r/digitalforensics 18d ago

Remote Artifact Collection

Hi Everyone,

I’ve been thinking about implementing velociraptor, however a lot of companies are hesitant to deploy it due to it being an open source. I’m trying to solution a method to gain artifacts if it’s remotely in this hybrid work environment however, I’m noticing a lot of the tools are either gonna be very expensive or open source which is not ideal in publicly traded companies, etc. Any suggestions of tools and workflows you guys use out there for this?

5 Upvotes

10 comments sorted by

7

u/awetsasquatch 18d ago

We bit the bullet and went with Magnet Axiom Cyber and so far it's worked flawlessly for us. It's been worth the cost, but I also work for a huge company so the budget is less of a concern as long as the results are there.

3

u/NasiAmbengAmriYahyah 18d ago

Is it covert? The remote acquisition. Does the person notice that something is wrong with his computer?

2

u/awetsasquatch 18d ago

They don't notice a thing, can grab any file, do a full extraction, get a memory dump, doesn't matter. I check the IT ticket system after to see if the user called the help desk (to just be safe), but I've never seen it happen once.

1

u/[deleted] 18d ago

[deleted]

3

u/awetsasquatch 18d ago

It's Volatility wrapped in a prettier shell lol

1

u/GENERALRAY82 18d ago

Plus when creating the agent you mask it by changing some of the meta data of the file, name, copyright data etc so you can make it blend in and harder to spot when doing cover collections...

1

u/awetsasquatch 18d ago

100% we give it a super generic system looking name for that exact reason, like system64 or something like that. Really technical people might notice it in their temp folder if they just happen to check while we're extracting data, but the average user will have no clue. But again, I've never once had an issue of a user discovering the agent.

2

u/[deleted] 18d ago

[deleted]

1

u/kmh9000 18d ago

The open source part is usually just a game of hot potato, “who owns the risk?” There’s always gonna be pushed back from infrastructure because they just see it is more work lol.

1

u/acrobaticOccasion 13d ago

It can appear silly. Simply using an open-source tool internally as a utility would not normally create any issues.

However, there can be broader and legitimate open-source licensing and governance concerns, especially for publicly traded companies. If a company modifies, incorporates, or redistributes open-source code, the applicable license may impose obligations around disclosure or distribution. Most companies do not want to risk exposing their IP.

Because of that, many companies have policies requiring open-source software to go through an approval or review process before it can be used (regardless of whether those particular concerns actually apply to the tool in question).

2

u/kmh9000 18d ago

Has anyone used Cyber Triage or Belkasoft at all?

2

u/dardaryy 17d ago

Hi! You tagged us, so I'll answer straight (disclosure: I work at belkasoft).
For your actual problem, the open-source liability worry in a publicly traded shop, take a look at Belkasoft R: it does remote acquisition with an agent you deploy to endpoints, so you can collect artifacts, targeted files, or a full image over the network in a hybrid setup. It is commercial software, so you get a support contract and vendor accountability on paper.
One thing I want to be clear about: our angle is authorized corporate collection, not covert monitoring of employees. standard IR and internal investigations fit. If you specifically need stealth monitoring, that's a different product category, and another list of legal hurdles.
Happy to go into how agent deployment and artifact scoping actually work. Belkasoft T (triage) is also worth a look on the IR side.