DFIR IRIS Module Velociraptor Quarantine - socarium/makarasoc GitHub Wiki
DFIR-IRIS Quarantine Module
Quarantine a Windows or Linux Endpoint using Velociraptor.
The module is built for the below Asset types:
- Windows
- Linux
- Select
DFIR IRIS Module Velociraptor Quarantine
.
- Once deployment finish, Access DFIR-IRIS from your Browser App.
-
Open the DFIR-IRIS via Browser App.
-
Navigate to
Advanced -> Modules
.
- Add a new module.
- Input the Module name:
iris_veloquarantine_module
- Select
Validate module
.
- The module will be automatically registered and activated.