Products and Tools

Enhancing Velociraptor with the Cado Security Platform

|Last updated on Jun 14, 2024|1 min read
LinkedInFacebookX
Enhancing Velociraptor with the Cado Security Platform

By: Nicholas Handy, Director of Technical Alliances & Partnerships at Cado Security

Velociraptor is a robust  open-source tool designed for collecting and querying forensic and incident response artifacts across various endpoints. This powerful tool  allows incident responders to effortlessly gather data from remote systems, regardless of their location.

Screenshot-2024-06-10-at-4.07.14-PM.png

Advanced data analysis with the Cado Security Platform

The Cado Security platform is a complementary technology that enables analysis and process of captured data at scale and from multiple sources. In conjunction with  Velociraptor data, Cado analyzes data captured from cloud VMs, container-based, serverless, and SaaS environments. The platform automatically scales up and down to provide fast, parallel data processing. This means that it can process hundreds of systems simultaneously.

The Cado Security Platform integrates seamlessly  with Velociraptor, creating a comprehensive suite for  end-to-end data capture and analysis. In fact, Cado’s existing customers routinely analyze data collected by Velociraptor during investigations using this  platform, making the most of its powerful capabilities

Optimized data processing and analysis

Screenshot-2024-06-10-at-4.11.07-PM.png

A common use case involves users performing  offline triage to create an agent to collect Windows.KapeFiles from endpoints, to  then upload these  to cloud storage where Cado can import, process, and analyze them. This capability leverages Cado's cloud-based parallel processing to quickly normalize collected artifacts. Cado creates a timeline of what happened on the systems, runs analysis against the files and enables an analyst to search and browse the captured data.

Screenshot-2024-06-10-at-4.11.38-PM.png

Enhanced threat visibility

The Cado Security Platform creates detailed timelines of system events, conducts thorough file analysis, and enables analysts to search and browse captured data efficiently. This detailed insight is invaluable for understanding the full impact of threats.

screenshot-2024-06-10-at-4.12.19-pm.pngScreenshot-2024-06-10-at-4.12.48-PM.png

With Velociraptor and The Cado Security Platform working together, incident response teams can achieve  a better understanding of the impact of threats with complete visibility across their entire ecosystem, enhancing the overall efficiency of forensic investigations and incident response.

Related blog posts