Stop Drowning in Logs: AI Accelerated Incident Response

No ratings

Presented at ChiBrrCon 2026 by

DFIR today involves millions of artifacts, hundreds of thousands of logs with a hundred different sources. An analyst would spend more time collecting, normalizing and then searching for data rather than reasoning about what happened. An average incident resulting in large timelines as APTs and ransomware gangs today, equipped with AI to help them on their quest for world encryption. So why not look at the problem? The analysts spending hours analyzing and looking at logs, a hundred different tools and then normalizing the mess... phew! This makes DFIR the path with the highest burnout rates withing the cybersecurity domain. The solution to this is relatively simple, or is it? Let's dive into employing the OSDFIR framework to automate investigations and as a plus, leveraging the ability of LLMs to work with opensource tools like OpenRelik and Tmesketch (both would be explained to the audience) to make this workflow applicable in your day to day forensics and incident response scenarios. I would demonstrate how a practical, end-to-end workflow using the above can be set and show the audience a demo where I prompt an LLM to identify malicious activity within a defined time frame. We will walk through a realistic muti-stage timeline where forensic artifacts are standardized and is used to build an enriched timeline for the the LLM to work with. The process to do the same would be explained followed by a short demo on the final product: a solution where you can ask the LLM using prompts in natural language to identify malicious activity!