Velociraptor

Rapid7

Velociraptor.exe gui

THM-VELOCIRAPTOR.eu-west-1.compute.internnal

2021-04-11T22:11:10Z

LET Generic_Client_Info_Users_0_0=SELECT Name, Description, Mtime AS LastLogin FROM Artifact.Windows.Sys.Users()

stdout

powershell -ExecutionPolicy Unrestricted -encodedCommand RwBlAHQALQBEAGEAdABlAA==

Ubuntu on Windows Subsystem for Linux

20

ntfs accessor

registry accessor 

desktop.ini

THM{VkVMT0NJUkFQVE9S} 

Column Selectors

VQL Plugins

 filter expression

?

execve()

parse_mft(filename="C:/$MFT", accessor="ntfs")

isDIR

Windows.Detection.PrintNightmare

SELECT "C:/" + FullPath AS Full_Path,FileName AS File_Name,parse_pe(file="C:/" + FullPath) AS PE

nightmare.dll

C:\Users\caleb\source\repos\nightmare\x64\Release\nightmare.pdb