Expert guide for authoring and validating Velociraptor forensic artifacts using VQL. Includes artifact schema validation, pattern library, VQL reference, and automated testing.
Security-focused Claude Code plugins for DFIR, detection engineering, and threat hunting by Digital Defense Institute.
/plugin marketplace add Digital-Defense-Institute/ddi-cc-plugins
| Plugin | Description |
|---|---|
| velociraptor-artifact | Author and validate Velociraptor forensic artifacts using VQL. Includes schema validation, VQL pattern library, and cross-platform binary validation. |
MIT
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub digital-defense-institute/ddi-cc-plugins --plugin velociraptor-artifactCore LimaCharlie skills for CLI-based API access, detection engineering, sensor tasking, case investigation, and fleet health monitoring.
YARA-X detection rule authoring with linting and quality analysis
Curated CQL detection engineering pattern catalog for CrowdStrike NG-SIEM — correlation, enrichment, aggregation, scoring, baselining, and more.
MalChela malware analysis toolkit — exposes file analysis, string extraction, hash lookup, NSRL queries, and directory scanning to Claude via MCP. Built for DFIR analysts and malware researchers.
Local cyber security assistant for PC issue detection, malware analysis, and system scanning
Assist with security incident response