I am very excited to announce that the latest Velociraptor release 0.74.2 is now in available.
Detailed release notes are at https://docs.velociraptor.app/blog/2025/2025-02-23-release-notes-0.74/
The major new feature in this release is reworking of the new Sigma editor as well as many new live event sources for Linux and Windows. You can read all about the latest timeline feature in our blog post Developing Sigma Rules in Velociraptor
If you find any issues please file an issue on GitHub or chat with us on our discord server.
Breaking Changes:
- 0.74-2 had relaxed sanitazation on the elastic index names to be more consistent with the official Elastic rules. This might change the names of indexes in your pipeline.