<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CrabCanneryShip</title>
    <description>The latest articles on DEV Community by CrabCanneryShip (@crabcanneryship).</description>
    <link>https://dev.to/crabcanneryship</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4151297%2F99716f6a-a7c0-4361-b093-f7908887da2a.jpeg</url>
      <title>DEV Community: CrabCanneryShip</title>
      <link>https://dev.to/crabcanneryship</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/crabcanneryship"/>
    <language>en</language>
    <item>
      <title>Why I Built My Cloud-Native DFIR Pipeline (And Ditched AWS/OpenSearch for BigQuery)</title>
      <dc:creator>CrabCanneryShip</dc:creator>
      <pubDate>Wed, 30 Sep 2026 05:49:05 +0000</pubDate>
      <link>https://dev.to/crabcanneryship/why-i-built-my-cloud-native-dfir-pipeline-and-ditched-awsopensearch-for-bigquery-ajg</link>
      <guid>https://dev.to/crabcanneryship/why-i-built-my-cloud-native-dfir-pipeline-and-ditched-awsopensearch-for-bigquery-ajg</guid>
      <description>&lt;p&gt;There are fantastic, battle-tested tools out there like KAPE and CDIR. But as a DFIR engineer, I wanted something more lightweight, highly customizable, and automated from the ground up to fit my own workflow. So, I built a fast forensics pipeline: &lt;strong&gt;Veloxamen&lt;/strong&gt;.&lt;/p&gt;

&lt;h4&gt;
  
  
  The Pain Points: Why Not AWS?
&lt;/h4&gt;

&lt;p&gt;I initially looked into building this on AWS. While Timesketch is hard to let go of, getting OpenSearch ingestion to feel &lt;em&gt;just right&lt;/em&gt; on AWS always felt heavier and clunky than it should be. &lt;/p&gt;

&lt;p&gt;Then, I shifted my focus to GCP. The scalability and sheer convenience of &lt;strong&gt;BigQuery&lt;/strong&gt; for structured log analysis completely won me over. &lt;/p&gt;

&lt;h4&gt;
  
  
  What Veloxamen Does
&lt;/h4&gt;

&lt;p&gt;Veloxamen is designed to automatically ingest and process forensic artifacts in GCP, transforming them into a structured, queryable timeline inside BigQuery. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Collector + Pipeline:&lt;/strong&gt; Combined with a custom collector, it handles the heavy lifting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Windows First (For Now):&lt;/strong&gt; Right now, it focuses heavily on Windows artifacts (since attackers love targeting them), but the architecture is fully extensible. Drop your logs into the staging bucket with a clean prefix, and anything supported gets automatically transformed into a unified timeline.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  Evolutional Improvements: What's Next?
&lt;/h4&gt;

&lt;p&gt;BigQuery is just the baseline. Because all the parsed forensic timelines live cleanly in BigQuery, the path forward opens up to some serious evolution:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Microservices Transformation&lt;/strong&gt;: While Log2Timeline/Plaso is undeniably powerful and sophisticated, managing and scaling its compute resources can be exhausting. It will be replaced with a highly concurrent microservices architecture for lightning-fast artifact processing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Looker / Looker Studio Integration:&lt;/strong&gt; Instant visual dashboards and interactive hunting views without wrestling with heavy legacy SIEM UIs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vertex AI-Powered Analysis:&lt;/strong&gt; Leveraging LLMs and ML models directly over BigQuery data to automate anomaly detection, summarize event horizons, and speed up triage reporting.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can check out the source code and architecture here:&lt;br&gt;
🔗 &lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/veloxamen" rel="noopener noreferrer"&gt;https://github.com/veloxamen&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'm currently opening it up to the global community. Feedback, issues, or thoughts from fellow DFIR/cloud security folks are more than welcome!&lt;/p&gt;

</description>
      <category>dfir</category>
      <category>security</category>
      <category>go</category>
      <category>googlecloud</category>
    </item>
  </channel>
</rss>
