purpose |
|------|---------|
| `--config <file>` | Path to config YAML |
| `-v` / `--verbose` | Verbose logging |
| `-q` | Alias usage with `query` |
| `--format json` | Output query results as JSON |
## Common VQL plugins (data sources)
| Plugin | Returns |
|--------|---------|
| `pslist()` | Running processes (Pid, Name, CommandLine, ...) |
| `glob(globs=...)` | Files matching glob patterns |
| `parse_evtx(filename=...)` | Windows event log records |
| `registry(...)` / `read_reg_key()` | Registry keys/values |
| `netstat()` | Network connections |
| `wmi(query=...)` | WMI query results |
| `info()` | Host/system information |
| `execve(argv=...)` | Run an external command |
| `artifact_definitions()` | Enumerate loaded artifacts |
| `hunt(description=..., artifacts=...)` | Create a server-side hunt |
## VQL query shape
```sql
SELECT <columns>
FROM <plugin>(<args>)
WHERE <condition> -- supports =~ for regex, AND/OR
ORDER BY <column>
LIMIT <n>
```
## Custom artifact YAML structure
```yaml
name: Custom.Category.Name
description: What it does.
parameters:
- name: param1
default: value
sources:
- query: |
SELECT * FROM plugin() WHERE col =~ param1
```
## Default ports
| Service | Port |
|---------|------|
| Frontend (client comms) | 8000 |
| Admin GUI | 8889 |