Authors: Desire Abdoul Kader Bonzi

DFRWS APAC 2026

Abstract

After a security incident, investigators must determine who reached which system, from where, and by what route. For small and medium-sized enterprises (SMEs), this reconstruction is often performed manually across network captures and authentication logs, despite limited analyst time, computing resources, training data and telemetry. Manual correlation can confuse concurrent sessions and overlook an important administrative blind spot: a privileged identity may be entitled to manage a Tier-0 asset while reaching it through a route that policy never approved.

This half-day hands-on workshop presents a small, transparent and training-free method for reconstructing identity-reachability timelines from captured evidence. Participants investigate a scripted incident using PCAP data and Windows Security Events 4624, 4672, and 4648. They run and inspect an open Python pipeline that creates a pivot edge only when network endpoints, remote logons and session identifiers can be joined using explicit rules. Supported edges are combined into a session-aware graph and the observed route is evaluated separately from the identity’s entitlement. When evidence or policy context is incomplete, the method reports insufficient evidence or insufficient context instead of inferring a connection that cannot be supported.

An optional CloudTrail exercise demonstrates how successful AWS STS AssumeRole activity can be expressed using the same reachability vocabulary while preserving the original cloud evidence and avoiding unsupported cross-environment identity links. Participants leave with a versioned offline lab kit, practical reference material and an examiner-readable report derived from hashed inputs. The implementation is presented as a scoped proof of concept for teaching and reproducible case reconstruction, not as a production forensic engine or a real-time detection system.

 

Biography

Desire Abdoul Kader, Bonzi

Downloads