Eiffel: A Tool to Oversee Incident Response From the Heights @FIRSTdotorg
Eiffel: A Tool to Oversee Incident Response From the Heights  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 10 hours ago
Óscar Salvador (Cybersecurity Agency of Catalonia, ES), Juan Gonzalez (Cybersecurity Agency of Catalonia, ES)

Modern incident response teams often face situations where dozens or even hundreds of endpoints require rapid triage and preliminary forensic analysis. Traditional manual approaches may not always scale efficiently and can slow down decision‑making during high‑pressure investigations.

Eiffel is a soon‑to‑be‑open‑source solution designed to assist DFIR practitioners during investigations, enabling analytics and SIGMA‑based alerts on top of large volumes of evidence, helping them find the few key needles in the haystack of logs, KAPE targets, and Velociraptor hunts.

This session will cover Eiffel’s current architecture and core components and will touch on how AI can leverage — or be leveraged by — the platform to unlock new critical capabilities. Attendees will leave with a clear understanding of how a solution like Eiffel can help their teams and how they could improve their evidence‑processing pipelines.

---

Óscar Salvador:Experienced systems and cybersecurity specialist with more than 10 years of expertise in IT infrastructures, cybersecurity incident response, digital forensics, and security engineering. Currently, I work for the Cybersecurity Agency of Catalonia where I serve as the head of the Incident Response team at CATALONIA-CERT, a role that involves addressing cybersecurity challenges that affect the Government of Catalonia and its related public sector.

Juan Gonzalez: Computer scientist with over 17 years of experience as a team leader in cybersecurity incident response, threat analysis, pentesting, and file system researching. I currently work at the Cybersecurity Agency of Catalonia, from where I serve as the head of the CATALONIA-CERT, which is the Government of Catalonia's CSIRT. At our CERT we deal on a daily basis with cyberincidents that might affect hospitals, universities, municipalities and information systems that provide service to more than 8M people in Catalonia. Before joining the Cybersecurity Agency of Catalonia I worked as a senior cybersecurity consultant at EY and as a file systems engineer both at Xyratex, a Seagate Company and at the Barcelona Supercomputing Center.
Eiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT OrganizationsMonday Keynote: Perseverance, Growth and Success. The Sunburst Story from the CISO perspective.Evaluating Threat Intelligence Through VelocitySaving Ourselves the ID Headache: How Purls Can Work for Models and DatasetsImproving Security Across Nations with FIRST: Sneha Rangari, FIRSTCON26 SpeakerNational CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination Cases
FIRST |

Eiffel: A Tool to Oversee Incident Response From the Heights

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER