S3:E5 // What to expect when you’re (not) expecting an incident
Every organization has an incident response plan and almost none of them survive contact with a real incident intact.
Every organization has an incident response plan and almost none of them survive contact with a real incident intact.
In this practical session, we will follow a realistic cyber fraud incident from the first SOC alert through forensic investigation and recovery. Using Magnet Axiom Cyber and Resilience’s DFIR approach, we will show how teams can move from noisy alerts to clear evidence, timelines, findings, and actions that matter.
In December 2024, Nigeria’s Economic and Financial Crimes Commission (EFCC) executed Operation Eagle Flush, a raid that arrested 792 suspects — including 148 Chinese nationals — tied to a cryptocurrency and romance scam syndicate targeting victims across North America and Europe. The operation yielded 4,222 mobile devices and 1,596 computers, with evidence requiring translation from Mandarin and other Asian languages for legal adjudication.
Cybercrimes with increasingly sophisticated digital techniques like investment fraud, pig-butchering scams, and fake trading platforms are creating new challenges for investigators West Africa.
This session addresses the critical role of pretrial preparation for investigators and digital evidence examiners who will testify at trial. Participants will learn how to coordinate with prosecutors to clarify the scope, anticipate challenges, and ensure testimony aligns with reports, exhibits, and legal theory. The goal is to promote clear, confident, and consistent testimony that withstands cross-examination and supports admissibility.
What if you could manage endpoints in the cloud without ever sending sensitive evidence there?
DFIR teams are usually stuck choosing between cloud speed and on-prem control. Magnet Nexus hybrid agents remove that trade-off — you manage endpoints and agents in Nexus (SaaS), while Axiom Cyber keeps full control over evidence collection and storage when required.
Join us to see how a single, lightweight agent supports both approaches: cloud-powered workflows for scale and reach, or collections initiated from Axiom Cyber that route data directly to your Cyber host over a configurable TCP port. Either way, you avoid unnecessary transmission of sensitive data over standard HTTPS (TCP/443) routes to the cloud.
You’ll learn:
-How one hybrid agent supports both cloud-managed and on-prem-controlled workflows
-How the data path works when collections route directly to your Axiom Cyber host instead of the cloud
-How to deploy at scale and simplify agent management across environments
-How to meet data sovereignty, compliance, and security requirements without compromise
Join us for a live, interactive Ask Me Anything (AMA) session where you can ask questions directly to seasoned digital forensics experts and get practical, real-world guidance on strengthening eDiscovery from the earliest stages of a matter.
This is your chance to ask questions directly to seasoned digital forensics experts and get practical guidance on running internal investigations from the earliest signal to final report.
Learn how the Magnet Nexus API enables automated forensic collection, processing, and triage, helping DFIR teams preserve critical evidence, accelerate investigations, and reduce MTTR.
The effectiveness of AI in digital forensics hinges on one critical factor: how you prompt it.
Join Brandon Epstein for a practical look at how to take control of AI so it works effectively for you. This session will break down what makes a good AI prompt, including effective structures and how they can produce meaningful and reliable outputs. Additionally, he’ll cover common prompting pitfalls that you’ll want to avoid, which can often introduce bias, errors, or hallucinations.
Whether you’re just starting to explore AI or looking to refine your current workflows, this webinar will give you the tools to get the most out of AI as a dependable investigative ally.