Velociraptor 支持从端点收集打包在“Artifacts”(制品)中的 VQL 查询。这些制品功能强大,通常以高权限运行,能够执行各种操作。为了限制对某些危险制品的访问,Velociraptor 允许对部分制品设置高权限要求,例如必须拥有 EXECVE 权限才能触发执行。 是一个用于将 Sysmon 事件转发至服务器的监控型制品。该制品允许用户指定任意二进制文件路径作为参数,但未强制要求额外的权限验证。因此,拥有 COLLECT_CLIENT 权限的用户(通常由“Investigator”角色赋予)可以从
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Velociraptor | 0 ~ 0.77.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78411 | 6.5 MEDIUM | Velociraptor Server Metadata update with Insufficient Permission Check |
| CVE-2026-78412 | 4.9 MEDIUM | WatchEvent API streams another organization's live events |
No comments yet