Velociraptor Detection-Forensics Methodology

Arxiv pdf 2026-06-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Detection engineering and digital forensics have evolved in parallel rather than in partnership, leaving Digital Forensics a gap between real-time alerting and forensic analysis. This paper develops a unified detectionDetection Engineering forensics methodology using Velociraptor, where detection logic directly initiates targeted evidence Velociraptor acquisition at the point of detection. The contribution is threefold: (1) a four-stage methodology (baseline establishment, evidence Endpoint Triage correlation, attack chain analysis, and scenario labelling with confidence) that converts artefact knowledge into reusable and testable detection rules suitable for both post-incident triage and live monitoring; (2) a practical demonstration, using three Velociraptor BaseVQL log sources (forensics/windows/prefetch, forensics/windows/usn, and /windows/wmi) that practitioners can deploy today, showing that artefact-based detections enable scalable forensic triage without full disk acquisition; and (3) evidence that periodic artefact analysis offers continuous monitoring while substantially reducing data volume compared to conventional endpoint logging. Two case studies illustrate the approach: a Prefetch/USN baseline for triage when Windows Event Logs are cleared or unavailable, and a WMI persistence correlation supporting both triage and continuous monitoring through periodic artefact analysis.

Loading executive summary...

LINK COPIED TO CLIPBOARD