Matthew Green

I am a DFIR and detection guy from Sydney Australia.

DEATHcon 2022 Velociraptor workshop


DEATHcon Velociraptor workshop was held November 2022. We cover some basic VQL use cases including NTFS, Event Logs, Yara and memory artifacts.

The workshop was implemented with Velociraptor 0.6.6 although the data generation can be applied to any version.

Workshop slides and labs

Data generation scripts

Youtube videos