Enterprise Incident Response with Velociraptor: when tempo is all

A few days before the end of the Matera DigiSec 2024, the first event created by ONIF in Matera on the topics related to "Digital Forensics and Cybersecurity for the protection of data and rights", particularly in the corporate sector, we can certainly say that it was a great success, in terms of participation but also in terms of the quality of the topics covered (I'm leaving an excellent article here, with comments and some photos of the day).

I'm truly grateful to ONIF for the invitation to actively participate in this event, and for the occasion I decided to illustrate a tool that is still little-known (unfortunately!) but which is instead part of the toolbox of many Incident Response teams and which perhaps deserves greater prominence.

I'm talking about the open source tool Velociraptor, on which I based my short speech, entitled “Enterprise Incident Response with Velociraptor: when tempo is all”.
Before being attacked (rightly) by language purists, I would like to point out that the term tempo, as I explained better during the speech, was intentionally left in Italian, since I used the universally recognized musical meaning of the term, precisely because I imagined the Incident Response manager as an orchestra conductor who, by expertly (and harmoniously, indeed) using the "tools" at his disposal, can "lead" to a resolution of the IT Incident.

Beyond the metaphors, I wanted to underline how an open source tool of this type, if used wisely and meticulously, can drastically reduce the intervention and resolution times (usually defined in time to identify and contain) leading to significant savings in time and, above all, money.

The topic certainly deserves a series of articles, which we will publish shortly, but since I have had many requests to share the slides, I have inserted them below, so that everyone can consult them, in full open source spirit 😊


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *