This lab is an introduction to look at Velociraptor performance when using yara.
We will be walking through the best way to run Velociraptor queries with a few different use cases.
Velociraptor available on the desktop to run as per Lab: GUI mode walk through
Open cmd, browse to desktop and run: velociraptor .exe gui –-datastore=./VRdata -v
The Velociraptor GUI is configured to open automatically upon start, but the credentials are available below:
https://127.0.0.1:8889/
admin
password
👈 To go back, tap the link at the top left, or swipe from left to right across your screen.