Velociraptor PDF Free Download

  • Dig deeper.

    Interrogate your endpoints with speed and precision.

    Watch How Download Latest
  • Go hunting.

    Harness digital forensic expertise to proactively find suspicious activities.

    Learn howDownload Latest </
  • Stop attackers in their tracks.

    Monitor for dangerous events and respond with accuracy and flexibility.

    Learn howDownload Latest

The next generation in endpoint visibility.

With a solid architecture, a library of customisable forensic artifacts and its own unique and flexible query language, Velociraptor provides the next generation in endpoint monitoring, digital forensic investigations and cyber incident response.


At the press of a (few) buttons, perform targeted collection of digital forensic evidence simultaneously across your endpoints, with speed and precision.


Continuously collect endpoint events such as event logs, file modifications and process execution. Centrally store events indefinitely for historical review and analysis.

Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries. To learn more about Velociraptor, read the documentation on: This will bring up the GUI, Frontend and a local client. You can collect artifacts from the client (which is just running on. Velociraptor's homepage. Velocidex Enterprises was founded by well established industry professionals with many years of proven expertise in the development of digital forensic software and its use to support a wide range of digital forensic investigations and cyber breach response cases. Get a Printed Plan for Free Post a build log and receive a free print for free. That´s it, we will send you one plan printed on paper for your next build if you share a well made building log of your current build at the forum. Please read the rules at the forum here. To post at the forum you have to register there too.


Don't wait until an event occurs. Actively search for suspicious activities using our library of forensic artifacts, then customize to your specific threat hunting needs.


When serious events occur on an endpoint, trigger an automated response to collect evidence, silently block malicious activity or lock-down endpoints entirely.


Open source

As an open source platform, Velociraptor continues to evolve and improve through feedback and input from practitioners on the front lines of cyber security and digital forensic investigations. As your needs change, so can Velociraptor. Compress software pressure vessel free download.

Deploys in minutes

Velociraptor works natively on Windows, macOS and Linux. It's distributed as a static binary with no libraries or dependencies. You can create a server within minutes and easy deploy clients using SCCM or Group Policy, even run in agentless mode.

Powered by VQL

The Velociraptor Query Language (VQL) is an expressive query language designed to adapt to your requirements easily and without needing to modify any code nor deploy additional software. VQL encapsulates digital forensic expertise into human readable files called 'artifacts' which can be shared and exchanged freely within the community.

Velociraptor Pdf Free Download For Windows 7

Community backed

Velociraptor is a vibrant open source project with a large community of users and developers.

Velociraptor 3d Model

Build upon real-world experience

Velociraptor is built by digital forensic and incident response practitioners and used on real-world investigations every day. As we encounter new challenges and requirements, we develop new features and artifacts, which are contributed back into the project, for the benefit of the whole community.

Performance management

Velociraptor security

We know that performance is critical and operational impact must be minimized. Velociraptor provides real-time performance monitoring and endpoint throttling to run more intense hunts 'low and slow' thereby minimizing any operational impact.

Velocidex Enterprises

A unique Australian technology company.

Proven track record

Lead by industry experts with over 20 years of proven experience in developing digital forensic software and using it successfully in thousands of real-life DFIR cases.

Trust and integrity

Our team are trusted advisors to hundreds of clients across Australia and internationally, providing digital forensic services on the most sensitive cases.

About us

Velocidex Enterprises was founded by well established industry professionals with many years of proven expertise in the development of digital forensic software and its use to support a wide range of digital forensic investigations and cyber breach response cases.

Velociraptor aims to provide the 'last step' in the process of digital forensic investigations, security monitoring and threat hunting. We already know a great deal about how to investigate computer systems and monitor for malicious activities. Velociraptor aims to encapsulate this industry knowledge and empower both experts and novices to leverage it, to collect and analyze evidence of malicious activities with speed and precision.

Mike Cohen

Mike is a renowned digital forensic researcher and senior software engineer. He's supported leading open-source DFIR projects including as a core developer of Volatility and lead developer of both Rekall and Grr Rapid Response.

Mike is our 'Digital Paleontologist' and brings his years of expertise to the role of principal developer of Velociraptor.