Digital Forensics and Incident Response: From Incident to Evidence Analysis

Date: October 9, 2026
Time: 7:00 PM IST | 9:30 AM EDT | 8:30 AM CDT

Topic: Digital Forensics and Incident Response: From Incident to Evidence Analysis

Register Now

Abstract: The effectiveness of an organization’s response to a cybersecurity incident depends not just on how fast it acts, but on whether that action preserves the evidence needed to understand the full scope of what occurred. Digital Forensics and Incident Response (DFIR) integrates both disciplines, giving security teams a structured approach to moving from initial detection and containment through to evidence collection, forensic analysis, and post-incident learning.

This session offers a practical walkthrough of the DFIR lifecycle, examining the procedures that guide security teams from the moment an incident is detected through to structured forensic investigation. Topics include first-response actions, evidence identification, acquisition and preservation, analysis of endpoint and network artifacts, timeline reconstruction, and the techniques used to map attacker behavior across an environment.

The webinar will also address the procedural and legal dimensions of forensic investigation, including chain of custody, documentation standards, and maintaining forensic integrity when findings may be used in internal reviews, regulatory responses, or legal proceedings. Attendees will leave with a clearer understanding of how to build DFIR processes that are both operationally effective and legally defensible.

Key Takeaways: 

  • Gaining a clear understanding of the DFIR lifecycle and how its phases work together.
  • Applying structured first-response procedures for incident triage, containment, and evidence preservation.
  • Following forensic acquisition best practices to maintain evidence integrity from collection to analysis.
  • Examining endpoint, network, system, and application artifacts to identify attacker activity and scope.
  • Using timeline reconstruction and evidence correlation to build a complete picture of attacker behavior.
  • Maintaining chain of custody and forensic documentation standards throughout the investigation process.
  • Translating DFIR investigation findings into actionable outputs for incident response, threat intelligence, compliance, and remediation.
  • Developing repeatable, defensible DFIR workflows that strengthen organizational readiness and long-term resilience

Speaker:

Harinderjeet Singh Walia, Senior Regional Manager, Critical Incident Response, Forcepoint 

Bio:  Harinderjeet Singh Walia brings more than 25 years of cybersecurity experience gained across high-security environments, including a distinguished career as a veteran of the Indian Air Force. His background spans critical information infrastructure protection, enterprise-wide security transformation, and leading incident response operations at scale.

With deep expertise across AI, penetration testing, digital forensics, threat intelligence, and enterprise security architecture, he has built a reputation for developing robust defenses against sophisticated and evolving cyber threats. Beyond his technical work, Harinderjeet is committed to developing the next generation of cybersecurity professionals, helping them align security strategy with both business objectives and regulatory requirements.

Share this post

Recent Posts

INQUIRE NOW

Related Posts

Are you looking to pursue a career in cybersecurity?

Unlock Your Cyber Security Potential at EC-Council University

Admission Inquiry

Admission Inquiry