Skip to content
Change the repository type filter

All

    Repositories list

    • Documentation site for Velociraptor
      HTML
      23452724Updated Sep 18, 2025Sep 18, 2025
    • Construct triage artifact based on rules
      Go
      0200Updated Sep 16, 2025Sep 16, 2025
    • vfilter

      Public
      A library implementing a generic SQL like query language.
      Go
      92100Updated Sep 15, 2025Sep 15, 2025
    • cloudvelo

      Public
      An experimental Velociraptor implementation using cloud infrastructure
      Go
      112510Updated Sep 12, 2025Sep 12, 2025
    • Build Velociraptor for Windows 7
      Go
      0000Updated Sep 3, 2025Sep 3, 2025
    • Hunt for SQLite files used by various applications
      Go
      142630Updated Sep 3, 2025Sep 3, 2025
    • Parser for systemd journal files.
      Go
      31400Updated Sep 2, 2025Sep 2, 2025
    • go-yara

      Public
      Go bindings for YARA
      C
      1101400Updated Aug 24, 2025Aug 24, 2025
    • A simple Ordered Dict implementation.
      Go
      3400Updated Aug 21, 2025Aug 21, 2025
    • A Compiler from Sigma rules to VQL
      Go
      51101Updated Aug 19, 2025Aug 19, 2025
    • A golang implementation of a prefetch parser.
      Go
      42010Updated Aug 11, 2025Aug 11, 2025
    • vtypes

      Public
      VTypes is a data driven binary parsing system in Go.
      Go
      41100Updated Aug 2, 2025Aug 2, 2025
    • PyVelociraptor contains the python bindings for the Velociraptor API.
      Python
      82020Updated Jul 30, 2025Jul 30, 2025
    • Presentations and Workshops
      HTML
      4300Updated Jul 28, 2025Jul 28, 2025
    • Hunt the windows Registry automatically using VQL
      Rebol
      2910Updated Jul 10, 2025Jul 10, 2025
    • evtx

      Public
      Golang Parser for Microsoft Event Logs
      Go
      1910520Updated Jun 30, 2025Jun 30, 2025
    • Linpmem

      Public
      Linpmem is a linux memory acquisition tool
      C
      108800Updated Jun 22, 2025Jun 22, 2025
    • An EBPF trace framework for Velociraptor based on tracee
      C
      2100Updated Jun 20, 2025Jun 20, 2025
    • WinPmem

      Public
      The multi-platform memory acquisition tool.
      C
      122841250Updated Jun 18, 2025Jun 18, 2025
    • go-vhdx

      Public
      A library to parse VHDX files
      Go
      0200Updated May 11, 2025May 11, 2025
    • go-ext4

      Public
      Parser for Ext4 filesystems
      Go
      0000Updated May 10, 2025May 10, 2025
    • Binary Parser Generator for Go
      Go
      4500Updated May 9, 2025May 9, 2025
    • go-vmdk

      Public
      A Go library for reading VMDK files
      Go
      0200Updated May 5, 2025May 5, 2025
    • amsi

      Public
      Golang implementation of Microsoft Antimalware Scan Interface
      Go
      4100Updated Apr 18, 2025Apr 18, 2025
    • go-ntfs

      Public
      An NTFS file parser in Go
      Go
      247031Updated Mar 22, 2025Mar 22, 2025
    • etw

      Public
      Go
      0100Updated Mar 14, 2025Mar 14, 2025
    • oleparse

      Public
      Golang parser for OLE files
      Go
      43211Updated Mar 12, 2025Mar 12, 2025
    • go-ese

      Public
      Go implementation of an Extensible Storage Engine parser
      Go
      123030Updated Feb 15, 2025Feb 15, 2025
    • regparser

      Public
      A Golang Registry parser
      Go
      101610Updated Feb 3, 2025Feb 3, 2025