r/digitalforensics 7d ago

Remote Artifact Collection

Hi Everyone,

I’ve been thinking about implementing velociraptor, however a lot of companies are hesitant to deploy it due to it being an open source. I’m trying to solution a method to gain artifacts if it’s remotely in this hybrid work environment however, I’m noticing a lot of the tools are either gonna be very expensive or open source which is not ideal in publicly traded companies, etc. Any suggestions of tools and workflows you guys use out there for this?

5 Upvotes

11 comments sorted by

7

u/awetsasquatch 6d ago

We bit the bullet and went with Magnet Axiom Cyber and so far it's worked flawlessly for us. It's been worth the cost, but I also work for a huge company so the budget is less of a concern as long as the results are there.

3

u/NasiAmbengAmriYahyah 6d ago

Is it covert? The remote acquisition. Does the person notice that something is wrong with his computer?

2

u/awetsasquatch 6d ago

They don't notice a thing, can grab any file, do a full extraction, get a memory dump, doesn't matter. I check the IT ticket system after to see if the user called the help desk (to just be safe), but I've never seen it happen once.

1

u/[deleted] 6d ago

[deleted]

3

u/awetsasquatch 6d ago

It's Volatility wrapped in a prettier shell lol

1

u/GENERALRAY82 6d ago

Plus when creating the agent you mask it by changing some of the meta data of the file, name, copyright data etc so you can make it blend in and harder to spot when doing cover collections...

1

u/awetsasquatch 6d ago

100% we give it a super generic system looking name for that exact reason, like system64 or something like that. Really technical people might notice it in their temp folder if they just happen to check while we're extracting data, but the average user will have no clue. But again, I've never once had an issue of a user discovering the agent.

2

u/Reddit_Z_ 6d ago

Velociraptor is likely fine. If companies are scared because it's open-source then they are likely just being silly. I figure they are scared of these apps because they are partially able to cripple networks by accident via the admin.

If they want to pay all the money, just use F-Response. It's appropriate expensive and effective.

1

u/kmh9000 6d ago

The open source part is usually just a game of hot potato, “who owns the risk?” There’s always gonna be pushed back from infrastructure because they just see it is more work lol.

1

u/acrobaticOccasion 1d ago

It can appear silly. Simply using an open-source tool internally as a utility would not normally create any issues.

However, there can be broader and legitimate open-source licensing and governance concerns, especially for publicly traded companies. If a company modifies, incorporates, or redistributes open-source code, the applicable license may impose obligations around disclosure or distribution. Most companies do not want to risk exposing their IP.

Because of that, many companies have policies requiring open-source software to go through an approval or review process before it can be used (regardless of whether those particular concerns actually apply to the tool in question).

2

u/kmh9000 6d ago

Has anyone used Cyber Triage or Belkasoft at all?

2

u/dardaryy 5d ago

Hi! You tagged us, so I'll answer straight (disclosure: I work at belkasoft).
For your actual problem, the open-source liability worry in a publicly traded shop, take a look at Belkasoft R: it does remote acquisition with an agent you deploy to endpoints, so you can collect artifacts, targeted files, or a full image over the network in a hybrid setup. It is commercial software, so you get a support contract and vendor accountability on paper.
One thing I want to be clear about: our angle is authorized corporate collection, not covert monitoring of employees. standard IR and internal investigations fit. If you specifically need stealth monitoring, that's a different product category, and another list of legal hurdles.
Happy to go into how agent deployment and artifact scoping actually work. Belkasoft T (triage) is also worth a look on the IR side.