APAC 2026 - Day 1
Time | Monday October 19 - Day 1 (Workshops) |
|
|---|---|---|
Workshop Track 1: Police Cantonment Complex (PCC) | Workshop Track 2: Police Cantonment Complex (PCC) |
|
12:00 | Registration Opens |
|
13:00 | Democratising Forensic Automation through Open‑Source Methods Gaurav Gogia, (Qualys) | Agentic AI for Digital Forensics and Investigation: Safely Building Interoperable Investigation Tools - Part 1 Cory Hall, (Project VIC) |
15:00 | Break |
|
15:30 | Tracing the Unauthorized Path: Evidence-Based Lateral-Movement Reconstruction Desire Abdoul Kader Bonzi, (Ritsumeiken University) | Agentic AI for Digital Forensics and Investigation: Safely Building Interoperable Investigation Tools - Part 2 Cory Hall, (Project VIC) |
17:30 | End of Day |
|
APAC 2026 - Day 2
Time | Tuesday October 20 - Day 2 (Workshops) |
|
|---|---|---|
Workshop Track 1: Suntec Singapore Convention & Exhibition Centre - Room 308 | Workshop Track 2: Suntec Singapore Convention & Exhibition Centre - Room 309 |
|
8:00 | Registration Opens |
|
9:00 | Understanding the Methods and Limits of GPS in Digital Forensics - Part 1 Charlotte Sorell, (Adelaide University) | From Isolated Digital Traces to Investigative Interpretation - Part 1 Elenore Ryser, (University of Technology Sydney) |
10:30 | Break |
|
10:45 | Understanding the Methods and Limits of GPS in Digital Forensics - Part 2 Charlotte Sorell, (Adelaide University) | From Isolated Digital Traces to Investigative Interpretation - Part 2 Elenore Ryser, (University of Technology Sydney) |
12:45 | Lunch |
|
14:00 | Normalizing and Enriching Warrant Returns With Cyber Domain Ontologies - Part 1 Cory Hall, (Project VIC) | Adversary vs Analyst: Hunting Anti-Forensic Tradecraft - Part 1 Akash Thakar, (Rashtriya Raksha University) |
15:00 | Break |
|
15:15 | Normalizing and Enriching Warrant Returns With Cyber Domain Ontologies - Part 2 Cory Hall, (Project VIC) | Adversary vs Analyst: Hunting Anti-Forensic Tradecraft - Part 2 Akash Thakar, (Rashtriya Raksha University) |
17:30 | End of Day |
|
18:00 | Social Gathering (Informal Networking) Lau Pa Sat |
|
APAC 2026 - Day 3
Time | Wednesday October 21 - Day 3 (Papers) |
|
|---|---|---|
Police Cantonment Complex (PCC) |
||
8:00 | Registration Opens |
|
9:00 | Welcome Remarks | |
9:30 | Keynote 1: Case Closed? How Agents will reshape the Future of Digital Forensics LIM Tuan Liang | Home Team Science & Technology Agency (HTX) |
|
10:30 | Break |
|
11:00 | Research Paper Session 1 - Mobile Device Forensics 1 | |
| Forensic Analysis of Virtual Phone Applications: Artifact Recovery, Provider Identification, and Automated User Attribution Yeonsu Yeo, Eunji Lee, Kiseok Lee, Gibum Kim, (Sungkyunkwan University) |
||
| Erased Photos, Surviving Faces: On-device AI Residue as a New Class of Digital Evidence in Samsung Gallery ChaeMin Park, JuHwan Park, Dohyun Kim, (Korea Maritime and Ocean University) |
||
11:50 | Presentation Session 1 | |
| Understanding Samsung’s pkgpredictions.db: Leveraging Predictive Behavioral Artifacts in Mobile Forensic Investigations Adam Firman, (MSAB) |
||
12:10 | Lunch |
|
13:40 | Research Paper Session 2 - Mobile Device Forensics 2 | |
| I Will Survive: CleanerScope, a Phase-Based Pipeline for Analyzing Residual Artifacts from Android File-Wiping Applications Uju E. Okoye, Abdus Satter, Shishir Panta, Ibrahim Baggili, (Center of Computation & Technology, Louisiana State University) |
||
| Time-Anchor: Detecting System Clock Manipulation in Android Jihye Jang, Eunji Lee, Yeon Baek, (Sungkyunkwan University); Jungho Kim, Sungjin Lee, (South Korea Financial Supervisory Service, FSS); Gibum Kim (Sungkyunkwan University) |
||
14:30 | Presentation Session 2 | |
| Operation Alice - Discovering, Analyzing and Dismantling a Network of 370k Hidden Services Thomas Goger (Bavarian Central Office for the Prosecution of Cybercrime) |
||
14:50 | Break |
|
15:20 | Keynote 2: From Craft to Court: Unifying OSINT as a Forensically Sound Discipline Mohamed Chahine Ghanem | Keele University |
|
16:20 | Presentation Session 3 | |
| Timestamp Changes between OS via SMB Share Crystal Tan, (Bank of America Merrill Lynch) |
||
| Finding Missing Children: Reassessing Leads When Digital Evidence Changes Forest Savage, (Oregon State University) |
||
17:00 | Closing Words | |
18:00 | Banquet + Award Ceremony + Rodeo The Mandala Club (Popis Penthous) 31 Bukit Pasoh Road, Singapore, 089845 |
|
APAC 2026 - Day 4
Time | Thursday October 22 - Day 4 (Papers) |
|
|---|---|---|
Police Cantonment Complex (PCC) |
||
8:00 | Registration Opens |
|
9:00 | Welcome Remarks | |
9:30 | Research Paper Session 3 - AI Forensics & Triage | |
| Evidence-Borne Prompt Injection in LLM-Assisted Textual Evidence Triage Dongho Kim, Damin Kim, Moohong Min, (Sungkyunkwan University) |
||
| STAFT: Privacy-Preserving Semantic Trace Abstraction for Forensic Triage of Personal AI Agent Incidents Minseok Hur, Jiho Shin, Moohong Min, (Sungkyunkwan University) |
||
10:20 | Break |
|
11:00 | Research Paper Session 4 - Multimedia Forensics | |
| A Forensic Methodology for Tracing Deepfake Multimedia Content Creation and Distribution on Android Smartphones Jong-in Kim, Dohyun Kim, (Korea Maritime and Ocean University) |
||
| Forensic Reliability of Publicly Accessible Image-Authentication and Deepfake-Detection Tools: An Investigator-Led Evaluation of Open-Source and Free-to-Use Platforms Michael Rettinger, Ben Beaumont, Nhien-An Le-Khac, Hong-Hanh Nguyen-Le, (University College Dublin) |
||
| CARVE: Recovering and Reconstructing Deleted H.264/H.265 Video from Honeywell Surveillance Systems Pravas Giri, Jinhee Yoon, Sungjae Hwang, (Sungkyunkwan University) |
||
12:15 | Lunch |
|
13:45 | Research Paper Session 5 - Forensic Verification, Frameworks and Methodologies | |
| CAFE: A Claim-Level Cross-Artifact Verification Framework for Assessing the Reliability of Windows Forensic Evidence under Anti-Forensic Manipulation Hyunwoo Shin, Jungheum Park, (Korea University) |
||
| Extending Detection Engineering to Digital Forensics: The Velociraptor Unified Detection-Forensics Methodology Adithyan Shaji Nambiar, Veda Dawoonauth, Aditya Kumar, (The University of Queensland); Mike Cohen, (Velocidex Enterprises); Priyanka Singh (The University of Queensland) |
||
| SoK: Operationalizing the Likelihood-Ratio Framework for Digital Evidence Jan Gruber (Karlsruhe Institute of Technology); Ruud Schramp (Netherlands Forensic Institute) |
||
15:00 | Lightning Talks (including brief talks by Poster authors) | |
15:30 | Break + Poster Session | |
16:05 | Research Paper Session 6 - File System and Database Forensics | |
| WALRUS: Reconstructing Deleted and Encrypted SQLite WALPages from Unallocated Space Sueun Jung, Jungheum Park, (Korea University) |
||
| Toward Next-Generation DFIR Triage: E01 Imaging of Selectively Collected Artifacts JunHyeong Lee, (PLAINBIT) |
||
| Active Block Hashing for Efficient Integrity Verification of Modern Storage Media and Their Forensic Duplicates Jan Gruber, (Karlsruhe Institute of Technology); Felix Freiling, (Friedrich-Alexander-Universität Erlangen-Nürnberg, FAU); Simson L. Garfinkel (BasisTech LLC) |
||
17:20 | Presentation Session 4 | |
17:40 | Concluding Remarks | |
19:00 | Informal meet up | |
Accepted Workshops
- Agentic AI for Digital Forensics and Investigation: Safely Building Interoperable Investigation Tools
Cory Hall (Project VIC International) - Democratising Forensic Automation through Open‑Source Methods
Gaurav Gogia (Qualys) - Tracing the Unauthorized Path: Evidence-Based Lateral-Movement Reconstruction
Desire Abdoul Kader, Bonzi (Ritsumeiken University) - Adversary vs Analyst: Hunting Anti-Forensic Tradecraft
Akash Thakar (Rashtriya Raksha University) - Normalizing and Enriching Warrant Returns With Cyber Domain Ontologies
Cory Hall (Project VIC International) - From Isolated Digital Traces to Investigative Interpretation
Elenore Ryser (University of Technology Sydney) - Understanding the Methods and Limits of GPS in Digital Forensics
Matthew Sorell (Adelaide University)
Accepted Papers
- Extending Detection Engineering to Digital Forensics: The Velociraptor Unified Detection-Forensics Methodology
Adithyan Shaji Nambiar, Veda Dawoonauth, Aditya Kumar, (The University of Queensland); Mike Cohen, (Velocidex Enterprises); Priyanka Singh (The University of Queensland) - Forensic Analysis of Virtual Phone Applications: Artifact Recovery, Provider Identification, and Automated User Attribution
Yeonsu Yeo, Eunji Lee, Kiseok Lee, Gibum Kim (Sungkyunkwan University) - A Forensic Methodology for Tracing Deepfake Multimedia Content Creation and Distribution on Android Smartphones
Jong-in Kim, Dohyun Kim (Korea Maritime and Ocean University) - SoK: Operationalizing the Likelihood-Ratio Framework for Digital Evidence
Jan Gruber, (Karlsruhe Institute of Technology); Ruud Schramp (Netherlands Forensic Institute) - Erased Photos, Surviving Faces: On-device AI Residue as a New Class of Digital Evidence in Samsung Gallery
ChaeMin Park, JuHwan Park, Dohyun Kim (Korea Maritime and Ocean University) - STAFT: Privacy-Preserving Semantic Trace Abstraction for Forensic Triage of Personal AI Agent Incidents
Minseok Hur, Jiho Shin, Moohong Min (Sungkyunkwan University) - I Will Survive: CleanerScope, a Phase-Based Pipeline for Analyzing Residual Artifacts from Android File-Wiping Applications
Uju E. Okoye, Abdus Satter, Shishir Panta, Ibrahim Baggili (Center of Computation & Technology, Louisiana State University) - Forensic Reliability of Publicly Accessible Image-Authentication and Deepfake-Detection Tools: An Investigator-Led Evaluation of Open-Source and Free-to-Use Platforms
Michael Rettinger, Ben Beaumont, Nhien-An Le-Khac, Hong-Hanh Nguyen-Le (University College Dublin) - Evidence-Borne Prompt Injection in LLM-Assisted Textual Evidence Triage
Dongho Kim, Damin Kim, Moohong Min (Sungkyunkwan University) - WALRUS: Reconstructing Deleted and Encrypted SQLite WALPages from Unallocated Space
Sueun Jung, Jungheum Park (Korea University) - CARVE: Recovering and Reconstructing Deleted H.264/H.265 Video from Honeywell Surveillance Systems
Pravas Giri, Jinhee Yoon, Sungjae Hwang (Sungkyunkwan University) - Toward Next-Generation DFIR Triage: E01 Imaging of Selectively Collected Artifacts
JunHyeong Lee (PLAINBIT) - Time-Anchor: Detecting System Clock Manipulation in Android
Jihye Jang, Eunji Lee, Yeon Baek, (Sungkyunkwan University); Jungho Kim, Sungjin Lee, (South Korea Financial Supervisory Service, FSS); Gibum Kim (Sungkyunkwan University) - CAFE: A Claim-Level Cross-Artifact Verification Framework for Assessing the Reliability of Windows Forensic Evidence under Anti-Forensic Manipulation
Hyunwoo Shin, Jungheum Park (Korea University) - Active Block Hashing for Efficient Integrity Verification of Modern Storage Media and Their Forensic Duplicates
Jan Gruber, (Karlsruhe Institute of Technology); Felix Freiling, (Friedrich-Alexander-Universität Erlangen-Nürnberg, FAU); Simson L. Garfinkel (BasisTech LLC)
Full Paper Acceptance Rate
This year, we received 76 research paper submissions from 22 countries, with 15 accepted after peer review – resulting in a paper acceptance rate of 19.7%.