IMF 2026

15th International Conference on
IT Security Incident Management & IT Forensics

September 15th - 16th, 2026
Bonn, Germany

http://www.imf-conference.org/
mailto:2026@imf-conference.org

Conference of SIG SIDAR
of the German Informatics Society (GI).

Conference Program

IMF 2026 · 15–16 September 2026 · Fraunhofer FKIE, Bonn, Germany

Preliminary programme — session order and times are subject to change.

Schedule

Day 1 — Tuesday, September 15, 2026

Time Programme Speaker
08:00–08:30 Registration & Welcome Coffee
08:30–10:00 Workshop: Agentic AI for DFIR (Part 1) Michael Külper (Fraunhofer FKIE)
10:00–10:15 Coffee Break
10:15–12:00 Workshop: Agentic AI for DFIR (Part 2) Michael Külper (Fraunhofer FKIE)
12:00–13:30 Lunch
13:30–13:40 Opening Remarks
13:40–14:30 Opening Keynote (title to be announced) Tillmann Werner
14:30–15:30 Paper Session: Agentic / Autonomous AI
15:30–16:00 Coffee Break
16:00–17:00 Paper Session: Mobile Forensics
from 17:00 Social Event & Conference Dinner

Day 2 — Wednesday, September 16, 2026

Time Programme Speaker
09:00–09:30 Practitioner's Talk: One-Shot Evidence Acquisition on Windows-Based Imaging Modalities: Assessing Triage Collector Risk Joao Collier de Mendonca, Amelie Regl
09:30–10:30 Paper Session: Network & OT Infrastructure / Event Reconstruction
10:30–11:00 Coffee Break
11:00–12:30 Paper Session: Memory Forensics — Acquisition & Analysis
12:30–13:30 Lunch
13:30–14:30 Paper Session — Meta-Perspective: Field, Law & Future
14:30–15:30 Closing Keynote: What happens after a report reaches the BSI? Stefan Donath & Chris Ewert (BSI)

Accepted Papers (preliminary)

  1. Bounty Hunter: Autonomous, Comprehensive Emulation of Multi-Faceted Adversaries
    Louis Hackländer-Jansen, Rafael Uetz, Martin Henze
  2. Foundations for Agentic AI Investigations from the Forensic Analysis of OpenClaw
    Jan Gruber, Jan-Niclas Hilgert
  3. Inside Job: The Methods, Challenges, and Opportunities for On-Device Data Acquisition on Android
    Felix Hollederer, Julian Geus, Felix Freiling
  4. Cell Selection Behaviour in Buildings with Indoor Cells: An Exploratory Study
    Lukas Baumeler, Hannes Spichiger, Florian Wamser
  5. Forensic Analysis of Encrypted SMB Traffic: Decryption, Client Identification and Event Reconstruction
    Carl Gadde, Jan-Niclas Hilgert
  6. FROHA – Forensic Recorder for Operator HMI Activities
    Alexios Karagiozidis, Martin Gergeleit
  7. Frankenstein's RAM: A Simulation Framework for Evaluating Memory Forensic Acquisition Strategies
    Lisa Rzepka, Jan Gruber, Felix Freiling, Harald Baier
  8. Digital Anti-Forensics Research: The Next 10 Years
    Janine Schneider, Florian Ramming, Maximilian Eichhorn, Gaston Pugliese, Christopher Hargreaves, Jan Gruber, Joschua Schilling, Julian Geus, Kevin Mayer, Lea Uhlenbrock, Lena Voigt, Frank Breitinger

Keynotes

Opening Keynote — Tillmann Werner

Title and abstract to be announced.

Closing Keynote — What happens after a report reaches the BSI?

Speakers: Stefan Donath & Chris Ewert, German Federal Office for Information Security (BSI)

Every report is more than just a notification — it is the starting point of a structured incident handling process. In this presentation, we will take a look behind the scenes at how reports are received, assessed, and analyzed by the BSI. We will also explore how incidents are prioritized, how additional information is gathered, and how the findings contribute to a better understanding of the current cyber threat landscape. Finally, we will discuss the actions the BSI may take in response, including incident coordination, technical guidance, and support provided by the BSI's CERT to help affected organizations contain, mitigate, and recover from cyber incidents. The presentation offers an overview of how effective reporting enables timely response and strengthens the overall resilience of Germany's cybersecurity ecosystem.

Short bio: Stefan Donath and Chris Ewert have both been with the BSI for several years, working among other things on the incident-reporting scheme for critical infrastructure.

Workshop

Agentic AI for DFIR

Presenter: Michael Külper, Fraunhofer FKIE

DFIR investigations rarely follow a straight line. Investigators move from one clue to the next, choose tools based on emerging evidence, and continuously refine their understanding of what happened. Agentic AI is well suited to support this type of work: it can reason over findings, call tools, adapt its plan, and help decide what to investigate next. In this hands-on workshop, participants will use agentic AI to work through a realistic DFIR case involving both forensic evidence and a live system.

The workshop combines practical investigation with the theoretical foundations needed to understand modern agentic workflows. Participants will learn how AI agents plan and execute tasks, connect to external tools and data sources through protocols such as MCP, delegate work to subagents, and manage context and memory across an investigation. We will also share practical guidance on how to instruct agents, define reusable skills, and structure workflows to achieve better investigative results.

Because DFIR work requires evidence integrity, the workshop also covers practical approaches to control, safety, and traceability. Using Claude Code as an example, participants will learn how to combine human-in-the-loop approvals, permission rules, hooks, and controlled tool access to reduce the risk of unintended changes to evidence. We will also examine how to review agent transcripts and tool activity so investigators can understand, validate, and explain what the agentic system did during the workflow.

By the end of the workshop, participants will have completed a realistic agentic DFIR workflow and gained practical experience using agents to investigate evidence, control tool execution, and produce traceable results.

In Cooperation with