手順 1Step 1
証跡を集める(Velociraptor オフラインコレクタ)Collect the evidence (Velociraptor offline collector)
疑わしい端末とは別の PC で収集ツールを作り、疑わしい端末で 1 回実行するだけです。端末にソフトを常駐させる必要はありません。
Build the collector on a different PC, then run it once on the suspect device. Nothing stays installed.
- 公式配布元(github.com/Velocidex/velociraptor)から Velociraptor を入手し、
velociraptor.exe guiで起動します。Download Velociraptor from its official releases (github.com/Velocidex/velociraptor) and start it withvelociraptor.exe gui. - 「Server Artifacts」→「Build Offline Collector」を開き、次のアーティファクトを選びます:
Windows.System.Pslist/Windows.Network.Netstat/Windows.Registry.*(Run キーなど) /Windows.EventLogs.*(Security・System・PowerShell)。Windows.Forensics.Prefetchもあると精度が上がります。Open "Server Artifacts" → "Build Offline Collector" and select:Windows.System.Pslist/Windows.Network.Netstat/Windows.Registry.*(Run keys etc.) /Windows.EventLogs.*(Security, System, PowerShell). AddingWindows.Forensics.Prefetchimproves the result. - 出力形式は ZIP のまま作成し、できたコレクタを疑わしい端末で管理者として実行します。
Collection-<ホスト名>-….zipが作られます。Keep ZIP as the output format, then run the collector on the suspect device as administrator. It writesCollection-<hostname>-….zip. - その ZIP を下のフォームからアップロードします(単体のアーティファクト JSON / CSV も受け付けます)。Upload that ZIP below (a single artifact JSON / CSV is accepted too).
手順 3Step 3
アクセスキーを保存してから、決済へ進んでくださいSave your access key, then continue to payment
レポートを開くにはこのキーが必要です。表示はこの一度きりで、当社も復元できません。このブラウザにも保存されますが、別の端末で開く場合に備えて必ず控えてください。
You need this key to open the report. It is shown only once and we cannot recover it. This browser remembers it too, but keep a copy for other devices.
- 受付番号Incident ID
- アクセスキーAccess key
- SHA-256
- 受領ファイルReceived
決済は Stripe が処理します。カード番号は当社サーバーを通りません。決済が完了すると解析が自動で始まり、進捗ページに戻ります。
Payment is processed by Stripe; card details never touch our servers. When it completes, the analysis starts and you return to the progress page.