Skip to content
Incident Response

SecTepe Collector & DFIR Portal: Forensic Acquisition Without a Login Barrier

SecTepe Editorial
|
|
7 min read

In an emergency, speed counts – but so does evidential weight. Whoever has to laboriously sort out access during an incident loses valuable time; whoever collects sloppily loses the chain of custody. The new DFIR offering in SecTepe.Core.CTI solves both: a SecTepe Collector for initial acquisition and a two-part DFIR portal that allows upload without a login and secures analysis behind SSO.

SecTepe Collector: One Binary, One Curated Artifact Set

The SecTepe Collector is a SecTepe-branded Velociraptor offline collector, pinned to a curated, Cyber-Triage-inspired artifact set: processes, network connections, autoruns/persistence, services, scheduled tasks, users, DNS, execution evidence, event logs, and filesystem changes. An operator runs a single binary on the live endpoint that packs everything into one container. Available for Windows, Linux, and macOS.

Full Disk Image – Deliberately Never Uploaded

Where a complete backup is needed, the collector can create a bit-for-bit full disk image – to an external drive or an SMB/Samba share, with a GUI disk picker and multi-disk imaging. Importantly, this image is deliberately never uploaded. It stays with the customer; only the compact artifact collection is uploaded. That keeps data protection and bandwidth under control.

Two-Host Portal: Login-Free Upload, SSO Analysis

The DFIR portal is deliberately split across two hosts:

  • dfir-upload – a login-free public uploader with per-case upload tokens. The operator on site needs no account.
  • dfir – the SSO-secured analyst console (Keycloak via oauth2-proxy). The portal container is reachable only over loopback, thus solely through the authenticating edge.

Large collections are transferred via chunked upload (8 MiB blocks) with a progress bar. The analyst identity is carried from X-Forwarded-Email as X-Actor into a tamper-evident chain of custody, complemented by X509-sealed evidence.

From Artifacts to Insights

In the console this becomes a complete case picture: automatic scoring, process tree, review workflow, a Cyber-Triage-like case overview with a host browser, cross-host IOC correlation, MISP enrichment, and a PDF case report – all the way to Sophos log analysis. This turns a collection of raw data into a robust incident story.

Part of the CTI Ecosystem

The collector complements the agentless sandbox: suspicious files from the endpoint move into detonation, the IOCs converge via MISP, and the analyst triage prioritizes the result. This closes the loop from initial acquisition to assessed insight.

Conclusion

With a simple collector binary, a login-free upload, and SSO-secured analysis, SecTepe.Core.CTI makes professional initial acquisition fast and evidence-safe at the same time – including chain of custody and a PDF case report. That is DFIR without the usual organizational friction.