{"data":{"skill":{"slug":"agentsecops-ir-velociraptor","name":"ir-velociraptor","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/incident-response/ir-velociraptor","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"825bd927-6599-4741-9cbe-fe640e1e495c","skill_id":"d9d73d59-e562-48ef-ad70-f884441e2870","version":9,"content_hash":"v3:9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2:0d73e6e09f7b5e3270508e6dda90e2711205f8859ff78db6361642eca73666b4:1439b1d2ab974f820924d76d6af755d2dcce6da9e8f5ecaf9aaeb61f90e8f3f2:736b696c6c732f6167656e747365636f70732f69722d76656c6f6369726170746f72:bb158545e29bbb6e2446e8c6aefce6b6","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"Most static alerts are documentation syntax, placeholders, or read-only defensive queries. Confirmed risks include remote script execution, privileged deployment, broad network exposure, and sensitive temporary files. CI bypasses and insecure deployment examples require correction before publication.","remediation":[{"issue":"Remote scripts and binaries execute without integrity verification.","severity":"critical","suggestion":"Pin exact versions, download files separately, verify published signatures or checksums, and execute only after successful validation."},{"issue":"CI scanners can fail without failing the workflow.","severity":"high","suggestion":"Remove unconditional success fallbacks, handle scanner errors separately from findings, and enforce documented severity thresholds."},{"issue":"A CI action uses a mutable branch and other actions use mutable tags.","severity":"high","suggestion":"Pin every third-party action to a reviewed commit SHA and use an automated process for controlled updates."},{"issue":"The NFS export disables root squashing for the evidence datastore.","severity":"high","suggestion":"Remove no_root_squash, restrict clients to a narrow network, apply least privilege, and protect evidence with immutable backups."},{"issue":"Deployment guidance performs privileged and persistent host changes.","severity":"high","suggestion":"Require explicit confirmation, document rollback steps, verify configurations, and test service and firewall changes in an isolated environment."},{"issue":"Generated client configuration is written to a shared temporary path.","severity":"medium","suggestion":"Create a private directory with restrictive permissions, write atomically, and delete the configuration securely after deployment."},{"issue":"Ransomware sample extraction lacks containment guidance.","severity":"high","suggestion":"Require isolated analysis systems, encrypted archives, access controls, malware labeling, and documented custody before sample extraction."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"assets/artifact-template.yaml","line_end":126,"line_start":126},{"file":"assets/artifact-template.yaml","line_end":127,"line_start":127},{"file":"assets/artifact-template.yaml","line_end":132,"line_start":132},{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240},{"file":"assets/hunt-template.yaml","line_end":138,"line_start":138},{"file":"assets/hunt-template.yaml","line_end":138,"line_start":138},{"file":"assets/rule-template.yaml","line_end":43,"line_start":43},{"file":"assets/rule-template.yaml","line_end":44,"line_start":44},{"file":"assets/rule-template.yaml","line_end":45,"line_start":45},{"file":"assets/rule-template.yaml","line_end":73,"line_start":73},{"file":"assets/rule-template.yaml","line_end":118,"line_start":118},{"file":"assets/rule-template.yaml","line_end":119,"line_start":119},{"file":"assets/rule-template.yaml","line_end":151,"line_start":151},{"file":"assets/rule-template.yaml","line_end":191,"line_start":191},{"file":"assets/rule-template.yaml","line_end":192,"line_start":192},{"file":"assets/rule-template.yaml","line_end":193,"line_start":193},{"file":"assets/rule-template.yaml","line_end":217,"line_start":217},{"file":"assets/rule-template.yaml","line_end":260,"line_start":260},{"file":"assets/rule-template.yaml","line_end":261,"line_start":261},{"file":"assets/rule-template.yaml","line_end":288,"line_start":288},{"file":"references/artifact-development.md","line_end":594,"line_start":594},{"file":"references/artifact-development.md","line_end":595,"line_start":595},{"file":"references/artifact-development.md","line_end":410,"line_start":410},{"file":"references/artifact-development.md","line_end":411,"line_start":411},{"file":"references/deployment-guide.md","line_end":77,"line_start":77},{"file":"references/deployment-guide.md","line_end":110,"line_start":110},{"file":"references/deployment-guide.md","line_end":200,"line_start":200},{"file":"references/deployment-guide.md","line_end":325,"line_start":325},{"file":"references/deployment-guide.md","line_end":117,"line_start":117},{"file":"references/deployment-guide.md","line_end":122,"line_start":122},{"file":"references/deployment-guide.md","line_end":126,"line_start":126},{"file":"references/deployment-guide.md","line_end":127,"line_start":127},{"file":"references/deployment-guide.md","line_end":128,"line_start":128},{"file":"references/deployment-guide.md","line_end":132,"line_start":132},{"file":"references/deployment-guide.md","line_end":357,"line_start":357},{"file":"references/deployment-guide.md","line_end":358,"line_start":358},{"file":"references/deployment-guide.md","line_end":359,"line_start":359},{"file":"references/deployment-guide.md","line_end":370,"line_start":370},{"file":"references/deployment-guide.md","line_end":371,"line_start":371},{"file":"references/deployment-guide.md","line_end":372,"line_start":372},{"file":"references/deployment-guide.md","line_end":385,"line_start":385},{"file":"references/deployment-guide.md","line_end":411,"line_start":411},{"file":"references/mitre-attack-mapping.md","line_end":419,"line_start":419},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":329,"line_start":329},{"file":"SKILL.md","line_end":330,"line_start":330}]},{"factor":"external_commands","evidence":[{"file":"assets/ci-config-template.yml","line_end":298,"line_start":298},{"file":"assets/ci-config-template.yml","line_end":301,"line_start":301},{"file":"assets/ci-config-template.yml","line_end":304,"line_start":304},{"file":"assets/ci-config-template.yml","line_end":307,"line_start":307},{"file":"assets/ci-config-template.yml","line_end":310,"line_start":310},{"file":"assets/ci-config-template.yml","line_end":134,"line_start":134},{"file":"assets/ci-config-template.yml","line_end":250,"line_start":250},{"file":"assets/ci-config-template.yml","line_end":291,"line_start":291},{"file":"assets/hunt-template.yaml","line_end":36,"line_start":36},{"file":"assets/hunt-template.yaml","line_end":115,"line_start":115},{"file":"assets/hunt-template.yaml","line_end":183,"line_start":183},{"file":"references/artifact-development.md","line_end":105,"line_start":105},{"file":"references/artifact-development.md","line_end":509,"line_start":509},{"file":"references/artifact-development.md","line_end":512,"line_start":512},{"file":"references/deployment-guide.md","line_end":290,"line_start":285},{"file":"references/deployment-guide.md","line_end":520,"line_start":520},{"file":"references/deployment-guide.md","line_end":278,"line_start":278},{"file":"references/deployment-guide.md","line_end":515,"line_start":515},{"file":"references/deployment-guide.md","line_end":81,"line_start":81},{"file":"references/deployment-guide.md","line_end":145,"line_start":145},{"file":"references/deployment-guide.md","line_end":173,"line_start":173},{"file":"references/deployment-guide.md","line_end":176,"line_start":176},{"file":"references/deployment-guide.md","line_end":177,"line_start":177},{"file":"references/deployment-guide.md","line_end":180,"line_start":180},{"file":"references/deployment-guide.md","line_end":181,"line_start":181},{"file":"references/deployment-guide.md","line_end":182,"line_start":182},{"file":"references/deployment-guide.md","line_end":215,"line_start":215},{"file":"references/deployment-guide.md","line_end":218,"line_start":218},{"file":"references/deployment-guide.md","line_end":272,"line_start":272},{"file":"references/deployment-guide.md","line_end":295,"line_start":295},{"file":"references/deployment-guide.md","line_end":296,"line_start":296},{"file":"references/deployment-guide.md","line_end":299,"line_start":299},{"file":"references/deployment-guide.md","line_end":315,"line_start":315},{"file":"references/deployment-guide.md","line_end":316,"line_start":316},{"file":"references/deployment-guide.md","line_end":380,"line_start":380},{"file":"references/deployment-guide.md","line_end":381,"line_start":381},{"file":"references/deployment-guide.md","line_end":382,"line_start":382},{"file":"references/deployment-guide.md","line_end":388,"line_start":388},{"file":"references/deployment-guide.md","line_end":408,"line_start":408},{"file":"references/deployment-guide.md","line_end":411,"line_start":411},{"file":"references/deployment-guide.md","line_end":412,"line_start":412},{"file":"references/deployment-guide.md","line_end":415,"line_start":415},{"file":"references/mitre-attack-mapping.md","line_end":59,"line_start":59},{"file":"references/mitre-attack-mapping.md","line_end":65,"line_start":65},{"file":"references/mitre-attack-mapping.md","line_end":68,"line_start":68},{"file":"references/mitre-attack-mapping.md","line_end":69,"line_start":69},{"file":"references/mitre-attack-mapping.md","line_end":73,"line_start":73},{"file":"references/mitre-attack-mapping.md","line_end":77,"line_start":77},{"file":"references/mitre-attack-mapping.md","line_end":165,"line_start":165},{"file":"references/mitre-attack-mapping.md","line_end":188,"line_start":188}]},{"factor":"filesystem","evidence":[{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"references/deployment-guide.md","line_end":246,"line_start":246}]},{"factor":"env_access","evidence":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":132,"line_start":132},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":156,"line_start":156},{"file":"assets/rule-template.yaml","line_end":157,"line_start":157},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":163,"line_start":163},{"file":"assets/rule-template.yaml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":165,"line_start":165},{"file":"references/deployment-guide.md","line_end":231,"line_start":231},{"file":"references/deployment-guide.md","line_end":236,"line_start":236},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":424,"line_start":424},{"file":"references/EXAMPLE.md","line_end":425,"line_start":425},{"file":"references/EXAMPLE.md","line_end":427,"line_start":427},{"file":"references/EXAMPLE.md","line_end":430,"line_start":430},{"file":"references/EXAMPLE.md","line_end":432,"line_start":432},{"file":"references/EXAMPLE.md","line_end":437,"line_start":437},{"file":"references/EXAMPLE.md","line_end":444,"line_start":444}]},{"factor":"scripts","evidence":[{"file":"references/EXAMPLE.md","line_end":138,"line_start":138},{"file":"references/EXAMPLE.md","line_end":137,"line_start":137}]}],"critical_findings":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.98,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template downloads a mutable remote script and pipes it directly to Bash. A compromised source can execute arbitrary code on the runner."}],"high_findings":[{"title":"Git platform tokens","locations":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164}],"confidence":0.9,"description":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The workflow passes GITHUB_TOKEN to a third-party action while the workflow has write permissions. A compromised mutable action could misuse repository access."},{"title":"PowerShell invocation","locations":[{"file":"references/deployment-guide.md","line_end":278,"line_start":278}],"confidence":0.98,"description":"```powershell","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The fenced PowerShell example installs and starts Velociraptor as a persistent Windows service. Following it performs real privileged endpoint modification."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":81,"line_start":81}],"confidence":0.98,"description":"sudo mv velociraptor-v0.72.3-linux-amd64 /usr/local/bin/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":145,"line_start":145}],"confidence":0.98,"description":"sudo cat > /etc/systemd/system/velociraptor.service <<'EOF'","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":173,"line_start":173}],"confidence":0.98,"description":"sudo useradd -r -s /bin/false velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":176,"line_start":176}],"confidence":0.98,"description":"sudo mkdir -p /etc/velociraptor /var/lib/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":177,"line_start":177}],"confidence":0.98,"description":"sudo chown -R velociraptor:velociraptor /etc/velociraptor /var/lib/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":180,"line_start":180}],"confidence":0.98,"description":"sudo systemctl daemon-reload","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":181,"line_start":181}],"confidence":0.98,"description":"sudo systemctl enable velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":182,"line_start":182}],"confidence":0.98,"description":"sudo systemctl start velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":215,"line_start":215}],"confidence":0.98,"description":"sudo apt install certbot","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":218,"line_start":218}],"confidence":0.98,"description":"sudo certbot certonly --standalone \\","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":272,"line_start":272}],"confidence":0.98,"description":"# Install: sudo dpkg -i velociraptor-client.deb","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":295,"line_start":295}],"confidence":0.98,"description":"sudo cp velociraptor /usr/local/bin/","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":296,"line_start":296}],"confidence":0.98,"description":"sudo cp client.config.yaml /etc/velociraptor/","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":299,"line_start":299}],"confidence":0.98,"description":"sudo cat > /etc/systemd/system/velociraptor-client.service <<'EOF'","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":315,"line_start":315}],"confidence":0.98,"description":"sudo systemctl enable velociraptor-client","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":316,"line_start":316}],"confidence":0.98,"description":"sudo systemctl start velociraptor-client","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":380,"line_start":380}],"confidence":0.98,"description":"sudo apt install nfs-kernel-server","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":381,"line_start":381}],"confidence":0.98,"description":"sudo mkdir -p /export/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":382,"line_start":382}],"confidence":0.98,"description":"sudo chown nobody:nogroup /export/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":388,"line_start":388}],"confidence":0.98,"description":"sudo mount -t nfs nfs-server:/export/velociraptor /var/lib/velociraptor","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":408,"line_start":408}],"confidence":0.98,"description":"sudo iptables -A INPUT -p tcp --dport 8000 -j ACCEPT","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":411,"line_start":411}],"confidence":0.98,"description":"sudo iptables -A INPUT -p tcp --dport 8889 -s 10.0.0.0/8 -j ACCEPT","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":412,"line_start":412}],"confidence":0.98,"description":"sudo iptables -A INPUT -p tcp --dport 8889 -j DROP","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"sudo privilege escalation","locations":[{"file":"references/deployment-guide.md","line_end":415,"line_start":415}],"confidence":0.98,"description":"sudo iptables-save > /etc/iptables/rules.v4","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review."},{"title":"Systemd service enablement","locations":[{"file":"references/deployment-guide.md","line_end":181,"line_start":181}],"confidence":0.98,"description":"sudo systemctl enable velociraptor","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration."},{"title":"Systemd service enablement","locations":[{"file":"references/deployment-guide.md","line_end":315,"line_start":315}],"confidence":0.98,"description":"sudo systemctl enable velociraptor-client","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration."},{"title":"Security scan failures are suppressed","locations":[{"file":"assets/ci-config-template.yml","line_end":61,"line_start":54},{"file":"assets/ci-config-template.yml","line_end":128,"line_start":116},{"file":"assets/ci-config-template.yml","line_end":235,"line_start":228}],"confidence":0.98,"description":"The CI template appends success fallbacks to several scanners. Tool failures and some findings can pass without an enforced security gate.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The template visibly uses success fallbacks after Semgrep, Safety, npm audit, and Checkov commands. Several jobs lack a reliable later failure check."},{"title":"Privileged binary installation lacks integrity verification","locations":[{"file":"references/deployment-guide.md","line_end":81,"line_start":73}],"confidence":0.98,"description":"The deployment guide downloads a Velociraptor executable and moves it into a privileged executable path without verifying a checksum or signature.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The displayed sequence performs wget, chmod, and sudo mv. No integrity verification appears between download and privileged installation."},{"title":"Mutable CI action can execute upstream changes","locations":[{"file":"assets/ci-config-template.yml","line_end":201,"line_start":196}],"confidence":0.99,"description":"The CI template runs the Trivy action from its mutable master branch. Future upstream changes can execute in repository workflows without review.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The action reference is explicitly aquasecurity/trivy-action@master. A branch is mutable and does not provide immutable supply-chain pinning."},{"title":"NFS evidence store disables root squashing","locations":[{"file":"references/deployment-guide.md","line_end":388,"line_start":377}],"confidence":0.99,"description":"The NFS example exports the evidence datastore with no_root_squash. A compromised root client can write files as root on the server.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The export option no_root_squash is explicit on line 385. This removes a standard NFS protection for remote root users."},{"title":"Malware sample handling lacks isolation controls","locations":[{"file":"SKILL.md","line_end":248,"line_start":241}],"confidence":0.86,"description":"The ransomware workflow directs analysts to extract binary samples without specifying quarantine, encrypted packaging, or isolated analysis requirements.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The workflow explicitly requests ransomware binary extraction. The surrounding steps do not state containment controls for handling executable malware samples."}],"medium_findings":[{"title":"Hardcoded IP address","locations":[{"file":"references/deployment-guide.md","line_end":117,"line_start":117}],"confidence":0.98,"description":"bind_address: 0.0.0.0","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The example binds the API to every interface. Without a separate access control, administrative functions may be reachable from unintended networks."},{"title":"Hardcoded IP address","locations":[{"file":"references/deployment-guide.md","line_end":122,"line_start":122}],"confidence":0.98,"description":"bind_address: 0.0.0.0","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The example binds the management GUI to every interface. This broad exposure increases authentication and web attack surface."},{"title":"Hardcoded IP address","locations":[{"file":"references/deployment-guide.md","line_end":132,"line_start":132}],"confidence":0.83,"description":"bind_address: 0.0.0.0","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The frontend listens on every interface to accept clients. The deployment must constrain exposure with tested firewall and TLS controls."},{"title":"Hardcoded IP address","locations":[{"file":"references/deployment-guide.md","line_end":385,"line_start":385}],"confidence":0.98,"description":"/export/velociraptor 10.0.1.0/24(rw,sync,no_subtree_check,no_root_squash)","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The NFS example hardcodes a trusted subnet and combines it with no_root_squash. A compromised client in that range can obtain root-level file access."},{"title":"Hardcoded IP address","locations":[{"file":"references/deployment-guide.md","line_end":411,"line_start":411}],"confidence":0.98,"description":"sudo iptables -A INPUT -p tcp --dport 8889 -s 10.0.0.0/8 -j ACCEPT","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The firewall example trusts the entire 10.0.0.0/8 range for GUI access. That range may be much broader than the intended management network."},{"title":"Temp directory access","locations":[{"file":"references/deployment-guide.md","line_end":246,"line_start":246}],"confidence":0.72,"description":"config client > /tmp/client.config.yaml","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The guide writes generated client configuration into a shared temporary directory. Weak permissions or local races could expose or replace sensitive configuration."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.98,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The external URL supplies a script that is executed immediately by Bash. Trust in the remote branch and delivery path is security-critical."},{"title":"Hardcoded URL","locations":[{"file":"references/deployment-guide.md","line_end":77,"line_start":77}],"confidence":0.98,"description":"wget https://github.com/Velocidex/velociraptor/releases/download/v0.72/velociraptor-v0.72.3-linux-am","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The guide downloads an executable for privileged installation without checksum or signature verification. A replaced release artifact could gain root execution."}],"dangerous_patterns":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.98,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template downloads a mutable remote script and pipes it directly to Bash. A compromised source can execute arbitrary code on the runner."},{"title":"Systemd service enablement","locations":[{"file":"references/deployment-guide.md","line_end":181,"line_start":181}],"confidence":0.98,"description":"sudo systemctl enable velociraptor","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration."},{"title":"Systemd service enablement","locations":[{"file":"references/deployment-guide.md","line_end":315,"line_start":315}],"confidence":0.98,"description":"sudo systemctl enable velociraptor-client","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration."}],"files_scanned":13,"total_lines":4899,"audit_model":"codex","audited_at":"2026-07-23T06:05:41.658+00:00","created_at":"2026-07-24T04:01:58.158015+00:00","static_findings":[{"id":"network:assets/artifact-template.yaml:126:hardcoded-url","file":"assets/artifact-template.yaml","pattern":"Hardcoded URL","snippet":"- https://docs.velociraptor.app/docs/vql/","category":"network","line_end":126,"severity":"low","line_start":126},{"id":"network:assets/artifact-template.yaml:127:hardcoded-url","file":"assets/artifact-template.yaml","pattern":"Hardcoded URL","snippet":"- https://attack.mitre.org/","category":"network","line_end":127,"severity":"low","line_start":127},{"id":"network:assets/artifact-template.yaml:132:hardcoded-url","file":"assets/artifact-template.yaml","pattern":"Hardcoded URL","snippet":"url: https://example.com/tool.exe","category":"network","line_end":132,"severity":"low","line_start":132},{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `sast-results`","category":"external_commands","line_end":298,"severity":"medium","line_start":298},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `dependency-scan-results`","category":"external_commands","line_end":301,"severity":"medium","line_start":301},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `secrets-scan-results`","category":"external_commands","line_end":304,"severity":"medium","line_start":304},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `container-scan-results`","category":"external_commands","line_end":307,"severity":"medium","line_start":307},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `iac-scan-results`","category":"external_commands","line_end":310,"severity":"medium","line_start":310},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/safety-results.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/checkov-results","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"**Scan Date**: $(date -u +\"%Y-%m-%d %H:%M:%S UTC\")","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","file":"assets/ci-config-template.yml","pattern":"Hardcoded URL","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"network","line_end":240,"severity":"low","line_start":240},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","file":"assets/ci-config-template.yml","pattern":"Node.js fs operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","file":"assets/ci-config-template.yml","pattern":"Synchronous file operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","file":"assets/ci-config-template.yml","pattern":"Git platform tokens","snippet":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","file":"assets/ci-config-template.yml","pattern":"Pipe to shell pattern","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"blocker","line_end":240,"severity":"critical","line_start":240},{"id":"external_commands:assets/hunt-template.yaml:36:powershell-invocation","file":"assets/hunt-template.yaml","pattern":"PowerShell invocation","snippet":"ProcessPattern: \"(?i)(powershell|cmd|wscript)\"","category":"external_commands","line_end":36,"severity":"high","line_start":36},{"id":"external_commands:assets/hunt-template.yaml:115:powershell-invocation","file":"assets/hunt-template.yaml","pattern":"PowerShell invocation","snippet":"- \"PowerShell execution with bypass flags\"","category":"external_commands","line_end":115,"severity":"high","line_start":115},{"id":"external_commands:assets/hunt-template.yaml:183:powershell-invocation","file":"assets/hunt-template.yaml","pattern":"PowerShell invocation","snippet":"- \"T1059.001: PowerShell\"","category":"external_commands","line_end":183,"severity":"high","line_start":183},{"id":"network:assets/hunt-template.yaml:138:hardcoded-url","file":"assets/hunt-template.yaml","pattern":"Hardcoded URL","snippet":"webhook: \"https://hooks.slack.com/services/...\"","category":"network","line_end":138,"severity":"low","line_start":138},{"id":"network:assets/hunt-template.yaml:138:slack-webhook","file":"assets/hunt-template.yaml","pattern":"Slack webhook","snippet":"webhook: \"https://hooks.slack.com/services/...\"","category":"network","line_end":138,"severity":"medium","line_start":138},{"id":"blocker:assets/hunt-template.yaml:112:c2-keywords","file":"assets/hunt-template.yaml","pattern":"C2 keywords","snippet":"- \"Connections to known C2 infrastructure\"","category":"blocker","line_end":112,"severity":"high","line_start":112},{"id":"blocker:assets/hunt-template.yaml:58:system-reconnaissance","file":"assets/hunt-template.yaml","pattern":"System reconnaissance","snippet":"SELECT client_id FROM clients()","category":"blocker","line_end":58,"severity":"low","line_start":58},{"id":"blocker:assets/hunt-template.yaml:190:system-reconnaissance","file":"assets/hunt-template.yaml","pattern":"System reconnaissance","snippet":"SELECT hunt_id FROM hunt(","category":"blocker","line_end":190,"severity":"low","line_start":190},{"id":"blocker:assets/hunt-template.yaml:204:system-reconnaissance","file":"assets/hunt-template.yaml","pattern":"System reconnaissance","snippet":"WHERE hunt_id = 'H.1234567890'","category":"blocker","line_end":204,"severity":"low","line_start":204},{"id":"sensitive:assets/offline-collector-config.yaml:94:certificate-key-files","file":"assets/offline-collector-config.yaml","pattern":"Certificate/key files","snippet":"#   public_key_file: \"collector-public.pem\"","category":"sensitive","line_end":94,"severity":"high","line_start":94},{"id":"sensitive:assets/offline-collector-config.yaml:208:certificate-key-files","file":"assets/offline-collector-config.yaml","pattern":"Certificate/key files","snippet":"#   certificate_file: \"code-signing-cert.pfx\"","category":"sensitive","line_end":208,"severity":"high","line_start":208},{"id":"blocker:assets/offline-collector-config.yaml:250:system-reconnaissance","file":"assets/offline-collector-config.yaml","pattern":"System reconnaissance","snippet":"Collection results saved to: collection-[hostname]-[timestamp].zip","category":"blocker","line_end":250,"severity":"low","line_start":250},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/SQL_Injection\"","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/89.html\"","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html\"","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/SQL_Injection","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/798.html\"","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password\"","category":"network","line_end":119,"severity":"low","line_start":119},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/798.html","category":"network","line_end":151,"severity":"low","line_start":151},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/xss/\"","category":"network","line_end":191,"severity":"low","line_start":191},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/79.html\"","category":"network","line_end":192,"severity":"low","line_start":192},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\"","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/xss/","category":"network","line_end":217,"severity":"low","line_start":217},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/327.html\"","category":"network","line_end":260,"severity":"low","line_start":260},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testin","category":"network","line_end":261,"severity":"low","line_start":261},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/327.html","category":"network","line_end":288,"severity":"low","line_start":288},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","file":"assets/rule-template.yaml","pattern":"Environment variable access (dot notation)","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","file":"assets/rule-template.yaml","pattern":"Environment variable object","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"low","line_start":147},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"low","line_start":162},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"...\"","category":"env_access","line_end":132,"severity":"high","line_start":132},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"high","line_start":147},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"high","line_start":148},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"sk-1234567890abcdef\"","category":"env_access","line_end":156,"severity":"high","line_start":156},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":157,"severity":"high","line_start":157},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"high","line_start":162},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":163,"severity":"high","line_start":163},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":165,"severity":"high","line_start":165},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","file":"assets/rule-template.yaml","pattern":"Environment file access","snippet":"- Node.js: process.env.API_KEY","category":"sensitive","line_end":148,"severity":"high","line_start":148},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- Python: cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- JavaScript: db.query(\"SELECT * FROM users WHERE id = $1\", [userId])","category":"blocker","line_end":71,"severity":"low","line_start":71},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":83,"severity":"low","line_start":83},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"external_commands:references/artifact-development.md:105:powershell-invocation","file":"references/artifact-development.md","pattern":"PowerShell invocation","snippet":"default: \"(?i)(powershell|cmd)\"","category":"external_commands","line_end":105,"severity":"high","line_start":105},{"id":"external_commands:references/artifact-development.md:509:powershell-invocation","file":"references/artifact-development.md","pattern":"PowerShell invocation","snippet":"SELECT * FROM pslist() WHERE Name =~ \"powershell\" LIMIT 10","category":"external_commands","line_end":509,"severity":"high","line_start":509},{"id":"external_commands:references/artifact-development.md:512:powershell-invocation","file":"references/artifact-development.md","pattern":"PowerShell invocation","snippet":"LET ProcessPattern = \"(?i)(powershell|cmd)\"","category":"external_commands","line_end":512,"severity":"high","line_start":512},{"id":"network:references/artifact-development.md:594:hardcoded-url","file":"references/artifact-development.md","pattern":"Hardcoded URL","snippet":"- https://attack.mitre.org/techniques/T1547/001/","category":"network","line_end":594,"severity":"low","line_start":594},{"id":"network:references/artifact-development.md:595:hardcoded-url","file":"references/artifact-development.md","pattern":"Hardcoded URL","snippet":"- https://attack.mitre.org/techniques/T1053/005/","category":"network","line_end":595,"severity":"low","line_start":595},{"id":"network:references/artifact-development.md:410:hardcoded-ip-address","file":"references/artifact-development.md","pattern":"Hardcoded IP address","snippet":"192.0.2.1,C2 Server","category":"network","line_end":410,"severity":"medium","line_start":410},{"id":"network:references/artifact-development.md:411:hardcoded-ip-address","file":"references/artifact-development.md","pattern":"Hardcoded IP address","snippet":"198.51.100.50,Malicious Host","category":"network","line_end":411,"severity":"medium","line_start":411},{"id":"blocker:references/artifact-development.md:410:c2-keywords","file":"references/artifact-development.md","pattern":"C2 keywords","snippet":"192.0.2.1,C2 Server","category":"blocker","line_end":410,"severity":"high","line_start":410},{"id":"blocker:references/artifact-development.md:446:windows-registry-access","file":"references/artifact-development.md","pattern":"Windows registry access","snippet":"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/**","category":"blocker","line_end":446,"severity":"high","line_start":446},{"id":"blocker:references/artifact-development.md:245:system-reconnaissance","file":"references/artifact-development.md","pattern":"System reconnaissance","snippet":"JOIN NetworkConnections nc ON sp.Pid = nc.Pid","category":"blocker","line_end":245,"severity":"low","line_start":245},{"id":"blocker:references/artifact-development.md:374:system-reconnaissance","file":"references/artifact-development.md","pattern":"System reconnaissance","snippet":"WHERE Ppid = ParentPID","category":"blocker","line_end":374,"severity":"low","line_start":374},{"id":"blocker:references/artifact-development.md:178:network-reconnaissance","file":"references/artifact-development.md","pattern":"Network reconnaissance","snippet":"SELECT * FROM netstat()","category":"blocker","line_end":178,"severity":"low","line_start":178},{"id":"blocker:references/artifact-development.md:237:network-reconnaissance","file":"references/artifact-development.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":237,"severity":"low","line_start":237},{"id":"blocker:references/artifact-development.md:425:network-reconnaissance","file":"references/artifact-development.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":425,"severity":"low","line_start":425},{"id":"external_commands:references/deployment-guide.md:285:ruby-shell-backtick-execution","file":"references/deployment-guide.md","pattern":"Ruby/shell backtick execution","snippet":"--config \"C:\\Program Files\\Velociraptor\\client.config.yaml\" `","category":"external_commands","line_end":290,"severity":"medium","line_start":285},{"id":"external_commands:references/deployment-guide.md:520:shell-command-substitution","file":"references/deployment-guide.md","pattern":"Shell command substitution","snippet":"DATE=$(date +%Y%m%d-%H%M%S)","category":"external_commands","line_end":520,"severity":"medium","line_start":520},{"id":"external_commands:references/deployment-guide.md:278:powershell-invocation","file":"references/deployment-guide.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":278,"severity":"high","line_start":278},{"id":"external_commands:references/deployment-guide.md:515:unix-shell-invocation","file":"references/deployment-guide.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":515,"severity":"medium","line_start":515},{"id":"external_commands:references/deployment-guide.md:81:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo mv velociraptor-v0.72.3-linux-amd64 /usr/local/bin/velociraptor","category":"external_commands","line_end":81,"severity":"high","line_start":81},{"id":"external_commands:references/deployment-guide.md:145:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo cat > /etc/systemd/system/velociraptor.service <<'EOF'","category":"external_commands","line_end":145,"severity":"high","line_start":145},{"id":"external_commands:references/deployment-guide.md:173:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo useradd -r -s /bin/false velociraptor","category":"external_commands","line_end":173,"severity":"high","line_start":173},{"id":"external_commands:references/deployment-guide.md:176:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo mkdir -p /etc/velociraptor /var/lib/velociraptor","category":"external_commands","line_end":176,"severity":"high","line_start":176},{"id":"external_commands:references/deployment-guide.md:177:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo chown -R velociraptor:velociraptor /etc/velociraptor /var/lib/velociraptor","category":"external_commands","line_end":177,"severity":"high","line_start":177},{"id":"external_commands:references/deployment-guide.md:180:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl daemon-reload","category":"external_commands","line_end":180,"severity":"high","line_start":180},{"id":"external_commands:references/deployment-guide.md:181:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl enable velociraptor","category":"external_commands","line_end":181,"severity":"high","line_start":181},{"id":"external_commands:references/deployment-guide.md:182:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl start velociraptor","category":"external_commands","line_end":182,"severity":"high","line_start":182},{"id":"external_commands:references/deployment-guide.md:215:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo apt install certbot","category":"external_commands","line_end":215,"severity":"high","line_start":215},{"id":"external_commands:references/deployment-guide.md:218:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo certbot certonly --standalone \\","category":"external_commands","line_end":218,"severity":"high","line_start":218},{"id":"external_commands:references/deployment-guide.md:272:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"# Install: sudo dpkg -i velociraptor-client.deb","category":"external_commands","line_end":272,"severity":"high","line_start":272},{"id":"external_commands:references/deployment-guide.md:295:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo cp velociraptor /usr/local/bin/","category":"external_commands","line_end":295,"severity":"high","line_start":295},{"id":"external_commands:references/deployment-guide.md:296:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo cp client.config.yaml /etc/velociraptor/","category":"external_commands","line_end":296,"severity":"high","line_start":296},{"id":"external_commands:references/deployment-guide.md:299:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo cat > /etc/systemd/system/velociraptor-client.service <<'EOF'","category":"external_commands","line_end":299,"severity":"high","line_start":299},{"id":"external_commands:references/deployment-guide.md:315:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl enable velociraptor-client","category":"external_commands","line_end":315,"severity":"high","line_start":315},{"id":"external_commands:references/deployment-guide.md:316:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl start velociraptor-client","category":"external_commands","line_end":316,"severity":"high","line_start":316},{"id":"external_commands:references/deployment-guide.md:380:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo apt install nfs-kernel-server","category":"external_commands","line_end":380,"severity":"high","line_start":380},{"id":"external_commands:references/deployment-guide.md:381:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo mkdir -p /export/velociraptor","category":"external_commands","line_end":381,"severity":"high","line_start":381},{"id":"external_commands:references/deployment-guide.md:382:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo chown nobody:nogroup /export/velociraptor","category":"external_commands","line_end":382,"severity":"high","line_start":382},{"id":"external_commands:references/deployment-guide.md:388:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo mount -t nfs nfs-server:/export/velociraptor /var/lib/velociraptor","category":"external_commands","line_end":388,"severity":"high","line_start":388},{"id":"external_commands:references/deployment-guide.md:408:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo iptables -A INPUT -p tcp --dport 8000 -j ACCEPT","category":"external_commands","line_end":408,"severity":"high","line_start":408},{"id":"external_commands:references/deployment-guide.md:411:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo iptables -A INPUT -p tcp --dport 8889 -s 10.0.0.0/8 -j ACCEPT","category":"external_commands","line_end":411,"severity":"high","line_start":411},{"id":"external_commands:references/deployment-guide.md:412:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo iptables -A INPUT -p tcp --dport 8889 -j DROP","category":"external_commands","line_end":412,"severity":"high","line_start":412},{"id":"external_commands:references/deployment-guide.md:415:sudo-privilege-escalation","file":"references/deployment-guide.md","pattern":"sudo privilege escalation","snippet":"sudo iptables-save > /etc/iptables/rules.v4","category":"external_commands","line_end":415,"severity":"high","line_start":415},{"id":"network:references/deployment-guide.md:77:hardcoded-url","file":"references/deployment-guide.md","pattern":"Hardcoded URL","snippet":"wget https://github.com/Velocidex/velociraptor/releases/download/v0.72/velociraptor-v0.72.3-linux-am","category":"network","line_end":77,"severity":"low","line_start":77},{"id":"network:references/deployment-guide.md:110:hardcoded-url","file":"references/deployment-guide.md","pattern":"Hardcoded URL","snippet":"- https://velociraptor.company.com:8000/","category":"network","line_end":110,"severity":"low","line_start":110},{"id":"network:references/deployment-guide.md:200:hardcoded-url","file":"references/deployment-guide.md","pattern":"Hardcoded URL","snippet":"# Access GUI at: https://velociraptor.company.com:8889/","category":"network","line_end":200,"severity":"low","line_start":200},{"id":"network:references/deployment-guide.md:325:hardcoded-url","file":"references/deployment-guide.md","pattern":"Hardcoded URL","snippet":"- https://velociraptor.company.com:8000/","category":"network","line_end":325,"severity":"low","line_start":325},{"id":"network:references/deployment-guide.md:117:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"bind_address: 0.0.0.0","category":"network","line_end":117,"severity":"medium","line_start":117},{"id":"network:references/deployment-guide.md:122:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"bind_address: 0.0.0.0","category":"network","line_end":122,"severity":"medium","line_start":122},{"id":"network:references/deployment-guide.md:126:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"- 10.0.0.0/8","category":"network","line_end":126,"severity":"medium","line_start":126},{"id":"network:references/deployment-guide.md:127:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"- 172.16.0.0/12","category":"network","line_end":127,"severity":"medium","line_start":127},{"id":"network:references/deployment-guide.md:128:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"- 192.168.0.0/16","category":"network","line_end":128,"severity":"medium","line_start":128},{"id":"network:references/deployment-guide.md:132:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"bind_address: 0.0.0.0","category":"network","line_end":132,"severity":"medium","line_start":132},{"id":"network:references/deployment-guide.md:357:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo1 10.0.1.10:8000 check","category":"network","line_end":357,"severity":"medium","line_start":357},{"id":"network:references/deployment-guide.md:358:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo2 10.0.1.11:8000 check","category":"network","line_end":358,"severity":"medium","line_start":358},{"id":"network:references/deployment-guide.md:359:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo3 10.0.1.12:8000 check","category":"network","line_end":359,"severity":"medium","line_start":359},{"id":"network:references/deployment-guide.md:370:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo1 10.0.1.10:8889 check","category":"network","line_end":370,"severity":"medium","line_start":370},{"id":"network:references/deployment-guide.md:371:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo2 10.0.1.11:8889 check","category":"network","line_end":371,"severity":"medium","line_start":371},{"id":"network:references/deployment-guide.md:372:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"server velo3 10.0.1.12:8889 check","category":"network","line_end":372,"severity":"medium","line_start":372},{"id":"network:references/deployment-guide.md:385:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"/export/velociraptor 10.0.1.0/24(rw,sync,no_subtree_check,no_root_squash)","category":"network","line_end":385,"severity":"medium","line_start":385},{"id":"network:references/deployment-guide.md:411:hardcoded-ip-address","file":"references/deployment-guide.md","pattern":"Hardcoded IP address","snippet":"sudo iptables -A INPUT -p tcp --dport 8889 -s 10.0.0.0/8 -j ACCEPT","category":"network","line_end":411,"severity":"medium","line_start":411},{"id":"filesystem:references/deployment-guide.md:246:temp-directory-access","file":"references/deployment-guide.md","pattern":"Temp directory access","snippet":"config client > /tmp/client.config.yaml","category":"filesystem","line_end":246,"severity":"medium","line_start":246},{"id":"env_access:references/deployment-guide.md:231:generic-api-secret-keys","file":"references/deployment-guide.md","pattern":"Generic API/secret keys","snippet":"private_key: /path/to/server-key.pem","category":"env_access","line_end":231,"severity":"high","line_start":231},{"id":"env_access:references/deployment-guide.md:236:generic-api-secret-keys","file":"references/deployment-guide.md","pattern":"Generic API/secret keys","snippet":"private_key: /path/to/gui-key.pem","category":"env_access","line_end":236,"severity":"high","line_start":236},{"id":"sensitive:references/deployment-guide.md:230:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"certificate: /path/to/server-cert.pem","category":"sensitive","line_end":230,"severity":"high","line_start":230},{"id":"sensitive:references/deployment-guide.md:231:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"private_key: /path/to/server-key.pem","category":"sensitive","line_end":231,"severity":"high","line_start":231},{"id":"sensitive:references/deployment-guide.md:235:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"certificate: /path/to/gui-cert.pem","category":"sensitive","line_end":235,"severity":"high","line_start":235},{"id":"sensitive:references/deployment-guide.md:236:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"private_key: /path/to/gui-key.pem","category":"sensitive","line_end":236,"severity":"high","line_start":236},{"id":"sensitive:references/deployment-guide.md:349:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"bind *:8000 ssl crt /etc/ssl/certs/velociraptor.pem","category":"sensitive","line_end":349,"severity":"high","line_start":349},{"id":"sensitive:references/deployment-guide.md:362:certificate-key-files","file":"references/deployment-guide.md","pattern":"Certificate/key files","snippet":"bind *:8889 ssl crt /etc/ssl/certs/velociraptor.pem","category":"sensitive","line_end":362,"severity":"high","line_start":362},{"id":"blocker:references/deployment-guide.md:181:systemd-service-enablement","file":"references/deployment-guide.md","pattern":"Systemd service enablement","snippet":"sudo systemctl enable velociraptor","category":"blocker","line_end":181,"severity":"high","line_start":181},{"id":"blocker:references/deployment-guide.md:315:systemd-service-enablement","file":"references/deployment-guide.md","pattern":"Systemd service enablement","snippet":"sudo systemctl enable velociraptor-client","category":"blocker","line_end":315,"severity":"high","line_start":315},{"id":"blocker:references/deployment-guide.md:93:system-reconnaissance","file":"references/deployment-guide.md","pattern":"System reconnaissance","snippet":"--frontend_hostname velociraptor.company.com \\","category":"blocker","line_end":93,"severity":"low","line_start":93},{"id":"blocker:references/deployment-guide.md:131:system-reconnaissance","file":"references/deployment-guide.md","pattern":"System reconnaissance","snippet":"hostname: velociraptor.company.com","category":"blocker","line_end":131,"severity":"low","line_start":131},{"id":"blocker:references/deployment-guide.md:493:system-reconnaissance","file":"references/deployment-guide.md","pattern":"System reconnaissance","snippet":"query \"SELECT client_id, os_info.hostname, last_seen_at FROM clients()\"","category":"blocker","line_end":493,"severity":"low","line_start":493},{"id":"blocker:references/deployment-guide.md:504:system-reconnaissance","file":"references/deployment-guide.md","pattern":"System reconnaissance","snippet":"os_info.hostname AS Hostname,","category":"blocker","line_end":504,"severity":"low","line_start":504},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","file":"references/EXAMPLE.md","pattern":"document.write injection","snippet":"document.write(userInput);","category":"scripts","line_end":138,"severity":"high","line_start":138},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","file":"references/EXAMPLE.md","pattern":"innerHTML assignment (XSS risk)","snippet":"element.innerHTML = userInput;","category":"scripts","line_end":137,"severity":"medium","line_start":137},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","file":"references/EXAMPLE.md","pattern":"Python environment access","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"low","line_start":423},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"high","line_start":423},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not VALID_API_KEY:","category":"env_access","line_end":424,"severity":"high","line_start":424},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":425,"severity":"high","line_start":425},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"def require_api_key(f):","category":"env_access","line_end":427,"severity":"high","line_start":427},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"api_key = request.headers.get('X-API-Key')","category":"env_access","line_end":430,"severity":"high","line_start":430},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":432,"severity":"high","line_start":432},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not hmac.compare_digest(api_key, VALID_API_KEY):","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"@require_api_key","category":"env_access","line_end":444,"severity":"high","line_start":444},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","file":"references/EXAMPLE.md","pattern":"C2 keywords","snippet":"- **T1041**: Exfiltration Over C2 Channel","category":"blocker","line_end":276,"severity":"high","line_start":276},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"- **T1078**: Valid Accounts","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":298,"severity":"low","line_start":298},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = %s\", (user_id,))","category":"blocker","line_end":301,"severity":"low","line_start":301},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"result = session.execute(text(\"SELECT * FROM users WHERE id = :id\"), {\"id\": user_id})","category":"blocker","line_end":305,"severity":"low","line_start":305},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid user ID format\")","category":"blocker","line_end":314,"severity":"low","line_start":314},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"return jsonify({'error': 'Invalid API key'}), 403","category":"blocker","line_end":438,"severity":"low","line_start":438},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"is_valid = verify_password(\"user_password\", stored_hash)  # True","category":"blocker","line_end":471,"severity":"low","line_start":471},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid file type\")","category":"blocker","line_end":523,"severity":"low","line_start":523},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"import uuid","category":"blocker","line_end":530,"severity":"low","line_start":529},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","file":"references/EXAMPLE.md","pattern":"Network reconnaissance","snippet":"- xss","category":"blocker","line_end":382,"severity":"low","line_start":381},{"id":"external_commands:references/mitre-attack-mapping.md:59:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"WHERE Content =~ \"(?i)(macro|vba|shell|exec|powershell)\"","category":"external_commands","line_end":59,"severity":"high","line_start":59},{"id":"external_commands:references/mitre-attack-mapping.md:65:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"### T1059.001: PowerShell","category":"external_commands","line_end":65,"severity":"high","line_start":65},{"id":"external_commands:references/mitre-attack-mapping.md:68:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"- `Windows.EventLogs.PowershellScriptblock`","category":"external_commands","line_end":68,"severity":"high","line_start":68},{"id":"external_commands:references/mitre-attack-mapping.md:69:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"- `Windows.System.Powershell.PSReadline`","category":"external_commands","line_end":69,"severity":"high","line_start":69},{"id":"external_commands:references/mitre-attack-mapping.md:73:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"-- Malicious PowerShell execution","category":"external_commands","line_end":73,"severity":"high","line_start":73},{"id":"external_commands:references/mitre-attack-mapping.md:77:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"FROM parse_evtx(filename=\"C:/Windows/System32/winevt/Logs/Microsoft-Windows-PowerShell%4Operational.","category":"external_commands","line_end":77,"severity":"high","line_start":77},{"id":"external_commands:references/mitre-attack-mapping.md:165:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"OR ImagePath.value =~ \"(?i)(powershell|cmd|wscript)\"","category":"external_commands","line_end":165,"severity":"high","line_start":165},{"id":"external_commands:references/mitre-attack-mapping.md:188:powershell-invocation","file":"references/mitre-attack-mapping.md","pattern":"PowerShell invocation","snippet":"WHERE ConsumerData =~ \"(?i)(powershell|cmd|wscript|executable)\"","category":"external_commands","line_end":188,"severity":"high","line_start":188},{"id":"external_commands:references/mitre-attack-mapping.md:91:windows-cmd-exe","file":"references/mitre-attack-mapping.md","pattern":"Windows cmd.exe","snippet":"-- Suspicious cmd.exe usage","category":"external_commands","line_end":91,"severity":"high","line_start":91},{"id":"external_commands:references/mitre-attack-mapping.md:94:windows-cmd-exe","file":"references/mitre-attack-mapping.md","pattern":"Windows cmd.exe","snippet":"WHERE Name =~ \"(?i)cmd.exe\"","category":"external_commands","line_end":94,"severity":"high","line_start":94},{"id":"network:references/mitre-attack-mapping.md:419:hardcoded-ip-address","file":"references/mitre-attack-mapping.md","pattern":"Hardcoded IP address","snippet":"AND EventData.IpAddress != \"127.0.0.1\"","category":"network","line_end":419,"severity":"medium","line_start":419},{"id":"sensitive:references/mitre-attack-mapping.md:347:browser-credential-files","file":"references/mitre-attack-mapping.md","pattern":"Browser credential files","snippet":"\"C:/Users/*/AppData/Local/Google/Chrome/User Data/*/Login Data\",","category":"sensitive","line_end":347,"severity":"critical","line_start":347},{"id":"sensitive:references/mitre-attack-mapping.md:338:windows-dpapi-access","file":"references/mitre-attack-mapping.md","pattern":"Windows DPAPI access","snippet":"- `Windows.Forensics.DPAPI`","category":"sensitive","line_end":338,"severity":"critical","line_start":338},{"id":"sensitive:references/mitre-attack-mapping.md:328:windows-sam-registry-hive-access","file":"references/mitre-attack-mapping.md","pattern":"Windows SAM/registry hive access","snippet":"\"C:/Windows/System32/config/SAM\",","category":"sensitive","line_end":328,"severity":"critical","line_start":328},{"id":"sensitive:references/mitre-attack-mapping.md:329:windows-sam-registry-hive-access","file":"references/mitre-attack-mapping.md","pattern":"Windows SAM/registry hive access","snippet":"\"C:/Windows/System32/config/SYSTEM\",","category":"sensitive","line_end":329,"severity":"critical","line_start":329},{"id":"sensitive:references/mitre-attack-mapping.md:330:windows-sam-registry-hive-access","file":"references/mitre-attack-mapping.md","pattern":"Windows SAM/registry hive access","snippet":"\"C:/Windows/System32/config/SECURITY\"","category":"sensitive","line_end":330,"severity":"critical","line_start":330},{"id":"blocker:references/mitre-attack-mapping.md:16:c2-keywords","file":"references/mitre-attack-mapping.md","pattern":"C2 keywords","snippet":"- [Command and Control](#command-and-control)","category":"blocker","line_end":16,"severity":"high","line_start":16},{"id":"blocker:references/mitre-attack-mapping.md:504:c2-keywords","file":"references/mitre-attack-mapping.md","pattern":"C2 keywords","snippet":"### T1041: Exfiltration Over C2 Channel","category":"blocker","line_end":504,"severity":"high","line_start":504},{"id":"blocker:references/mitre-attack-mapping.md:138:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*\",","category":"blocker","line_end":138,"severity":"high","line_start":138},{"id":"blocker:references/mitre-attack-mapping.md:139:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/RunOnce/*\",","category":"blocker","line_end":139,"severity":"high","line_start":139},{"id":"blocker:references/mitre-attack-mapping.md:141:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/WOW6432Node/Microsoft/Windows/CurrentVersion/Run/*\"","category":"blocker","line_end":141,"severity":"high","line_start":141},{"id":"blocker:references/mitre-attack-mapping.md:161:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"FROM read_reg_key(globs=\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/*\")","category":"blocker","line_end":161,"severity":"high","line_start":161},{"id":"blocker:references/mitre-attack-mapping.md:262:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows Defender/**\",","category":"blocker","line_end":262,"severity":"high","line_start":262},{"id":"blocker:references/mitre-attack-mapping.md:263:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Policies/Microsoft/Windows Defender/**\",","category":"blocker","line_end":263,"severity":"high","line_start":263},{"id":"blocker:references/mitre-attack-mapping.md:264:windows-registry-access","file":"references/mitre-attack-mapping.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/WinDefend/**\"","category":"blocker","line_end":264,"severity":"high","line_start":264},{"id":"blocker:references/mitre-attack-mapping.md:20:system-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"System reconnaissance","snippet":"### T1078: Valid Accounts","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:references/mitre-attack-mapping.md:96:system-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"System reconnaissance","snippet":"AND Ppid IN (","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/mitre-attack-mapping.md:97:system-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"System reconnaissance","snippet":"SELECT Pid FROM pslist()","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/mitre-attack-mapping.md:367:system-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"System reconnaissance","snippet":"WHERE CommandLine =~ \"(?i)(systeminfo|whoami|ipconfig|hostname|ver)\"","category":"blocker","line_end":367,"severity":"low","line_start":367},{"id":"blocker:references/mitre-attack-mapping.md:454:system-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"System reconnaissance","snippet":"Ppid IN (SELECT Pid FROM pslist() WHERE Name =~ \"(?i)wmiprvse.exe\")","category":"blocker","line_end":454,"severity":"low","line_start":454},{"id":"blocker:references/mitre-attack-mapping.md:397:network-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"Network reconnaissance","snippet":"WHERE CommandLine =~ \"(?i)(netstat|net use|net view|arp|route print|nslookup)\"","category":"blocker","line_end":397,"severity":"low","line_start":397},{"id":"blocker:references/mitre-attack-mapping.md:519:network-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":519,"severity":"low","line_start":519},{"id":"blocker:references/mitre-attack-mapping.md:557:network-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":557,"severity":"low","line_start":557},{"id":"blocker:references/mitre-attack-mapping.md:579:network-reconnaissance","file":"references/mitre-attack-mapping.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":579,"severity":"low","line_start":579},{"id":"external_commands:references/vql-patterns.md:28:powershell-invocation","file":"references/vql-patterns.md","pattern":"PowerShell invocation","snippet":"AND Name =~ \"(?i)(powershell|cmd|wscript|cscript)\")","category":"external_commands","line_end":28,"severity":"high","line_start":28},{"id":"external_commands:references/vql-patterns.md:476:powershell-invocation","file":"references/vql-patterns.md","pattern":"PowerShell invocation","snippet":"-- Suspicious PowerShell/VBS scripts","category":"external_commands","line_end":476,"severity":"high","line_start":476},{"id":"blocker:references/vql-patterns.md:164:malware-type-keywords","file":"references/vql-patterns.md","pattern":"Malware type keywords","snippet":"OR FullPath =~ \"(?i)(cmd|shell|upload|backdoor|c99)\"","category":"blocker","line_end":164,"severity":"high","line_start":164},{"id":"blocker:references/vql-patterns.md:191:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*\",","category":"blocker","line_end":191,"severity":"high","line_start":191},{"id":"blocker:references/vql-patterns.md:192:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/RunOnce/*\",","category":"blocker","line_end":192,"severity":"high","line_start":192},{"id":"blocker:references/vql-patterns.md:194:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/WOW6432Node/Microsoft/Windows/CurrentVersion/Run/*\",","category":"blocker","line_end":194,"severity":"high","line_start":194},{"id":"blocker:references/vql-patterns.md:195:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/*\"","category":"blocker","line_end":195,"severity":"high","line_start":195},{"id":"blocker:references/vql-patterns.md:207:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/**\",","category":"blocker","line_end":207,"severity":"high","line_start":207},{"id":"blocker:references/vql-patterns.md:208:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/**\",","category":"blocker","line_end":208,"severity":"high","line_start":208},{"id":"blocker:references/vql-patterns.md:223:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Windows/AppInit_DLLs\",","category":"blocker","line_end":223,"severity":"high","line_start":223},{"id":"blocker:references/vql-patterns.md:224:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"\"HKEY_LOCAL_MACHINE/SOFTWARE/WOW6432Node/Microsoft/Windows NT/CurrentVersion/Windows/AppInit_DLLs\"","category":"blocker","line_end":224,"severity":"high","line_start":224},{"id":"blocker:references/vql-patterns.md:311:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"FROM read_reg_key(globs=\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*\")","category":"blocker","line_end":311,"severity":"high","line_start":311},{"id":"blocker:references/vql-patterns.md:318:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"FROM read_reg_key(globs=\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/**/ImagePath\")","category":"blocker","line_end":318,"severity":"high","line_start":318},{"id":"blocker:references/vql-patterns.md:419:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"FROM read_reg_key(globs=\"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Enum/USBSTOR/**/FriendlyName\")","category":"blocker","line_end":419,"severity":"high","line_start":419},{"id":"blocker:references/vql-patterns.md:531:windows-registry-access","file":"references/vql-patterns.md","pattern":"Windows registry access","snippet":"FROM glob(globs=\"HKEY_LOCAL_MACHINE/SOFTWARE/**\", accessor=\"registry\")","category":"blocker","line_end":531,"severity":"high","line_start":531},{"id":"blocker:references/vql-patterns.md:27:system-reconnaissance","file":"references/vql-patterns.md","pattern":"System reconnaissance","snippet":"(Ppid IN (SELECT Pid FROM pslist() WHERE Name =~ \"(?i)(winword|excel|powerpnt|acrobat)\")","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:references/vql-patterns.md:510:system-reconnaissance","file":"references/vql-patterns.md","pattern":"System reconnaissance","snippet":"JOIN SuspiciousConnections sc ON sp.Pid = sc.Pid","category":"blocker","line_end":510,"severity":"low","line_start":510},{"id":"blocker:references/vql-patterns.md:511:system-reconnaissance","file":"references/vql-patterns.md","pattern":"System reconnaissance","snippet":"GROUP BY sp.Pid","category":"blocker","line_end":512,"severity":"low","line_start":511},{"id":"blocker:references/vql-patterns.md:87:network-reconnaissance","file":"references/vql-patterns.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":87,"severity":"low","line_start":87},{"id":"blocker:references/vql-patterns.md:102:network-reconnaissance","file":"references/vql-patterns.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":102,"severity":"low","line_start":102},{"id":"blocker:references/vql-patterns.md:501:network-reconnaissance","file":"references/vql-patterns.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":501,"severity":"low","line_start":501},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","file":"references/WORKFLOW_CHECKLIST.md","pattern":"Malware type keywords","snippet":"[ ] 10. Remove malicious artifacts (malware, backdoors, webshells)","category":"blocker","line_end":193,"severity":"high","line_start":193},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":50,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":54,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":66,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":85,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.EventLogs.RDP` - Remote desktop authentication events","category":"external_commands","line_end":86,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.System.Pslist` - Running processes with details","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.Network.NetstatEnriched` - Network connections with process context","category":"external_commands","line_end":88,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.Persistence.PermanentWMIEvents` - WMI-based persistence","category":"external_commands","line_end":89,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.Timeline.Prefetch` - Program execution timeline","category":"external_commands","line_end":90,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Windows.Forensics.Timeline` - Comprehensive filesystem timeline","category":"external_commands","line_end":127,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":137,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":151,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":157,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":169,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":175,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":181,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":187,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":194,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":202,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":221,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":244,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Collect: `Windows.Forensics.Timeline` for file modification patterns","category":"external_commands","line_end":245,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Collect: `Windows.EventLogs.Evtx` for authentication events","category":"external_commands","line_end":253,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Collect network connection history: `Windows.Network.NetstatEnriched`","category":"external_commands","line_end":284,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Limit concurrent VQL queries using `rate()` function","category":"external_commands","line_end":286,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `--ops_per_second` limit when creating offline collectors","category":"external_commands","line_end":293,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Check client logs: `velociraptor --config client.config.yaml logs`","category":"external_commands","line_end":303,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `log()` function to debug query execution","category":"external_commands","line_end":308,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Scripts (`scripts/`)","category":"external_commands","line_end":310,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `vql_query_builder.py` - Generate common VQL queries from templates","category":"external_commands","line_end":311,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `artifact_validator.py` - Validate custom artifact YAML syntax","category":"external_commands","line_end":312,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `evidence_collector.sh` - Automate offline collector deployment","category":"external_commands","line_end":314,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### References (`references/`)","category":"external_commands","line_end":316,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `vql-patterns.md` - Comprehensive VQL query patterns for common IR scenarios","category":"external_commands","line_end":317,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `artifact-development.md` - Guide to creating custom forensic artifacts","category":"external_commands","line_end":318,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mitre-attack-mapping.md` - MITRE ATT&CK technique detection artifacts","category":"external_commands","line_end":319,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `deployment-guide.md` - Enterprise server deployment and architecture","category":"external_commands","line_end":321,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Assets (`assets/`)","category":"external_commands","line_end":323,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `artifact-template.yaml` - Template for custom artifact development","category":"external_commands","line_end":324,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hunt-template.yaml` - Hunt configuration template with best practices","category":"external_commands","line_end":325,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:111:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"- Malicious PowerShell execution patterns","category":"external_commands","line_end":111,"severity":"high","line_start":111},{"id":"external_commands:SKILL.md:149:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"WHERE Name =~ \"(?i)(powershell|cmd|wscript|cscript)\"","category":"external_commands","line_end":149,"severity":"high","line_start":149},{"id":"external_commands:SKILL.md:193:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"WHERE ValueData =~ \"(?i)(powershell|cmd|wscript|rundll32)\"","category":"external_commands","line_end":193,"severity":"high","line_start":193},{"id":"external_commands:SKILL.md:209:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"default: \"(?i)(powershell|cmd|wscript)\"","category":"external_commands","line_end":209,"severity":"high","line_start":209},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://docs.velociraptor.app/","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://github.com/Velocidex/velociraptor","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://docs.velociraptor.app/artifact_references/","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:43:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# https://github.com/Velocidex/velociraptor/releases","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:SKILL.md:48:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Access web interface at https://127.0.0.1:8889/","category":"network","line_end":48,"severity":"low","line_start":48},{"id":"network:SKILL.md:329:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Velociraptor Documentation](https://docs.velociraptor.app/)","category":"network","line_end":329,"severity":"low","line_start":329},{"id":"network:SKILL.md:330:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [VQL Reference](https://docs.velociraptor.app/vql_reference/)","category":"network","line_end":330,"severity":"low","line_start":330},{"id":"network:SKILL.md:331:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Artifact Exchange](https://docs.velociraptor.app/exchange/)","category":"network","line_end":331,"severity":"low","line_start":331},{"id":"network:SKILL.md:332:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [GitHub Repository](https://github.com/Velocidex/velociraptor)","category":"network","line_end":332,"severity":"low","line_start":332},{"id":"network:SKILL.md:333:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [MITRE ATT&CK Framework](https://attack.mitre.org/)","category":"network","line_end":333,"severity":"low","line_start":333},{"id":"network:SKILL.md:48:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"# Access web interface at https://127.0.0.1:8889/","category":"network","line_end":48,"severity":"medium","line_start":48},{"id":"blocker:SKILL.md:241:ransomware-keywords","file":"SKILL.md","pattern":"Ransomware keywords","snippet":"### Pattern: Ransomware Investigation","category":"blocker","line_end":241,"severity":"critical","line_start":241},{"id":"blocker:SKILL.md:248:ransomware-keywords","file":"SKILL.md","pattern":"Ransomware keywords","snippet":"6. Extract: Ransomware binary samples for malware analysis","category":"blocker","line_end":248,"severity":"critical","line_start":248},{"id":"blocker:SKILL.md:192:windows-registry-access","file":"SKILL.md","pattern":"Windows registry access","snippet":"FROM read_reg_key(globs=\"HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/*\")","category":"blocker","line_end":192,"severity":"high","line_start":192},{"id":"blocker:SKILL.md:166:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"FROM netstat()","category":"blocker","line_end":166,"severity":"low","line_start":166},{"id":"obfuscation:multiple:1:heuristic-suspicious-combination-code-execution-","file":"multiple","pattern":"[HEURISTIC] SUSPICIOUS COMBINATION: Code execution + Persistence mechanism","snippet":"This combination is common in malware that maintains access","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"network:assets/artifact-template.yaml:126:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/artifact-template.yaml:127:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/artifact-template.yaml:132:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","reason":"The documented substitution runs a fixed local date or report parser command. No untrusted value controls the command structure.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","reason":"The documented substitution runs a fixed local date or report parser command. No untrusted value controls the command structure.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","reason":"The documented substitution runs a fixed local date or report parser command. No untrusted value controls the command structure.","verdict":"false_positive","confidence":0.91},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","reason":"The external URL supplies a script that is executed immediately by Bash. Trust in the remote branch and delivery path is security-critical.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","reason":"The CI script reads a fixed report path created in the same job. No user-controlled path or sensitive system file is involved.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","reason":"The CI script reads a fixed report path created in the same job. No user-controlled path or sensitive system file is involved.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","reason":"The workflow passes GITHUB_TOKEN to a third-party action while the workflow has write permissions. A compromised mutable action could misuse repository access.","verdict":"confirmed","severity":"high","confidence":0.9},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","reason":"The CI template downloads a mutable remote script and pipes it directly to Bash. A compromised source can execute arbitrary code on the runner.","verdict":"confirmed","severity":"critical","confidence":0.98},{"id":"external_commands:assets/hunt-template.yaml:36:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/hunt-template.yaml:115:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/hunt-template.yaml:183:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"network:assets/hunt-template.yaml:138:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/hunt-template.yaml:138:slack-webhook","reason":"The webhook value ends with an ellipsis and is an obvious configuration placeholder. No usable Slack credential is present.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/hunt-template.yaml:112:c2-keywords","reason":"The phrase appears in defensive hunt criteria, ATT&CK headings, or TEST-NET IOC examples. It describes activity to detect, not command-and-control behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/hunt-template.yaml:58:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/hunt-template.yaml:190:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/hunt-template.yaml:204:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:assets/offline-collector-config.yaml:94:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:assets/offline-collector-config.yaml:208:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"blocker:assets/offline-collector-config.yaml:250:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","reason":"This is defensive example code showing how to load an API key from the environment. It does not expose or transmit the value.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","reason":"This is defensive example code showing how to load an API key from the environment. It does not expose or transmit the value.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","reason":"This is defensive example code showing how to load an API key from the environment. It does not expose or transmit the value.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","reason":"This is defensive example code showing how to load an API key from the environment. It does not expose or transmit the value.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","reason":"The line references process.env.API_KEY in remediation guidance. It does not open a dotenv file or enumerate environment contents.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/artifact-development.md:105:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/artifact-development.md:509:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/artifact-development.md:512:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"network:references/artifact-development.md:594:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:references/artifact-development.md:595:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:references/artifact-development.md:410:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/artifact-development.md:411:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/artifact-development.md:410:c2-keywords","reason":"The phrase appears in defensive hunt criteria, ATT&CK headings, or TEST-NET IOC examples. It describes activity to detect, not command-and-control behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:446:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:245:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:374:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:178:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:237:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/artifact-development.md:425:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/deployment-guide.md:285:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/deployment-guide.md:520:shell-command-substitution","reason":"The documented substitution runs a fixed local date or report parser command. No untrusted value controls the command structure.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deployment-guide.md:278:powershell-invocation","reason":"The fenced PowerShell example installs and starts Velociraptor as a persistent Windows service. Following it performs real privileged endpoint modification.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:515:unix-shell-invocation","reason":"This line is a Bash shebang for a documented backup example. A shebang alone is not command injection or hidden execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/deployment-guide.md:81:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:145:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:173:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:176:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:177:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:180:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:181:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:182:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:215:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:218:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:272:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:295:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:296:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:299:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:315:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:316:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:380:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:381:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:382:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:388:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:408:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:411:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:412:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/deployment-guide.md:415:sudo-privilege-escalation","reason":"This deployment instruction uses sudo to change packages, system files, services, mounts, or firewall state. It requires explicit authorization and host-specific review.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:references/deployment-guide.md:77:hardcoded-url","reason":"The guide downloads an executable for privileged installation without checksum or signature verification. A replaced release artifact could gain root execution.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:references/deployment-guide.md:110:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:200:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:325:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:117:hardcoded-ip-address","reason":"The example binds the API to every interface. Without a separate access control, administrative functions may be reachable from unintended networks.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"network:references/deployment-guide.md:122:hardcoded-ip-address","reason":"The example binds the management GUI to every interface. This broad exposure increases authentication and web attack surface.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"network:references/deployment-guide.md:126:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:127:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:128:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:132:hardcoded-ip-address","reason":"The frontend listens on every interface to accept clients. The deployment must constrain exposure with tested firewall and TLS controls.","verdict":"confirmed","severity":"medium","confidence":0.83},{"id":"network:references/deployment-guide.md:357:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:358:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:359:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:370:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:371:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:372:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deployment-guide.md:385:hardcoded-ip-address","reason":"The NFS example hardcodes a trusted subnet and combines it with no_root_squash. A compromised client in that range can obtain root-level file access.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"network:references/deployment-guide.md:411:hardcoded-ip-address","reason":"The firewall example trusts the entire 10.0.0.0/8 range for GUI access. That range may be much broader than the intended management network.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"filesystem:references/deployment-guide.md:246:temp-directory-access","reason":"The guide writes generated client configuration into a shared temporary directory. Weak permissions or local races could expose or replace sensitive configuration.","verdict":"confirmed","severity":"medium","confidence":0.72},{"id":"env_access:references/deployment-guide.md:231:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/deployment-guide.md:236:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/deployment-guide.md:230:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/deployment-guide.md:231:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/deployment-guide.md:235:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/deployment-guide.md:236:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/deployment-guide.md:349:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/deployment-guide.md:362:certificate-key-files","reason":"The line references placeholder or expected certificate paths in example configuration. It does not copy, disclose, or transmit key material.","verdict":"false_positive","confidence":0.91},{"id":"blocker:references/deployment-guide.md:181:systemd-service-enablement","reason":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"blocker:references/deployment-guide.md:315:systemd-service-enablement","reason":"The guide enables a persistent Velociraptor service at system startup. This changes host persistence and expands the impact of a compromised binary or configuration.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"blocker:references/deployment-guide.md:93:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/deployment-guide.md:131:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/deployment-guide.md:493:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/deployment-guide.md:504:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","reason":"The unsafe statement is explicitly labeled as vulnerable educational material and is followed by remediation. It is not executable skill code.","verdict":"false_positive","confidence":0.97},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","reason":"The unsafe statement is explicitly labeled as vulnerable educational material and is followed by remediation. It is not executable skill code.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","reason":"This is defensive example code showing how to load an API key from the environment. It does not expose or transmit the value.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","reason":"The match is a placeholder, variable name, validation branch, or secure authentication example. No live credential is embedded or exfiltrated.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","reason":"The phrase appears in defensive hunt criteria, ATT&CK headings, or TEST-NET IOC examples. It describes activity to detect, not command-and-control behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:59:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:65:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:68:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:69:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:73:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:77:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:165:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:188:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:91:windows-cmd-exe","reason":"The VQL query searches process telemetry for suspicious cmd.exe use. It does not start cmd.exe or execute a command.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/mitre-attack-mapping.md:94:windows-cmd-exe","reason":"The VQL query searches process telemetry for suspicious cmd.exe use. It does not start cmd.exe or execute a command.","verdict":"false_positive","confidence":0.97},{"id":"network:references/mitre-attack-mapping.md:419:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:references/mitre-attack-mapping.md:347:browser-credential-files","reason":"The forensic query returns only file paths and access timestamps. It does not read or export browser credential database contents.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/mitre-attack-mapping.md:338:windows-dpapi-access","reason":"The text only names a Velociraptor forensic artifact in an ATT&CK mapping. It does not call DPAPI or decrypt credentials.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/mitre-attack-mapping.md:328:windows-sam-registry-hive-access","reason":"The forensic query checks hive path timestamps only. It does not read hive contents, extract hashes, or export credentials.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/mitre-attack-mapping.md:329:windows-sam-registry-hive-access","reason":"The forensic query checks hive path timestamps only. It does not read hive contents, extract hashes, or export credentials.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/mitre-attack-mapping.md:330:windows-sam-registry-hive-access","reason":"The forensic query checks hive path timestamps only. It does not read hive contents, extract hashes, or export credentials.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:16:c2-keywords","reason":"The phrase appears in defensive hunt criteria, ATT&CK headings, or TEST-NET IOC examples. It describes activity to detect, not command-and-control behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:504:c2-keywords","reason":"The phrase appears in defensive hunt criteria, ATT&CK headings, or TEST-NET IOC examples. It describes activity to detect, not command-and-control behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:138:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:139:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:141:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:161:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:262:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:263:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:264:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:20:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:96:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:97:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:367:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:454:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:397:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:519:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:557:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/mitre-attack-mapping.md:579:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/vql-patterns.md:28:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/vql-patterns.md:476:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:164:malware-type-keywords","reason":"The term appears in a defensive detection regex or incident eradication checklist. It does not provide malware functionality or deployment instructions.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:191:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:192:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:194:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:195:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:207:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:208:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:223:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:224:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:311:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:318:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:419:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:531:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:27:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:510:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:511:system-reconnaissance","reason":"This is a read-only defensive query, placeholder, or unrelated secure-code example. It does not perform unauthorized discovery or transmit results.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:87:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:102:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/vql-patterns.md:501:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","reason":"The term appears in a defensive detection regex or incident eradication checklist. It does not provide malware functionality or deployment instructions.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The match is Markdown code fencing, inline code, or PowerShell line continuation. It does not invoke Ruby or perform shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:111:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:149:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:193:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:209:powershell-invocation","reason":"The text is a detection regex, technique label, or forensic query for identifying PowerShell activity. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:19:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:20:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:43:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:48:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:329:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:330:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:331:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:332:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:333:hardcoded-url","reason":"The URL is an official reference, loopback address, company placeholder, or explicit example. It does not receive secrets or trigger hidden network access.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:48:hardcoded-ip-address","reason":"The address is loopback, RFC1918, or TEST-NET data used in deployment or detection examples. It is not an attacker-controlled destination.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:241:ransomware-keywords","reason":"The text describes defensive ransomware investigation and evidence collection. It does not encrypt data, demand payment, or deploy ransomware.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:248:ransomware-keywords","reason":"The text describes defensive ransomware investigation and evidence collection. It does not encrypt data, demand payment, or deploy ransomware.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:192:windows-registry-access","reason":"The VQL reads registry metadata for persistence detection. It does not create, modify, or delete registry keys.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:166:network-reconnaissance","reason":"The VQL reads local connection telemetry for an authorized defensive hunt. It does not scan remote hosts or transmit collected data.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:multiple:1:heuristic-suspicious-combination-code-execution-","reason":"The combination comes from defensive detection queries and documented service deployment. No obfuscation or concealed execution chain exists.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Security scan failures are suppressed","severity":"high","locations":[{"file":"assets/ci-config-template.yml","line_end":61,"line_start":54},{"file":"assets/ci-config-template.yml","line_end":128,"line_start":116},{"file":"assets/ci-config-template.yml","line_end":235,"line_start":228}],"confidence":0.98,"description":"The CI template appends success fallbacks to several scanners. Tool failures and some findings can pass without an enforced security gate.","confidence_reasoning":"The template visibly uses success fallbacks after Semgrep, Safety, npm audit, and Checkov commands. Several jobs lack a reliable later failure check."},{"title":"Privileged binary installation lacks integrity verification","severity":"high","locations":[{"file":"references/deployment-guide.md","line_end":81,"line_start":73}],"confidence":0.98,"description":"The deployment guide downloads a Velociraptor executable and moves it into a privileged executable path without verifying a checksum or signature.","confidence_reasoning":"The displayed sequence performs wget, chmod, and sudo mv. No integrity verification appears between download and privileged installation."},{"title":"Mutable CI action can execute upstream changes","severity":"high","locations":[{"file":"assets/ci-config-template.yml","line_end":201,"line_start":196}],"confidence":0.99,"description":"The CI template runs the Trivy action from its mutable master branch. Future upstream changes can execute in repository workflows without review.","confidence_reasoning":"The action reference is explicitly aquasecurity/trivy-action@master. A branch is mutable and does not provide immutable supply-chain pinning."},{"title":"NFS evidence store disables root squashing","severity":"high","locations":[{"file":"references/deployment-guide.md","line_end":388,"line_start":377}],"confidence":0.99,"description":"The NFS example exports the evidence datastore with no_root_squash. A compromised root client can write files as root on the server.","confidence_reasoning":"The export option no_root_squash is explicit on line 385. This removes a standard NFS protection for remote root users."},{"title":"Malware sample handling lacks isolation controls","severity":"high","locations":[{"file":"SKILL.md","line_end":248,"line_start":241}],"confidence":0.86,"description":"The ransomware workflow directs analysts to extract binary samples without specifying quarantine, encrypted packaging, or isolated analysis requirements.","confidence_reasoning":"The workflow explicitly requests ransomware binary extraction. The surrounding steps do not state containment controls for handling executable malware samples."}],"subject_marketplace_commit_sha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","subject_content_hash":"0d73e6e09f7b5e3270508e6dda90e2711205f8859ff78db6361642eca73666b4","subject_tree_hash":"1439b1d2ab974f820924d76d6af755d2dcce6da9e8f5ecaf9aaeb61f90e8f3f2","subject_plugin_path":"skills/agentsecops/ir-velociraptor","audit_payload_hash":"bb158545e29bbb6e2446e8c6aefce6b6","confirmed_risk_level":"critical","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","contentHash":"0d73e6e09f7b5e3270508e6dda90e2711205f8859ff78db6361642eca73666b4","treeHash":"1439b1d2ab974f820924d76d6af755d2dcce6da9e8f5ecaf9aaeb61f90e8f3f2","pluginPath":"skills/agentsecops/ir-velociraptor","auditPayloadHash":"bb158545e29bbb6e2446e8c6aefce6b6"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-ir-velociraptor/audits/9/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":8,"capabilityReviewCount":34,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}