Bringing Chronological Context to Disparate Artifacts: Accelerating Digital Forensics @FIRSTdotorg
Bringing Chronological Context to Disparate Artifacts: Accelerating Digital Forensics  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 5 hours ago
Junya Hiwatari (NTT Social Informatics Laboratories, JP)

In digital forensics and incident response (DFIR), analysts must not only examine various artifacts but also trace their chronological relationships to understand the full scope of an incident. However, because of the complex interrelationships between artifacts, traditional manual analysis becomes increasingly time‑consuming.

To address this problem, we developed Attack Flow Finder (AFF) to automate and accelerate digital forensic investigations. AFF assists analysts by investigating and organizing artifacts according to user‑defined detection rules, called Ordered‑Sigma, which describe the intended sequence of events.

In this presentation, we will share the implementation ideas and use cases of AFF, focusing on:

designing “Ordered‑Sigma” rules;
implementing an algorithm to efficiently process chronological relationships;
comparison with existing tools;
analyzing endpoints infected with various cyber threats;
indicating response improvements through stakeholder use.
Through these points, we propose a new approach for accelerating digital forensics and discuss future challenges.


This presentations author's include Junya Hiwatari and Yuta Kuwahara.

---

Junya Hiwatari is a member of NTT-CERT and a GCFE holder. Since 2020, he has worked on digital forensics and incident response, as well as R&D on new attack detection technologies using machine learning. He is also a member of "The Institute of Digital Forensics" which promotes digital forensics in Japan. In the community, he supports collaboration among young members and contributes to developing technical documentation on cloud forensics for IaaS services, including GCP and AWS.

Yuta Kuwahara is a chief at NTT-CERT, leading the forensic team since 2025. His main expertise is in digital forensics and incident response. Previously, he worked at NTT-East, where he led projects on perimeter security and C2 server detection through network flow analysis. He also contributes to IT education in Japan by organizing the "ICT Troubleshooting Contest (ICTSC)" and actively participates in CTF competitions.
Bringing Chronological Context to Disparate Artifacts: Accelerating Digital ForensicsQuantifying Swiss Cheese, the Bayesian WayMind Over Malware: Reducing Decision Fatigue in Incident Response TeamsSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise ParticipantsEpisode 63: John Hollenberger, Fortinet, FIRSTCON26 SpeakerRevolutionizing Malware Analysis with Agentic AI: Lessons and InnovationsIdentifying Exploited and Likely-to-Be-Exploited VulnerabilitiesTaming the Scanner Storm: How VEX Brings Context to Vulnerability DataEpisode 62: Tim Brown, Team8, former SolarWinds CISO, FIRSTCON26 KeynoteUnmasking MSC FilesImproving Security Across Nations with FIRST: Dr. Lisa Bradley, FIRST PSIRT SIG Member
FIRST |

Bringing Chronological Context to Disparate Artifacts: Accelerating Digital Forensics

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER