Show simple item record

Live forensics και απομακρυσμένη ανταπόκριση σε περιστατικά : θεωρητική και πειραματική αξιολόγηση του Velociraptor

dc.contributor.advisorΛαμπρινουδάκης, Κωνσταντίνος
dc.contributor.authorΓκιζώρης, Σπυρίδων
dc.date.accessioned2026-07-15T07:14:29Z
dc.date.available2026-07-15T07:14:29Z
dc.date.issued2026-06
dc.identifier.urihttps://dione.lib.unipi.gr/xmlui/handle/unipi/19557
dc.description.abstractΗ παρούσα διπλωματική εργασία αποσκοπεί στην θεωρητική και πειραματική αξιολόγηση του Velociraptor, μίας πλατφόρμας ανοιχτού κώδικα για τη Ψηφιακή Εγκληματολογία και Ανταπόκριση σε Περιστατικά (DFIR), με έμφαση στις δυνατότητές της για live forensic ανάλυση και απομακρυσμένη ανταπόκριση σε σύγχρονα περιβάλλοντα. Αφορμή για την έρευνα αποτέλεσε ο εντοπισμός ερευνητικών κενών στη βιβλιογραφία ως προς τη συστηματική ακαδημαϊκή τεκμηρίωση τέτοιων εργαλείων, ιδίως όσον αφορά την απόδοσή τους σε σενάρια εκμετάλλευσης πραγματικών ευπαθειών, τη διατήρηση της εγκληματολογικής ακεραιότητας κατά την απομακρυσμένη συλλογή και τη σύγκρισή τους με παραδοσιακές dead-box forensic τεχνικές. Για τον σκοπό αυτό, η εργασία συνδυάζει συστηματική ανασκόπηση της βιβλιογραφίας στους τομείς της ψηφιακής εγκληματολογίας, του incident response, του volatile memory forensics και της απομακρυσμένης συλλογής δεδομένων, με μια ελεγχόμενη πειραματική μελέτη μέσα στο εικονικό περιβάλλον ενός home lab. Στο πλαίσιο αυτό αναπτύχθηκε ένα προσαρμοσμένο VQL artifact για την ανίχνευση των forensic artifacts της ευπάθειας CVE-2026-21510, μιας πραγματικής ευπάθειας του Windows Shell που αξιοποιεί κακόβουλα LNK αρχεία με ενσωματωμένα UNC paths, μέσω της μεθοδολογικής προσέγγισης της ελεγχόμενης προσομοίωσης (controlled artifact simulation). Τα ευρήματα κατέδειξαν ότι το Velociraptor εντόπισε επιτυχώς τα forensic artifacts και στις τέσσερις κατηγορίες αξιολόγησης, με χρόνους απόκρισης της τάξης των δευτερολέπτων, μηδενικά false positives σε καθαρό περιβάλλον και αυτόματη τεκμηρίωση που διασφαλίζει την εγκληματολογική ακεραιότητα. Συμπερασματικά, η εργασία αναδεικνύει ότι το Velociraptor υπερτερεί σε σενάρια όπου ο χρόνος είναι κρίσιμος, η κλίμακα μεγάλη ή όπου απαιτείται η ανάκτηση πτητικών δεδομένων, λειτουργώντας μαζί με τις παραδοσιακές προσεγγίσεις, ενώ παρέχει πρακτικές κατευθύνσεις για σύγχρονες ομάδες SOC και IR και προτείνει επεκτάσεις προς enterprise, cloud και SIEM/SOAR λύσεις.el
dc.format.extent140el
dc.language.isoelel
dc.publisherΠανεπιστήμιο Πειραιώςel
dc.rightsΑναφορά Δημιουργού 3.0 Ελλάδα*
dc.rights.urihttp://creativecommons.org/licenses/by/3.0/gr/*
dc.titleLive forensics και απομακρυσμένη ανταπόκριση σε περιστατικά : θεωρητική και πειραματική αξιολόγηση του Velociraptorel
dc.title.alternativeLive forensics and remote incident response : a theoretical and experimental evaluation of Velociraptorel
dc.typeMaster Thesisel
dc.contributor.departmentΣχολή Τεχνολογιών Πληροφορικής και Επικοινωνιών. Τμήμα Ψηφιακών Συστημάτωνel
dc.description.abstractENThis master’s thesis aims at the experimental evaluation of Velociraptor, an open-source platform for Digital Forensics and Incident Response (DFIR), with an emphasis on its capabilities for live forensic analysis and remote incident response in modern environments. The research was motivated by identifying gaps in the literature regarding the systematic academic documentation of such tools, particularly with respect to their performance in scenarios involving the exploitation of real vulnerabilities, the preservation of forensic integrity during remote collection and their comparison with traditional dead-box forensic techniques. To this end, the thesis combines a systematic review of the literature in the fields of digital forensics, incident response, volatile memory forensics and remote data acquisition with a controlled experimental study conducted within the virtual environment of a home lab. Within this framework, a custom VQL artifact was developed for the detection of the forensic artifacts of the CVE-2026-21510 vulnerability, a real Windows Shell vulnerability that exploits malicious LNK files with embedded UNC paths, through the methodological approach of controlled artifact simulation. The findings demonstrated that Velociraptor successfully detected the forensic artifacts across all four evaluation categories, with response times on the order of seconds, zero false positives in a clean environment, and automatic documentation that ensures forensic integrity. In conclusion, the thesis highlights that Velociraptor excels in scenarios where time is critical, the scale is large, or the recovery of volatile data is required, operating alongside traditional approaches, while it provides practical guidance for modern SOC and IR teams and proposes extensions toward enterprise, cloud, and SIEM/SOAR solutions.el
dc.contributor.masterΚυβερνοασφάλεια και Τεχνολογίες Τεχνητής Νοημοσύνης / MSc Cybersecurity & AI Technologiesel
dc.subject.keywordVelociraptorel
dc.subject.keywordDFIRel
dc.subject.keywordDigital forensicsel
dc.subject.keywordIncident responseel
dc.date.defense2026-07-08


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record

Αναφορά Δημιουργού 3.0 Ελλάδα
Except where otherwise noted, this item's license is described as
Αναφορά Δημιουργού 3.0 Ελλάδα

Βιβλιοθήκη Πανεπιστημίου Πειραιώς
Contact Us
Send Feedback
Created by ELiDOC
Η δημιουργία κι ο εμπλουτισμός του Ιδρυματικού Αποθετηρίου "Διώνη", έγιναν στο πλαίσιο του Έργου «Υπηρεσία Ιδρυματικού Αποθετηρίου και Ψηφιακής Βιβλιοθήκης» της πράξης «Ψηφιακές υπηρεσίες ανοιχτής πρόσβασης της βιβλιοθήκης του Πανεπιστημίου Πειραιώς»