Unlocking Insights: The Role of TI in Modern DFIR Operations @FIRSTdotorg
Unlocking Insights: The Role of TI in Modern DFIR Operations  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 46 minutes ago
Efstratios Lontzetidis (NVISO), Stef Collart (NVISO)

Incorporating Threat Intelligence (TI) into Digital Forensics and Incident Response (DFIR) can be difficult and costly based on several factors. However, this collaboration is crucial in modern incident work, significantly enhancing the DFIR operations, saving time and offering contextualization to consumers of the DFIR report. This presentation aims to explore the relationship between TI and DFIR, providing insights into how TI can be incorporated in incidents with structured processes and responsibilities, and what additional value the usage of appropriate tools and research methodologies can bring. Sample outcomes include campaign, malware family, threat actor and motivation identification as well as expansion of infrastructure through pivoting and hunting.

---

Stef Collart is a Principal Threat Hunting & Threat Intelligence consultant at NVISO. He has worked in SOC and CSIRT teams for multiple MSSPs and customers across a wide variety of sectors gaining a broad skillset. The broad skillset also reflects the interest in a broad range of topics with a current focus on incident response, threat hunting and threat intelligence.

Efstratios Lontzetidis is a Senior Threat Intelligence Consultant at NVISO. He has experience in consulting and researching roles in both private and public sectors. He holds a BSc in Applied Informatics from the University of Macedonia, a MSc in Information Security and Digital Forensics from the University of East London and certifications such as GCTI, GCIH, CPTIA, CRTIA and PJMR. His research interests include cyber threat intelligence, infrastructure hunting, and malware analysis.
Unlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding PartnerCVE/FIRST VulnCon 2026 & Annual CNA Summit Recap VideoFighting Back Without Hacking Back: Why “Risk Management” Isn’t Enough In The Era of Cyber War
FIRST |

Unlocking Insights: The Role of TI in Modern DFIR Operations

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER