DFIR IRIS Module Velociraptor Remove Quarantine - socarium/makarasoc GitHub Wiki
DFIR-IRIS Remove Quarantine Module
Remove quarantine a Windows or Linux Endpoint using Velociraptor.
The module is built for the below Asset types:
- Windows
- Linux
- Select
DFIR IRIS Module Velociraptor Remove Quarantine.

- Once deployment finish, Access DFIR-IRIS from your Browser App.

-
Open the DFIR-IRIS via Browser App.
-
Navigate to
Advanced -> Modules.

- Add a new module.

- Input the Module name:
iris_veloquarantineremove_module

- Select
Validate module. The module will be automatically registered and activated.
