Harnessing the Power of Velociraptor: Taking Investigations to the Next Level

No ratings

Presented at SecTor 2024 by

This talk shares insights from a skilled investigator with over 14 years of experience in Incident Response, Threat Hunting, and Insider Threat Investigations.As investigators, we regularly come up against the same challenges, both from a collection and analysis perspective. These problems are common across the industry, and this talk will dive into Velociraptor, a tool that addresses them in a way that nothing else does. This tool is a must-have for any skilled investigator, from one professional to another.The speaker is an experienced investigator sharing personal insights and experience and is NOT involved in the development of Velociraptor.If any of these problems sound familiar, you will be very interested in this talk!Have you ever had to wait for a system to come online so you could collect more investigative data with your EDR?Have you ever wanted to collect a certain artifact, but were told that your existing tools don't support that, so you had to write a PowerShell script by hand?Were you ever provided with detailed telemetry, but discovered there were gaps because file writes were only recorded for certain extensions?Have you ever needed to collect multiple files from a system, but your tools only collect one file at a time, so you're forced to manually zip and transfer the archive?Have you ever been trying to collect investigation data and the system went offline and you lost all your progress?We will talk about how all these problems, and more, can be solved using Velociraptor!This talk is best suited for folks who have an interest in any of Threat Hunting, Digital Forensics, Incident Response or Insider Threat Investigations. Both technical practitioners and management teams will find value and insights here.By the end of this talk, attendees will have learned how their organization can use Velociraptor right away, to solve at least one of their pain points.