Velociraptor is a free, open-source digital forensics and incident response tool for endpoint monitoring and threat hunting, maintained by Rapid7.
Velociraptor is an open-source digital forensics, incident response, and endpoint monitoring tool used by security teams to investigate and hunt for threats across large numbers of computers at once. It is designed for incident responders who need to quickly pull very specific forensic evidence from many endpoints without deploying a full commercial EDR agent.
The project was created in 2018 by Mike Cohen, a forensics specialist with a background at the Australian Department of Defence, the Australian Federal Police, and eight years at Google, where he worked on related open-source forensic tools such as GRR and Rekall. Velociraptor built on those lessons with a more flexible, purpose-built query language for endpoint investigation.
In April 2021, cybersecurity company Rapid7 acquired Velociraptor along with its open-source community. Rapid7 committed to keeping the project open source rather than converting it into a paid product, while using the underlying technology to strengthen its own incident response capabilities.
At the core of Velociraptor is VQL, the Velociraptor Query Language, a SQL-like language used to write custom artifacts that define exactly what evidence to collect from an endpoint, from specific registry keys to running processes to browser history.
Velociraptor supports simultaneous evidence collection and threat hunting across thousands of endpoints from a single server, returning results in minutes rather than the hours or days a manual, host-by-host investigation would take.
Continuous endpoint monitoring streams events such as file modifications, process execution, and event logs to a central Velociraptor server for indefinite historical storage, letting analysts retroactively investigate activity that occurred before an incident was detected.
Velociraptor is entirely free and open source, with no paid tier or license fee for the software itself, distributed via GitHub under an open-source license.
Organizations pay only for the infrastructure they run the Velociraptor server and agents on, or for professional services and incident response engagements from Rapid7 or other security consultancies that use Velociraptor as part of a paid engagement.
Velociraptor is used for digital forensics, incident response, endpoint monitoring, and threat hunting across large numbers of computers, letting security teams collect evidence and investigate incidents quickly.
Yes, Velociraptor is a free, open-source tool with no license fees, distributed on GitHub.
Velociraptor was created in 2018 by Mike Cohen, a digital forensics specialist who previously worked at the Australian Department of Defence, the Australian Federal Police, and Google.
Rapid7, a publicly traded cybersecurity company, acquired Velociraptor in April 2021 and continues to maintain it as an open-source project.
VQL, the Velociraptor Query Language, is the SQL-like language used to write custom artifacts that define what forensic evidence Velociraptor collects from an endpoint.
Yes, Velociraptor is designed to query and collect evidence from thousands of endpoints simultaneously, returning results in minutes.
Velociraptor can complement or partially substitute for commercial EDR and XDR tools for forensic collection and threat hunting, but it lacks some of the automated response and built-in threat intelligence features of full commercial platforms.