关于
The Velociraptor DFIR skill provides a powerful interface for security analysts to perform advanced forensic triage and threat hunting through Claude. By integrating the Velociraptor framework with LimaCharlie, it enables users to discover VQL artifacts, launch remote collections across Windows, Linux, and macOS endpoints, and retrieve raw or processed results. This skill streamlines the entire IR workflow—from artifact definition to automated D&R rule creation—allowing for rapid evidence gathering and analysis without leaving the terminal.