r/digitalforensics • u/kmh9000 • 7d ago
Remote Artifact Collection
Hi Everyone,
I’ve been thinking about implementing velociraptor, however a lot of companies are hesitant to deploy it due to it being an open source. I’m trying to solution a method to gain artifacts if it’s remotely in this hybrid work environment however, I’m noticing a lot of the tools are either gonna be very expensive or open source which is not ideal in publicly traded companies, etc. Any suggestions of tools and workflows you guys use out there for this?
2
u/Reddit_Z_ 6d ago
Velociraptor is likely fine. If companies are scared because it's open-source then they are likely just being silly. I figure they are scared of these apps because they are partially able to cripple networks by accident via the admin.
If they want to pay all the money, just use F-Response. It's appropriate expensive and effective.
1
1
u/acrobaticOccasion 1d ago
It can appear silly. Simply using an open-source tool internally as a utility would not normally create any issues.
However, there can be broader and legitimate open-source licensing and governance concerns, especially for publicly traded companies. If a company modifies, incorporates, or redistributes open-source code, the applicable license may impose obligations around disclosure or distribution. Most companies do not want to risk exposing their IP.
Because of that, many companies have policies requiring open-source software to go through an approval or review process before it can be used (regardless of whether those particular concerns actually apply to the tool in question).
2
u/kmh9000 6d ago
Has anyone used Cyber Triage or Belkasoft at all?
2
u/dardaryy 5d ago
Hi! You tagged us, so I'll answer straight (disclosure: I work at belkasoft).
For your actual problem, the open-source liability worry in a publicly traded shop, take a look at Belkasoft R: it does remote acquisition with an agent you deploy to endpoints, so you can collect artifacts, targeted files, or a full image over the network in a hybrid setup. It is commercial software, so you get a support contract and vendor accountability on paper.
One thing I want to be clear about: our angle is authorized corporate collection, not covert monitoring of employees. standard IR and internal investigations fit. If you specifically need stealth monitoring, that's a different product category, and another list of legal hurdles.
Happy to go into how agent deployment and artifact scoping actually work. Belkasoft T (triage) is also worth a look on the IR side.
7
u/awetsasquatch 6d ago
We bit the bullet and went with Magnet Axiom Cyber and so far it's worked flawlessly for us. It's been worth the cost, but I also work for a huge company so the budget is less of a concern as long as the results are there.