Uploaded August 2026 | Updated September 2026, 5 hours ago
Junya Hiwatari (NTT Social Informatics Laboratories, JP)
In digital forensics and incident response (DFIR), analysts must not only examine various artifacts but also trace their chronological relationships to understand the full scope of an incident. However, because of the complex interrelationships between artifacts, traditional manual analysis becomes increasingly time‑consuming.
To address this problem, we developed Attack Flow Finder (AFF) to automate and accelerate digital forensic investigations. AFF assists analysts by investigating and organizing artifacts according to user‑defined detection rules, called Ordered‑Sigma, which describe the intended sequence of events.
In this presentation, we will share the implementation ideas and use cases of AFF, focusing on:
designing “Ordered‑Sigma” rules;
implementing an algorithm to efficiently process chronological relationships;
comparison with existing tools;
analyzing endpoints infected with various cyber threats;
indicating response improvements through stakeholder use.
Through these points, we propose a new approach for accelerating digital forensics and discuss future challenges.
This presentations author's include Junya Hiwatari and Yuta Kuwahara.
---
Junya Hiwatari is a member of NTT-CERT and a GCFE holder. Since 2020, he has worked on digital forensics and incident response, as well as R&D on new attack detection technologies using machine learning. He is also a member of "The Institute of Digital Forensics" which promotes digital forensics in Japan. In the community, he supports collaboration among young members and contributes to developing technical documentation on cloud forensics for IaaS services, including GCP and AWS.
Yuta Kuwahara is a chief at NTT-CERT, leading the forensic team since 2025. His main expertise is in digital forensics and incident response. Previously, he worked at NTT-East, where he led projects on perimeter security and C2 server detection through network flow analysis. He also contributes to IT education in Japan by organizing the "ICT Troubleshooting Contest (ICTSC)" and actively participates in CTF competitions.
Junya Hiwatari (NTT Social Informatics Laboratories, JP)
In digital forensics and incident response (DFIR), analysts must not only examine various artifacts but also trace their chronological relationships to understand the full scope of an incident. However, because of the complex interrelationships between artifacts, traditional manual analysis becomes increasingly time‑consuming.
To address this problem, we developed Attack Flow Finder (AFF) to automate and accelerate digital forensic investigations. AFF assists analysts by investigating and organizing artifacts according to user‑defined detection rules, called Ordered‑Sigma, which describe the intended sequence of events.
In this presentation, we will share the implementation ideas and use cases of AFF, focusing on:
designing “Ordered‑Sigma” rules;
implementing an algorithm to efficiently process chronological relationships;
comparison with existing tools;
analyzing endpoints infected with various cyber threats;
indicating response improvements through stakeholder use.
Through these points, we propose a new approach for accelerating digital forensics and discuss future challenges.
This presentations author's include Junya Hiwatari and Yuta Kuwahara.
---
Junya Hiwatari is a member of NTT-CERT and a GCFE holder. Since 2020, he has worked on digital forensics and incident response, as well as R&D on new attack detection technologies using machine learning. He is also a member of "The Institute of Digital Forensics" which promotes digital forensics in Japan. In the community, he supports collaboration among young members and contributes to developing technical documentation on cloud forensics for IaaS services, including GCP and AWS.
Yuta Kuwahara is a chief at NTT-CERT, leading the forensic team since 2025. His main expertise is in digital forensics and incident response. Previously, he worked at NTT-East, where he led projects on perimeter security and C2 server detection through network flow analysis. He also contributes to IT education in Japan by organizing the "ICT Troubleshooting Contest (ICTSC)" and actively participates in CTF competitions.










