Velociraptor for Endpoint Investigation

Reach it. Ask it. Prove it.

The machine is three floors away, or three time zones. An agent on the endpoint answers your question from the live system, and nothing had to be shipped in advance. This course teaches you to deploy that, write the queries that ask well, collect in an order that survives a reboot, hunt an entire estate, and turn what comes back into an account somebody else can check. Every section shows you a capability and then the specific way it produces a confident wrong answer.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 12 CPE Credits

What you'll be able to do

✓Stand up a deployment and state precisely what it reaches, including the machines it never will and why that population matters most
✓Write, compose and debug VQL, and recognize the one behavior in the language capable of doing real damage across an estate
✓Collect from one endpoint in an order that reflects how long each class of evidence survives, scoped to a question rather than a checklist
✓Reach a machine with no agent at all using an offline collector, and know why its encryption choice decides who can read the result
✓Hunt an entire fleet: scope it, rehearse it, read progress honestly, and grow the scope as the investigation grows
✓Turn separate results into one account, with evidence horizons, clock skew, cross-host links and findings whose strength is visible on the page
✓Extend the platform with your own artifacts, monitor continuously rather than asking, contain a host, and keep the deployment working
FOR202 | Premium tier | 7 modules across 4 phases | 10–12 hours at your own pace | 12 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: The Deployment

Module 0Course OrientationCourse Preview

What Velociraptor for Endpoint Investigation teaches: reaching a machine you cannot walk to, asking it a specific question, and turning the answer into evidence. The deployment you will run, the query language you will write, hunts across a fleet, and the honest limits of what an agent can see. Start here.

Show 7 lessonsHide lessons
  1. 0.10.1 What Remote Live Collection IsPreview
  2. 0.20.2 How This Course Is StructuredPreview
  3. 0.30.3 The Environment You Will BuildPreview
  4. 0.40.4 Where This Shows UpPreview
  5. 0.50.5 What It Cannot DoPreview
  6. 0.60.6 Following AlongPreview
  7. 0.7Module SummaryPreview
Module 1Deployment and Access Control

What Velociraptor reaches that your other tools do not, the architecture that makes a collection arrive in seconds, choosing a deployment model before you generate a config, standing the server up on a current release, the roles and organizations that decide who can run a query against whose endpoints, and enrolling clients so the fleet actually appears.

Show 8 lessonsHide lessons
  1. 1.11.1 What Velociraptor Reaches, and What It Does Not
  2. 1.21.2 The Architecture Behind a Two-Second Answer
  3. 1.31.3 Choosing a Deployment Model
  4. 1.41.4 Standing Up the Server
  5. 1.51.5 Users, Roles, and Organizations
  6. 1.61.6 Enrolling Clients and Proving the Fleet Is Real
  7. 1.7Module Summary
  8. 1.8Check My Knowledge
Module 2Driving the Console

Finding a host among hundreds and reading what its record actually claims, why the file browser is a cache rather than a live view and what that means for every conclusion drawn from it, retrieving and inspecting a file without touching the machine, running and reading collections, notebooks as the place investigation work accumulates, and the labels that turn a client list into groups you can act on.

Show 8 lessonsHide lessons
  1. 2.12.1 Finding a Host and Reading Its Record
  2. 2.22.2 The Virtual File System, and Why It Is a Cache
  3. 2.32.3 Retrieving and Inspecting a File
  4. 2.42.4 Collections, from Launch to Result
  5. 2.52.5 Notebooks as the Investigation Workspace
  6. 2.62.6 Labels and Metadata
  7. 2.7Module Summary
  8. 2.8Check My Knowledge

Phase 2: Asking Questions

Module 3VQL for Investigators

The query language underneath every artifact you have collected so far: how a query is shaped, the difference between the things that produce rows and the things that transform them, stored queries and when they materialize, the evaluation order that decides whether a filter protects you, and how to debug a query that fails on a real endpoint.

Show 8 lessonsHide lessons
  1. 3.13.1 The Shape of a Query
  2. 3.23.2 Row Sources
  3. 3.33.3 Transforming What Comes Back
  4. 3.43.4 Stored Queries and Composition
  5. 3.53.5 Evaluation Order, and the Trap
  6. 3.63.6 When a Query Fails
  7. 3.7Module Summary
  8. 3.8Check My Knowledge
Module 4Collecting from One Endpoint

Turning the console and the language into a collection you can defend: the order volatile evidence has to be taken in, choosing artifacts for a question rather than from a checklist, scoping with parameters, building an offline collector for machines with no agent, handling a collection that fails partway, and the record that makes the result worth something in a month.

Show 8 lessonsHide lessons
  1. 4.14.1 Order of Volatility
  2. 4.24.2 Choosing Artifacts for a Question
  3. 4.34.3 Scoping with Parameters
  4. 4.44.4 The Offline Collector
  5. 4.54.5 When a Collection Fails Partway
  6. 4.64.6 The Custody Record
  7. 4.7Module Summary
  8. 4.8Check My Knowledge

Phase 3: The Fleet

Module 5Hunts Across the Fleet

The collection you already know how to build, addressed to every machine at once: why a hunt expires rather than completes, scoping by label and condition, launching from the paused state with an expiry and limits that mean something, watching one run against a fleet that is never all online, and recruiting hosts into a running hunt by labeling them.

Show 8 lessonsHide lessons
  1. 5.15.1 What a Hunt Is, and Why It Never Completes
  2. 5.25.2 Scoping a Hunt
  3. 5.35.3 Launching Safely
  4. 5.45.4 Watching a Hunt Run
  5. 5.55.5 Incremental Hunting
  6. 5.65.6 Reading Fleet Results
  7. 5.7Module Summary
  8. 5.8Check My Knowledge
Module 6Fleet Analysis and Correlation

Turning separate results into one account: correlating findings across machines, baselining an estate so abnormal becomes visible, building a timeline that spans hosts, handling clocks that disagree, pivoting from a finding to the next question, and writing the sequence in a form somebody else can check.

Show 8 lessonsHide lessons
  1. 6.16.1 From Samples to a Sequence
  2. 6.26.2 Baselining and Differential Analysis
  3. 6.36.3 Building a Timeline Across Machines
  4. 6.46.4 When Clocks Disagree
  5. 6.56.5 Pivoting
  6. 6.66.6 Writing the Account
  7. 6.7Module Summary
  8. 6.8Check My Knowledge

Phase 4: Extending and Operating

Module 7Extending and Operating It

Writing your own artifact when nothing published answers the question, reading and trusting community definitions, monitoring instead of asking, containing a host, keeping the deployment healthy, and taking one case from alert to written account using everything in the six modules behind it.

Show 8 lessonsHide lessons
  1. 7.17.1 Writing Your First Artifact
  2. 7.27.2 Artifacts Worth Borrowing
  3. 7.37.3 Monitoring Instead of Asking
  4. 7.47.4 Containment
  5. 7.57.5 Operating the Deployment
  6. 7.67.6 One Case, End to End
  7. 7.7Module Summary
  8. 7.8Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

Queries and commands by the question you arrived with, each with the fields that carry the decision and what the result does not establish.

Show 6 lessonsHide lessons
  1. 1Query Patterns
  2. 2First Response
  3. 3Hunting the Fleet
  4. 4Correlation and Timeline
  5. 5Operating It
  6. 6States, Limits and Lookups
ResourcesCookbooks

Six runbooks for the procedures this work repeats: triaging an alerted host, hunting an indicator across the estate, collecting from a machine with no agent, containing one, promoting a query to an artifact, and handing evidence to somebody else.

Show 6 lessonsHide lessons
  1. 1Triaging an Alerted Host
  2. 2Hunting an Indicator Across the Estate
  3. 3Collecting from a Machine with No Agent
  4. 4Containing a Host
  5. 5Promoting a Query to an Artifact
  6. 6Handing Evidence to Somebody Else
ResourcesWalkthroughs

Endpoint investigations reasoned end to end, including the cases where the tool was the wrong answer and the ones that finish with a weaker finding than the evidence first suggested.

Show 6 lessonsHide lessons
  1. 1The Alert That Was the Last Host
  2. 2The Hunt That Found Nothing
  3. 3The Collection That Said Finished
  4. 4The Five Minutes That Were Not There
  5. 5The Task on Six Hundred Machines
  6. 6The Laptop That Should Have Been Imaged
ResourcesPlayground

Every practice surface available for this course, what each one gives you, where the gaps are, and the exercises worth building yourself.

ResourcesOperational Reference

Every command, query, artifact invocation, state and check from the Velociraptor for Endpoint Investigation course in one place, organized by task and linked back to the section that explains when not to use it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

Vendor documentation, the artifact reference and community exchange, endpoint forensics sources, incident response standards and frameworks, and the operational research used throughout the Velociraptor for Endpoint Investigation course.

Course Completion

CompletionCourse Exam

Velociraptor for Endpoint Investigation end-of-course exam: fleet scoping inside the hour during a live intrusion, testing whether you can match a hunt design to the question, cost it before launching, and know what complete means when a fifth of the fleet is offline.

Show 1 lessonHide lessons
  1. 1Course Completion. Velociraptor for Endpoint Investigation

Course overview

Velociraptor is free, widely deployed, and taught almost entirely as a tour of its interface. That produces analysts who can run a collection and cannot say what its result covers. This course teaches the tool and the reasoning together, because on this platform they are the same skill: a collection returns rows and does not tell you it was canceled at a limit, a hunt reaches 731 machines and does not tell you the estate has 812, and a connection list is a snapshot in which a beacon talking every five minutes is invisible. Learn how to:

✓ Stand up a deployment and state precisely what it reaches, including the machines it never will
✓ Write, compose and debug VQL, including the one behavior in the language capable of doing real damage
✓ Collect from one endpoint in an order that reflects how long each class of evidence survives
✓ Ask the same question of eight hundred machines and read the answer without overstating it
✓ Turn separate results into one account, with timelines, clock skew and findings whose strength is visible

By the end you will run this tool the way somebody responsible for an estate does, with an honest account of what an agent can and cannot see.

How this course works

Velociraptor turns a question into a query that runs on every endpoint at once. This course runs the same loop for every investigation it works.

1. Deploy it so the answers are trustworthy. Client authentication and access control first, because a collection platform anybody can query is a liability rather than a capability.

2. Ask the question in VQL. Artifacts are queries. Learning to write them is what separates running somebody else's collection from running your own investigation.

3. Prove it on one endpoint. A query that works on one host and returns nothing across the fleet is a query with a bug. Establish the shape of a correct answer before scaling it.

4. Hunt, then read the denominator. A fleet hunt reports what answered. How many clients were enrolled, how many responded and how many errored is the part that makes the result mean something.

5. Turn the finding into a standing artifact. The investigation you just ran is worth more as a saved artifact somebody can re-run than as a result in a notebook.

What this course assumes

No minimum experience and no prerequisite course. VQL, the client-server model and the artifact system are built from nothing.

What makes it go faster: two machines to run a server and a client on, virtual is fine, and comfort with SQL-like syntax. Neither is required, and every query in the course is shown with its output.

What this course does not cover: Windows artifact forensics in depth, malware analysis, and incident response process. Velociraptor is how you reach the evidence at scale, and those decide what to do with it.

Who this course is for

You are an incident responder, SOC analyst, threat hunter, or the security engineer who owns the deployment. No prior Velociraptor experience is assumed and no query language experience is assumed. This course is for you if you want to:

✓ Reach a machine you cannot walk to, in seconds rather than after a day of travel or shipping
✓ Ask a question of an entire estate and defend what the answer covers when somebody challenges it
✓ Stop guessing whether an empty result means nothing happened or the query never asked
✓ Run the platform properly, including the checks that fail silently between incidents

If endpoints appear in your investigations and reaching them is the slow part, this course is for you.

What you'll learn

Seven modules, working from what the tool can reach to one case taken end to end.

✓ Deploy a server, enroll clients, and establish your real coverage against a source of truth outside the platform
✓ Drive the console without mistaking a cached view for a live one, and read a collection's state before its rows
✓ Write VQL from sources through composition and debugging, and recognize the acting expression that retrieves everything it matched
✓ Collect from one endpoint in the order of volatility, scoped to a question, with a record that still means something in a month
✓ Reach a machine with no agent using an offline collector, and choose the encryption that decides who can read the result
✓ Scope, rehearse, launch and read a fleet-wide hunt, including why a hunt expires rather than completes
✓ Apply prevalence analysis and recognize the case where it ranks the malicious entry as ordinary
✓ Correlate across hosts with evidence horizons, clock skew and cross-host links, and write findings whose registers are visible
✓ Write your own artifacts, judge somebody else's before running it, monitor continuously, and contain a host without losing the evidence

Key course takeaways

✓ Run a full investigation end to end, from an alert naming one machine to a written account somebody else can check
✓ Know the four ways this platform produces a confident wrong answer, and the check that catches each one
✓ Hunt an estate and report the finding with its population attached, which is the difference between a claim that survives review and one that does not
✓ Carry six runbooks and six worked cases for the procedures this work repeats, including the ones that end in a weaker finding than the evidence first suggested
✓ Operate the deployment through the checks that fail silently, because a year without problems is equally consistent with a year without looking

Things you need to know

What are the prerequisites for this course?

None. No prior Velociraptor experience and no query language experience are assumed, and every concept is explained where it is first used. If you have run investigations on endpoints by any means you will recognize the problems this course solves.

Do I need a lab to follow along?

You should have one, and it costs nothing. Velociraptor is a single free binary with no license and no expiring trial, so a server and a client on the machine you are reading this on takes a minute. Two or three clients make the fleet modules considerably better, and a virtual machine you can afford to isolate and restore completes the final module.

What licensing does this assume?

None. Every capability in this course, including the parts most products reserve for an enterprise edition, is available to somebody working on their own machines.

Is this course current?

Every artifact name, parameter and invocation is drawn from the published artifact reference rather than written for teaching, and each was checked at the time of writing. Command syntax changes across major versions and published artifact definitions are revised, so the references module tells you which two sources resolve a disagreement and in what order.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Queries, artifacts and scenarios are illustrative and use the fictional Northgate Engineering environment. Verify against your own deployment and against the current artifact reference before relying on any specific behavior, and treat what your server actually returns as authoritative over any document, including this one.

Ridgeline Cyber is not affiliated with Velocidex or Rapid7. Product names are used descriptively.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.