Velociraptor logo

Velociraptor

Endpoint Security (Antivirus/EPP)

Open Source
Self-hosted
OpenMSP Score
50
35
Reddit Impact Score
Github Score
23M
3KStars
601Forks
3KCommits
OtherLicense
Mar 20, 2026Last commit
Velociraptor is an open-source endpoint visibility and digital forensics tool. It offers advanced digital forensics and incident response capabilities with a flexible query language and scalable architecture for efficient threat hunting and investigation.
image media
1 / 2

Key Features

VQL Query Language

Powerful Velociraptor Query Language for creating custom artifacts and hunting across endpoints

Real-time Endpoint Monitoring

Continuous monitoring of endpoint events including process creation, file modifications, and system changes

Digital Forensics Capabilities

Advanced forensic analysis including dead disk forensics, memory analysis, and artifact collection

Scalable Architecture

Client-server architecture capable of managing thousands of endpoints from a central console

Cross-Platform Support

Native support for Windows, Linux, and macOS with consistent functionality across platforms

Pros and Cons

Pros

Advanced Query Capabilities

VQL provides unprecedented flexibility for custom hunting, forensics, and endpoint analysis

Free and Open Source

No licensing costs with full source code availability and active development community

Comprehensive Forensics Features

Built-in support for digital forensics, incident response, and threat hunting in a single platform

Rapid7 Backing

Professional development and support backed by established security company since 2021 acquisition

Flexible Deployment

Supports permanent monitoring, temporary investigations, and offline forensic analysis

Cons

Steep Learning Curve

VQL and advanced features require significant training and technical expertise to use effectively

Resource Intensive

Can consume significant system resources during intensive hunting or forensic operations

Limited GUI Features

Primary functionality requires command-line knowledge and VQL scripting skills

Specialized Use Case

Primarily designed for security professionals and may be overkill for basic monitoring needs

Feature Comparison

Comments

Inés MoralesCloudSecure Pro

Inés MoralesCloudSecure Pro

Jun 1, 2025

Excellent endpoint visibility tool

Velociraptor provides comprehensive endpoint visibility for client security monitoring. Digital forensics capabilities are impressive and deployment is straightforward.

Alina DimitrovaDataGuard Central

Alina DimitrovaDataGuard Central

May 31, 2025

Powerful forensics platform

Using Velociraptor for endpoint investigation and monitoring. Query language is flexible and artifact collection capabilities are extensive. Open source is appealing.

Carter DanielsCloudReady Services

Carter DanielsCloudReady Services

May 30, 2025

Good for threat hunting

Velociraptor handles endpoint visibility needs effectively across diverse client environments. Real-time monitoring works well and forensic analysis is detailed.