PyVelociraptor contains the python bindings for the Velociraptor API.
☆23May 5, 2026Updated last month
Alternatives and similar repositories for pyvelociraptor
Users that are interested in pyvelociraptor are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An experimental Velociraptor implementation using cloud infrastructure☆26Dec 2, 2025Updated 6 months ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Information about the open-source-dfir slack community☆29Jun 17, 2023Updated 2 years ago
- Netwitness Maltego integration Project☆18May 9, 2017Updated 9 years ago
- Documentation site for Velociraptor☆71Updated this week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A Compiler from Sigma rules to VQL☆19May 18, 2026Updated 3 weeks ago
- ☆12Aug 27, 2025Updated 9 months ago
- ☆12Apr 2, 2022Updated 4 years ago
- CLI generator for Velociraptor offline collector☆16Jun 2, 2026Updated last week
- VMDK Forensic Artifact Extractor (VFAE) is windows based tool written in C++ that extracts files with a known location from VMDK images r…☆17Aug 7, 2015Updated 10 years ago
- Transform EQL detection rules to VQL artifacts☆12Nov 12, 2021Updated 4 years ago
- Repo to hold mcp server for velociraptor☆39Apr 15, 2026Updated last month
- Library of threat hunts to get any user started!☆51Sep 4, 2020Updated 5 years ago
- A parser for the MFT (Master File Table) format☆161Jan 3, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Hunt the windows Registry automatically using VQL☆17May 4, 2026Updated last month
- Sample queries for Advanced hunting in Windows Defender ATP☆11Apr 22, 2020Updated 6 years ago
- ☆23Mar 12, 2025Updated last year
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆32Mar 19, 2026Updated 2 months ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- Recon Hunt Queries☆79May 16, 2021Updated 5 years ago
- Hunt for SQLite files used by various applications☆31Mar 1, 2026Updated 3 months ago
- ☆15Oct 24, 2024Updated last year
- A repository to share publicly available Velociraptor detection content☆203Jun 7, 2026Updated last week
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Apr 16, 2021Updated 5 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 4 years ago
- ☆74May 11, 2026Updated last month
- ☆12Jul 14, 2025Updated 11 months ago
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- ☆22Aug 29, 2024Updated last year
- Hundred Days of Yara Challenge☆12Jun 21, 2022Updated 3 years ago
- Generates TCP/UDP stream configuration files for NGINX based on the backend servers and ports provided☆11May 23, 2019Updated 7 years ago
- ☆22Jan 31, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Scripts and tools to automate a Windows 7 installation for QEMU☆14Nov 4, 2015Updated 10 years ago
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆118Jan 26, 2022Updated 4 years ago
- Publicly shareable windows event log message data☆29Nov 29, 2019Updated 6 years ago
- Queries for parsed spotlight database in sqlite☆13Dec 29, 2020Updated 5 years ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated last year