| dc.contributor.advisor | Λαμπρινουδάκης, Κωνσταντίνος | |
| dc.contributor.author | Γκιζώρης, Σπυρίδων | |
| dc.date.accessioned | 2026-07-15T07:14:29Z | |
| dc.date.available | 2026-07-15T07:14:29Z | |
| dc.date.issued | 2026-06 | |
| dc.identifier.uri | https://dione.lib.unipi.gr/xmlui/handle/unipi/19557 | |
| dc.description.abstract | Η παρούσα διπλωματική εργασία αποσκοπεί στην θεωρητική και πειραματική αξιολόγηση του
Velociraptor, μίας πλατφόρμας ανοιχτού κώδικα για τη Ψηφιακή Εγκληματολογία και
Ανταπόκριση σε Περιστατικά (DFIR), με έμφαση στις δυνατότητές της για live forensic ανάλυση
και απομακρυσμένη ανταπόκριση σε σύγχρονα περιβάλλοντα. Αφορμή για την έρευνα αποτέλεσε
ο εντοπισμός ερευνητικών κενών στη βιβλιογραφία ως προς τη συστηματική ακαδημαϊκή
τεκμηρίωση τέτοιων εργαλείων, ιδίως όσον αφορά την απόδοσή τους σε σενάρια εκμετάλλευσης
πραγματικών ευπαθειών, τη διατήρηση της εγκληματολογικής ακεραιότητας κατά την
απομακρυσμένη συλλογή και τη σύγκρισή τους με παραδοσιακές dead-box forensic τεχνικές. Για
τον σκοπό αυτό, η εργασία συνδυάζει συστηματική ανασκόπηση της βιβλιογραφίας στους τομείς
της ψηφιακής εγκληματολογίας, του incident response, του volatile memory forensics και της
απομακρυσμένης συλλογής δεδομένων, με μια ελεγχόμενη πειραματική μελέτη μέσα στο εικονικό
περιβάλλον ενός home lab. Στο πλαίσιο αυτό αναπτύχθηκε ένα προσαρμοσμένο VQL artifact για
την ανίχνευση των forensic artifacts της ευπάθειας CVE-2026-21510, μιας πραγματικής ευπάθειας
του Windows Shell που αξιοποιεί κακόβουλα LNK αρχεία με ενσωματωμένα UNC paths, μέσω
της μεθοδολογικής προσέγγισης της ελεγχόμενης προσομοίωσης (controlled artifact simulation).
Τα ευρήματα κατέδειξαν ότι το Velociraptor εντόπισε επιτυχώς τα forensic artifacts και στις
τέσσερις κατηγορίες αξιολόγησης, με χρόνους απόκρισης της τάξης των δευτερολέπτων, μηδενικά
false positives σε καθαρό περιβάλλον και αυτόματη τεκμηρίωση που διασφαλίζει την
εγκληματολογική ακεραιότητα. Συμπερασματικά, η εργασία αναδεικνύει ότι το Velociraptor
υπερτερεί σε σενάρια όπου ο χρόνος είναι κρίσιμος, η κλίμακα μεγάλη ή όπου απαιτείται η
ανάκτηση πτητικών δεδομένων, λειτουργώντας μαζί με τις παραδοσιακές προσεγγίσεις, ενώ
παρέχει πρακτικές κατευθύνσεις για σύγχρονες ομάδες SOC και IR και προτείνει επεκτάσεις προς
enterprise, cloud και SIEM/SOAR λύσεις. | el |
| dc.format.extent | 140 | el |
| dc.language.iso | el | el |
| dc.publisher | Πανεπιστήμιο Πειραιώς | el |
| dc.rights | Αναφορά Δημιουργού 3.0 Ελλάδα | * |
| dc.rights.uri | http://creativecommons.org/licenses/by/3.0/gr/ | * |
| dc.title | Live forensics και απομακρυσμένη ανταπόκριση σε περιστατικά : θεωρητική και πειραματική αξιολόγηση του Velociraptor | el |
| dc.title.alternative | Live forensics and remote incident response : a theoretical and experimental evaluation of Velociraptor | el |
| dc.type | Master Thesis | el |
| dc.contributor.department | Σχολή Τεχνολογιών Πληροφορικής και Επικοινωνιών. Τμήμα Ψηφιακών Συστημάτων | el |
| dc.description.abstractEN | This master’s thesis aims at the experimental evaluation of Velociraptor, an open-source platform
for Digital Forensics and Incident Response (DFIR), with an emphasis on its capabilities for live
forensic analysis and remote incident response in modern environments. The research was
motivated by identifying gaps in the literature regarding the systematic academic documentation
of such tools, particularly with respect to their performance in scenarios involving the exploitation
of real vulnerabilities, the preservation of forensic integrity during remote collection and their
comparison with traditional dead-box forensic techniques. To this end, the thesis combines a
systematic review of the literature in the fields of digital forensics, incident response, volatile
memory forensics and remote data acquisition with a controlled experimental study conducted
within the virtual environment of a home lab. Within this framework, a custom VQL artifact was
developed for the detection of the forensic artifacts of the CVE-2026-21510 vulnerability, a real Windows Shell vulnerability that exploits malicious LNK files with embedded UNC paths,
through the methodological approach of controlled artifact simulation. The findings demonstrated
that Velociraptor successfully detected the forensic artifacts across all four evaluation categories,
with response times on the order of seconds, zero false positives in a clean environment, and
automatic documentation that ensures forensic integrity. In conclusion, the thesis highlights that
Velociraptor excels in scenarios where time is critical, the scale is large, or the recovery of volatile
data is required, operating alongside traditional approaches, while it provides practical guidance
for modern SOC and IR teams and proposes extensions toward enterprise, cloud, and SIEM/SOAR
solutions. | el |
| dc.contributor.master | Κυβερνοασφάλεια και Τεχνολογίες Τεχνητής Νοημοσύνης / MSc Cybersecurity & AI Technologies | el |
| dc.subject.keyword | Velociraptor | el |
| dc.subject.keyword | DFIR | el |
| dc.subject.keyword | Digital forensics | el |
| dc.subject.keyword | Incident response | el |
| dc.date.defense | 2026-07-08 | |