Opening Keynote — Tillmann Werner
Title and abstract to be announced.
September 15th - 16th, 2026
Bonn, Germany
http://www.imf-conference.org/
mailto:2026@imf-conference.org
Conference of SIG SIDAR
of the German Informatics Society (GI).
IMF 2026 · 15–16 September 2026 · Fraunhofer FKIE, Bonn, Germany
Preliminary programme — session order and times are subject to change.
| Time | Programme | Speaker |
|---|---|---|
| 08:00–08:30 | Registration & Welcome Coffee | |
| 08:30–10:00 | Workshop: Agentic AI for DFIR (Part 1) | Michael Külper (Fraunhofer FKIE) |
| 10:00–10:15 | Coffee Break | |
| 10:15–12:00 | Workshop: Agentic AI for DFIR (Part 2) | Michael Külper (Fraunhofer FKIE) |
| 12:00–13:30 | Lunch | |
| 13:30–13:40 | Opening Remarks | |
| 13:40–14:30 | Opening Keynote (title to be announced) | Tillmann Werner |
| 14:30–15:30 | Paper Session: Agentic / Autonomous AI | |
| 15:30–16:00 | Coffee Break | |
| 16:00–17:00 | Paper Session: Mobile Forensics | |
| from 17:00 | Social Event & Conference Dinner | |
| Time | Programme | Speaker |
|---|---|---|
| 09:00–09:30 | Practitioner's Talk: One-Shot Evidence Acquisition on Windows-Based Imaging Modalities: Assessing Triage Collector Risk | Joao Collier de Mendonca, Amelie Regl |
| 09:30–10:30 | Paper Session: Network & OT Infrastructure / Event Reconstruction | |
| 10:30–11:00 | Coffee Break | |
| 11:00–12:30 | Paper Session: Memory Forensics — Acquisition & Analysis | |
| 12:30–13:30 | Lunch | |
| 13:30–14:30 | Paper Session — Meta-Perspective: Field, Law & Future | |
| 14:30–15:30 | Closing Keynote: What happens after a report reaches the BSI? | Stefan Donath & Chris Ewert (BSI) |
Title and abstract to be announced.
Speakers: Stefan Donath & Chris Ewert, German Federal Office for Information Security (BSI)
Every report is more than just a notification — it is the starting point of a structured incident handling process. In this presentation, we will take a look behind the scenes at how reports are received, assessed, and analyzed by the BSI. We will also explore how incidents are prioritized, how additional information is gathered, and how the findings contribute to a better understanding of the current cyber threat landscape. Finally, we will discuss the actions the BSI may take in response, including incident coordination, technical guidance, and support provided by the BSI's CERT to help affected organizations contain, mitigate, and recover from cyber incidents. The presentation offers an overview of how effective reporting enables timely response and strengthens the overall resilience of Germany's cybersecurity ecosystem.
Short bio: Stefan Donath and Chris Ewert have both been with the BSI for several years, working among other things on the incident-reporting scheme for critical infrastructure.
Presenter: Michael Külper, Fraunhofer FKIE
DFIR investigations rarely follow a straight line. Investigators move from one clue to the next, choose tools based on emerging evidence, and continuously refine their understanding of what happened. Agentic AI is well suited to support this type of work: it can reason over findings, call tools, adapt its plan, and help decide what to investigate next. In this hands-on workshop, participants will use agentic AI to work through a realistic DFIR case involving both forensic evidence and a live system.
The workshop combines practical investigation with the theoretical foundations needed to understand modern agentic workflows. Participants will learn how AI agents plan and execute tasks, connect to external tools and data sources through protocols such as MCP, delegate work to subagents, and manage context and memory across an investigation. We will also share practical guidance on how to instruct agents, define reusable skills, and structure workflows to achieve better investigative results.
Because DFIR work requires evidence integrity, the workshop also covers practical approaches to control, safety, and traceability. Using Claude Code as an example, participants will learn how to combine human-in-the-loop approvals, permission rules, hooks, and controlled tool access to reduce the risk of unintended changes to evidence. We will also examine how to review agent transcripts and tool activity so investigators can understand, validate, and explain what the agentic system did during the workflow.
By the end of the workshop, participants will have completed a realistic agentic DFIR workflow and gained practical experience using agents to investigate evidence, control tool execution, and produce traceable results.