Live forensics και απομακρυσμένη ανταπόκριση σε περιστατικά : θεωρητική και πειραματική αξιολόγηση του Velociraptor
Live forensics and remote incident response : a theoretical and experimental evaluation of Velociraptor

View/ Open
Keywords
Velociraptor ; DFIR ; Digital forensics ; Incident responseAbstract
This master’s thesis aims at the experimental evaluation of Velociraptor, an open-source platform
for Digital Forensics and Incident Response (DFIR), with an emphasis on its capabilities for live
forensic analysis and remote incident response in modern environments. The research was
motivated by identifying gaps in the literature regarding the systematic academic documentation
of such tools, particularly with respect to their performance in scenarios involving the exploitation
of real vulnerabilities, the preservation of forensic integrity during remote collection and their
comparison with traditional dead-box forensic techniques. To this end, the thesis combines a
systematic review of the literature in the fields of digital forensics, incident response, volatile
memory forensics and remote data acquisition with a controlled experimental study conducted
within the virtual environment of a home lab. Within this framework, a custom VQL artifact was
developed for the detection of the forensic artifacts of the CVE-2026-21510 vulnerability, a real Windows Shell vulnerability that exploits malicious LNK files with embedded UNC paths,
through the methodological approach of controlled artifact simulation. The findings demonstrated
that Velociraptor successfully detected the forensic artifacts across all four evaluation categories,
with response times on the order of seconds, zero false positives in a clean environment, and
automatic documentation that ensures forensic integrity. In conclusion, the thesis highlights that
Velociraptor excels in scenarios where time is critical, the scale is large, or the recovery of volatile
data is required, operating alongside traditional approaches, while it provides practical guidance
for modern SOC and IR teams and proposes extensions toward enterprise, cloud, and SIEM/SOAR
solutions.


