Velociraptor Powered • Digital Defense Institute Maintained

Triage Collector

A ready-to-run Velociraptor package that collects the evidence responders need without extra setup.

Build health

Build Status

Latest workflow run from GitHub Actions

Platform

Windows (x64)

Output

ZIP evidence archive

Velociraptor version

Syncing…

What This Collector Gathers

Artifacts collected:

Includes Volume Shadow Copy snapshots up to 3 days old.

Would you like to see additional targets added? Open an issue to request them.

How to Use the Collector

  1. 1
    Download

    Grab the latest release and place it on the host you are triaging.

  2. 2
    Collect

    Run the executable with administrative privileges and let it finish.

  3. 3
    Extract

    Retrieve the generated ZIP archive for immediate analysis.

Need timelines? Convert the triage archive into full forensic timelines using our openrelik-pipeline.

Fast Deployment

Single download with pre-packaged artifacts keeps triage moving even during active incidents.

Defender Friendly

Predictable behavior and an open build pipeline reduce the friction of running evidence collection on critical hosts.

Actionable Output

Combines live system data with historical snapshots, giving investigators immediate context.

Need deeper customization?

Fork the project, tweak the Velociraptor artifacts, and keep your responders aligned with your playbooks.

Explore the repository

Threat Hunting & Incident Response with Velociraptor

Hands-on training that dives into the same workflows powering this collector.

Explore the course