Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • harvard-cite-them-right
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Velociraptor i praktiken: En fallstudie om digital forensik och incidentrespons kopplad till NIST CSF
University of Borås, Faculty of Textiles, Engineering and Business.
University of Borås, Faculty of Textiles, Engineering and Business.
2025 (Swedish)Independent thesis Basic level (university diploma), 10 credits / 15 HE creditsStudent thesisAlternative title
A Case Study on Digital Forensics and Incident Response Aligned with the NIST Cybersecurity Framework (English)
Abstract [sv]

I denna studie undersöks hur det forensiska verktyget Velociraptor kan användas för att identifiera och hantera säkerhetsincidenter i linje med NIST Cybersecurity Framework. Genom en simulerad Trigona ransomware attack i en kontrollerad labbmiljö testades Velociraptors funktioner för detektion, isolering och artefaktinsamling. Med hjälp av skräddarsydda VQL skript skapades hunts som detekterade indikatorer på kompromettering (IoCs), inklusive RDP sessioner, batchfiler och verktyg för dataexfiltration. När dessa upptäcktes användes Velociraptor för att isolera drabbade klienter och exportera forensiska data för vidare analys. Resultaten visar att Velociraptor effektivt stödjer funktionerna detect, respond, protect och identify samt i viss utsträckning recover. Studien bidrar med empirisk insikt i hur DFIR verktyg kan operationalisera säkerhetsramverk och förbättra incidentrespons, särskilt i miljöer med begränsade resurser.

Abstract [en]

This study examines how the forensic tool Velociraptor can be applied to detect and manage security incidents in alignment with the NIST Cybersecurity Framework. A simulated Trigona ransomware attack was conducted in a controlled lab environment to evaluate Velociraptor's capabilities for detection, isolation, and artifact collection. Custom VQL scripts were developed to create hunts that identified indicators of compromise (IoCs), such as RDP sessions, batch files, and data exfiltration tools. Once detected, Velociraptor was used to isolate affected clients and export forensic data for further analysis. The results demonstrate that Velociraptor effectively supports detect, respond, protect, identify functions, and to some extent recover. The study offers empirical insight into how DFIR tools can operationalize cybersecurity frameworks and enhance incident response, particularly in resource constrained environments.

Place, publisher, year, edition, pages
2025.
Keywords [en]
Digital Forensics, Incident Response, Velociraptor, NIST Cybersecurity Framework, DFIR, Ransomware, Trigona, IoCs, VQL, Threat Hunting, Quarantine, Artifact Collection
Keywords [sv]
Digital forensik, Incidentrespons, Velociraptor, NIST Cybersecurity Framework, DFIR, Ransomware, Trigona, IoCs, VQL, Hotjakt, Karantän, Artefaktinsamling
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hb:diva-34018OAI: oai:DiVA.org:hb-34018DiVA, id: diva2:1981924
Supervisors
Examiners
Available from: 2025-07-09 Created: 2025-07-07 Last updated: 2025-09-24Bibliographically approved

Open Access in DiVA

fulltext(1237 kB)94 downloads
File information
File name FULLTEXT01.pdfFile size 1237 kBChecksum SHA-512
f7a95d9c1089571905c4e2fe8cdc145984f2c23e6bb08a4b3e50db1778c1fb8abdbc68a6e7d57db82a9ce052f888abe798d42d8e7272d196dd308e42407f1176
Type fulltextMimetype application/pdf

By organisation
Faculty of Textiles, Engineering and Business
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 95 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 209 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • harvard-cite-them-right
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf