DFIR in Action: From Evidence to Incident Report

2–3 November 2026 • Hyatt Place, Westlands • USD 1,250 per participant

Africa’s cybersecurity community has made significant strides in threat detection and monitoring. Yet detection without investigation is an incomplete defence. When an incident occurs, the ability to determine what happened, how far the attacker moved, what was taken, and who was responsible — and to prove it — is what separates organisations that recover cleanly from those that remain exposed. That capability is digital forensics.

Overview

DFIR in Action: From Evidence to Incident Report is a two-day, hands-on workshop that delivers the complete Digital Forensics and Incident Response practitioner lifecycle — from the moment an alert fires to the moment a forensically sound report reaches the CISO’s desk. Participants will master each core forensic discipline in sequence: live acquisition, disk examination, memory forensics, log analysis, and network forensics. Crucially, every skill is taught in the context of an active incident, using real tools and real workflows, so participants learn not just what to do but when to do it, in what order, and why it matters.

The workshop is divided into two phases. Phase 1 is a facilitated skills build. The facilitator teaches each forensic discipline, demonstrates it live, then immediately places every participant in a structured hands-on exercise on the same evidence. Phase 2 is built around a multi-layerd cyber incident, in which participants will use the skillset gotten in Phase 1 to respond to. They produce a forensic report and brief the room.

Target Audience

This workshop is designed for practitioners who need to build or consolidate digital forensics skills in a hands-on environment. It suits those new to forensics as much as those who have used individual tools but have never integrated them into a complete IR workflow.

  • Incident Responders & SOC Analysts
  • Digital Forensics Practitioners
  • Law Enforcement Cybercrime Units
  • National CERTs & CSIRTs
  • Military & Intelligence Cyber Units
  • Financial Sector Security Teams
  • IT Security Engineers Moving into DFIR
Workshop Structure

Day 1 — 2 November 2026

  • Participant orientation, tool verification, and introduction to the two-phase workshop structure
  • Module 1: Evidence acquisition — order of volatility, live vs. dead acquisition, disk imaging with hash verification, RAM capture, and chain of custody documentation
  • Module 2: Disk and artefact forensics — Windows registry, prefetch data, LNK files, and browser history examined hands-on using Autopsy and supporting tools
  • Module 3: Log analysis and timeline construction — Windows Event Log triage using Chainsaw, proxy log analysis, and building a corroborated attack timeline from multiple sources
  • Module 4: Memory forensics — Volatility 3 from first principles, covering process listing, network connections, code injection detection, credential exposure, and command-line reconstruction

 

Day 2 Morning — 3 November 2026

  • Module 5: Network forensics — PCAP analysis in Wireshark, C2 beacon identification, exfiltration detection, and lateral movement tracing in network logs
  • Phase 1 synthesis: facilitator-led session connecting all five modules into a single end-to-end investigation workflow
  • Scenario brief: Case dossier distributed, investigation rules explained
  • Independent investigation: participants work through all five evidence types — disk artefacts, event logs, PowerShell transcripts, memory evidence, and network captures — without investigative guidance
  • Forensic report writing: participants produce a complete report covering executive summary, timeline, key findings, TTPs, and recommendations
  • Findings briefings: each participant delivers a two-minute verbal summary to the room
  • Full debrief, scenario solution revealed, and certificates issued
Learning Outcomes

By the end of DFIR Foundations, every participant will be able to:

  • Evidence Acquisition: Execute a structured first-responder triage workflow; acquire forensically sound disk images and RAM captures with hash verification and compliant chain of custody documentation.
  • Disk Forensics: Conduct a structured examination of a Windows logical evidence set: recover deleted files, extract registry artefacts, prefetch data, LNK files, and browser history.
  • Log Analysis: Triage Windows Event Logs and proxy logs using Chainsaw and manual analysis to identify authentication events, PowerShell activity, log clearing, and lateral movement.
  • Timeline Building: Construct a chronological, corroborated attack timeline from multiple evidence sources, with each event linked to a specific named artefact or log entry.
  • Memory Forensics: Deploy Volatility 3 against a RAM capture: identify malicious processes, injected code, active network connections, and credentials exposed in memory.
  • Network Forensics: Analyse a PCAP in Wireshark: identify C2 beacon patterns, data exfiltration events, and lateral movement in network traffic.
  • Evidence Synthesis: Combine findings across all five evidence types into a single coherent investigation narrative with no evidentiary gaps.
  • Forensic Reporting: Produce a structured, legally defensible forensic investigation report covering executive summary, scope, timeline, methodology, findings, TTPs, and recommendations
Recommended Laptop Specifications
  • Processor: 64-bit quad-core CPU, 2.0 GHz or higher (Intel Core i5/i7 or AMD Ryzen 5/7 recommended)
  • RAM: 8 GB minimum; 16 GB strongly recommended
  • Storage: 50 GB free disk space minimum (for VM image, evidence package, and tool outputs)
  • USB: One USB 3.0 port (for evidence package and toolkit distribution)
  • Operating System: Windows 10/11 (64-bit)
About the Trainer

Dr. Robinson Tombari Sibe

PhD, MSc (Digital Forensics) · LLM Candidate (Cybercrime, Cybersecurity & International Law) · M.Eng (Electronic/Telecommunication Engineering) · B.Tech (Computer Engineering)

Fellow, Nigerian Society of Engineers · Forbes Technology Council Member · AfICTA Board Member

Cybersecurity Personality of the Year — Nigeria 2025

Dr. Robinson Tombari Sibe is the CEO and Lead Forensic Examiner of Digital Footprints Limited, Nigeria’s foremost private digital forensics laboratory and cybersecurity consulting company, based in Abuja. He has over 2 decades of high impact consulting experience across several sectors. He holds Ph.D and Master of Science qualifications in Digital Forensics from the University of the Cumberlands (USA) and is completing an LLM in Cybercrime, Cybersecurity and International Law at the University for Peace/UNICRI. He also holds a Master of Engineering degree in Electronic/Telecommunication Engineering and a Bachelors degree in Computer Engineering.

Practitioner Credentials

  • Active Lead Forensic Examiner with a caseload spanning financial fraud, cybercrime, insider threats, and complex corporate investigations across Nigeria and beyond.
  • Forensic laboratory architect: designed forensic laboratories, SOPs and governance frameworks for the sovereign entities, agencies, academia, and corporate institutions.
  • International capacity-building delivery in partnership with ICMPD, FCDO, the Commonwealth Secretariat, ECOWAS, and others. Facilitated high impact forensic and cybersecurity trainings across several countries.
  • Consulted for Law Enforcement Agencies, Criminal Justice Department, Military Institutions, financial institutions, National CERTs, and multiple national cybercrime investigation.

Academic & Thought Leadership

  • Respected scholar-practioner, with affiliations with several universities such as University of South Wales, United Kingdom (Visiting Fellow), Capitol Technology University, USA (Dissertation Chair), University of the Cumberlands, USA (PhD IT Advisory Board Member), Rivers State University (Lecturer), MIVA Open University (Professor of Practice), and National Open University of Nigeria (Industry Supervisor).
  • Co-author: Cybercrime, Digital Forensic Readiness and Financial Crime Investigation in Nigeria (Springer Nature)
  • Authored several Peer-reviewed publications in respected journals.
  • Written several expert opinion articles across channels such as Forbes, Guardian, Business Day, and featured as cybercrime and digital forensic expert on BBC, Channels TV, and many other global broadcasting stations.
  • Member of the Board of Africa ICT Alliance (AfICTA).

Industry Certifications

Dr. Sibe holds several industry certifications, some of which include:

  • EC-Council Certified Chief Information Security Officer (CCISO)
  • PECB ISO/IEC 42001 (Artificial Intelligence Management System) Senior Lead Implementer
  • PECB Certified Lead Forensic Examiner (PECB, Canada)
  • PECB Certified Chief Information Security Officer (CCISO) (PECB, Canada)
  • PECB Lead Cybersecurity Manager (PECB, Canada)
  • PECB Certified Trainer (PECB, Canada)
  • Certified Cyber Crime Examiner – National White Collar Crime Center (NW3C), USA
  • Certified Economic Crimes Forensic Examiner (CECFE) – NW3C Inc, USA.
  • Cellebrite Certified Mobile Examiner (CCME)
  • Cellebrite Certified Physical Analyst (CCPA)
  • Cellebrite Certified Operator (CCO)
  • Cellebrite Certified Mobile Fundamentals (CMFF)
  • Belkasoft Certified Instructor (BelkaCI)
  • Belkasoft Certified Examiner (BelkaCE)
  • Mobile Device Investigator – ADF Solutions Inc, USA
  • Mobile Communication and Cell Forensic Analyst – SecurCube, Italy

Workshop Modules

Each module below follows the same three-step cycle: explain and demonstrate, guided practice, group debrief. All practice exercises use the Case scenario evidence package loaded on participant USB drives.

Module 1: IR Triage & Evidence Acquisition

The first hour of a DFIR engagement determines whether the investigation succeeds or fails. This module teaches the disciplined first-responder approach: what to collect, in what order, and how to document it so the evidence holds up.

  • Order of volatility — from RAM and network connections down to archive and backup — and why it governs every acquisition decision
  • Live vs. dead acquisition: the forensic trade-offs and how to document the decision
  • FTK Imager: disk imaging with hash verification, demonstrated live from selection of source to completion
  • WinPmem: RAM capture from a running system without contaminating the process list
  • Chain of custody: completing a legally defensible seizure log and evidence manifest

Module 2: Disk & Artefact Forensics

Windows cannot help leaving forensic traces, even when an attacker tries to cover them. This module covers the artefacts that survive and what each one proves.

  • Autopsy logical file ingestion: adding the workstation artefact folder as a Logical Files data source and navigating the result
  • Browser forensics: Chrome’s History SQLite database — visits, downloads, and what timestamps prove. Live demo using the workshop evidence.
  • Registry forensics: the Run key as a persistence mechanism. Live demo: identify the malicious entry in the .reg export.
  • Prefetch analysis: what execution timestamps prove. Live demo: identify tools run for the first time on the incident date from the PECmd CSV.
  • PowerShell transcripts: how script block logging captures the full attacker command sequence even when obfuscated

Module 3: Log Analysis & Timeline Construction

Logs are the story of what every account and process did across every system. But only if you know which events matter and how to combine them with artefacts into a timeline.

  • Windows Event Log structure: the six key channels and the twelve Event IDs that matter most in DFIR
  • Chainsaw: sigma-rule-based triage of large event log sets. Live demo: run Chainsaw against the Security log XML.
  • PowerShell Operational log (Event ID 4104): script block logging as the investigator’s best friend
  • Proxy log format: reading Apache/SQUID combined log, filtering by IP, identifying C2 beacon patterns
  • Timeline construction: merging artefact and log timestamps into a single corroborated narrative. Every event needs a named source.

Module 4: Memory Forensics

RAM is the one source that captures what an attacker was doing inside legitimate processes — activity that leaves no trace on disk and is gone the moment a system powers off.

  • Why RAM is irreplaceable: the classes of evidence that exist only in memory
  • Volatility 3 from first principles: what it is, how plugins work, what each plugin answers
  • pslist / windows.pstree: enumerate processes, identify suspicious parent-child relationships.
  • netstat: every active network connection. Correlate to known IPs from log analysis. Live demo.
  • malfind: detect process injection — the attacker’s technique for hiding in legitimate processes.
  • hashdump: recover NTLM hashes. What this means for understanding credential exposure and lateral movement.
  • cmdline: reconstruct the exact command line of every process, including attacker tools

Module 5: Network Forensics

Network traffic captures the attacker’s actions across the entire environment — not just the systems already examined. It answers what disk and memory cannot: what left the network, where it went, and how much.

  • PCAP structure and Wireshark orientation: protocol hierarchy, conversation statistics, navigating large captures
  • Display filters: isolating relevant traffic instantly with ip.addr, tcp.port, http filters
  • C2 beacon identification: periodic callback intervals, unusual user agents, DNS-based channels
  • Data exfiltration detection: large outbound POST requests, total bytes per conversation, staging server patterns
  • Lateral movement in traffic: SMB authentication, PsExec signatures
  • Following a TCP stream: reading the full client-server conversation

Module 6: Case Investigation

This is a realistic multi-layered cyber incident affecting the East African Federation Ministry of Finance — a fictional institution built on documented attack patterns from real African financial sector breaches. Participants must investigate it using only the evidence package and the skills from Modules 1-5.

  • The evidence is deliberately layered: no single source tells the full story. Disk artefacts establish initial access. Logs reveal lateral movement. The PCAP answers what was stolen. Only by combining all five evidence types does the complete picture emerge.
  • The attacker actively covered their tracks: the Security event log was partially cleared. Participants must work with incomplete evidence — exactly as in a real investigation.
  • There is a plausible red herring in the proxy log: one IP initially looks suspicious but proves to be a legitimate cloud update service. Jumping to conclusions without corroboration costs time.
  • The scenario has a satisfying resolution: when all five evidence types are correctly combined, the complete attack chain from phishing email to ransomware deployment and data exfiltration is fully reconstructable.
Dr. Robinson Tombari Sibe

Dr. Robinson Tombari Sibe

CEO & Lead Forensic Examiner

Digital Footprints Nigeria

DATES2–3 Nov 2026

VENUEHyatt Place WestlandsNAIROBI, KENYA

WORKSHOP COSTUSD 1,250PER DELEGATE

Digital Footprints Nigeria, logo