Idaho Murders Forensic Keynote and New Digital Forensics and Incident Response AI Frameworks Headline SANS DFIR Summit 2026

Two days of practitioner-led talks and workshops across four tracks: Digital Forensics, Incident Response, Ransomware, and Threat Hunting, with select sessions available live online.

ARLINGTON, Va, Oct. 07, 2026 (GLOBE NEWSWIRE) -- The digital evidence in the University of Idaho student murders case survived deliberate attempts to erase it. Heather Barnhart, who led that forensic investigation, opens the SANS Digital Forensics and Incident Response (DFIR) Summit & Training 2026 with the story of what those attempts left behind. The keynote is the first of more than 40 talks and workshops from 39 speakers, October 15-16 in Arlington, Virginia, counting toward 12 Summit Continuing Professional Education (CPE) credits. The event arrives as AI moves into forensic and incident response casework faster than most labs have built governance for it. A panel will be held to discuss secure implementation.

As Head of Faculty at SANS Institute, Barnhart delivers the Summit's opening keynote Thursday at 9:00 a.m.: "Anti-Forensics in the Idaho Murders Case: The Traces He Left Trying to Leave No Trace," drawn from the investigation Barnhart led. In the keynote, Barnhart walks through the digital logs and artifacts that helped investigators reconstruct the case, showing how even a minimized digital footprint can still carry the weight of a larger investigation.

"Every contact leaves a trace, even when someone tries to erase it," said Barnhart. "That's the story behind this keynote, and it's the same principle behind our new AI guidance for the field. While the technology may move faster, the evidence, and the responsibility for reading and understanding it, still belongs to the practitioner."

Barnhart draws on more than 24 years of casework spanning fraud investigations, crimes against children, and counterterrorism work for government agencies, defense contractors, law enforcement, and Fortune 500 companies.

Jason Higley, founder and principal at SG Consulting, follows at 9:35 a.m. on Thursday with "From Lilith to Truth: The Digital Evidence that Put the Badge Behind the Keyboard," based on his direct work, later featured in the Netflix documentary "A Toxic Love Story." Higley, a former U.S. Department of Justice special agent, led the supplemental federal review that reexamined bodycam footage and government-issued laptop backups after the local investigation had already closed the case, uncovering the digital evidence that reopened it. That review helped clear a wrongfully jailed victim and led to a 2021 federal indictment.

Raymond DePalma, principal DFIR technical architect on Unit 42's engineering team at Palo Alto Networks, delivers Friday's keynote with "The AI System Was the Victim: Forensics for a Crime Scene With No Disk Image." All three keynotes are built from cases the speakers worked firsthand, giving attendees lessons they can measure against their own casework.

The "AI Question: What Does It Mean for DFIR?" panel, moderated by Barnhart with panelists and Summit co-chairs Ovie Carroll, Director at DOJ Cybercrime Lab, and Mari DeGrazia, Principal Instructor at SANS Institute, follows the release of SANS Faculty Fellow Joshua Wright's new book, Dynamic Incident Response: A Framework for Security Teams.

The book introduces the Dynamic Approach to Incident Response, an adaptive framework replacing the two-decade-old six-step response sequence that no longer holds up against modern incidents. The book unfolds in three parts: the elements of incident response, the DAIR model itself, and how it plays out across specific domains. DAIR aligns to NIST guidance, the Cybersecurity Framework, and current Department of War guidelines and is taught in SEC504: Hacker Tools, Techniques, and Incident Handling, the SANS flagship incident handling course Wright authors and leads. Ryan Chapman, one of this Summit's co-chairs, contributed the book's ransomware and cyber extortion chapter.

Barnhart authored two new SANS frameworks governing AI use in DFIR: one for digital forensics, aligned with the Scientific Working Group on Digital Evidence (SWGDE) Best Practices for Digital and Multimedia Evidence, and one for incident response, aligned with the NIST Cybersecurity Framework 2.0. Both treat AI as a tool that accelerates casework without owning conclusions; attribution, legal findings, and expert witness testimony remain human responsibilities.

Two Days, Four Tracks

The two days pair real investigations presented firsthand by the practitioners who worked them, with direct access to ask questions and compare notes with peers doing the same work. Sessions cover Apple and OneDrive internals in the Digital Forensics track, cloud and identity compromise in incident response, pre-encryption hunting and EDR blind spots in Ransomware, and OAuth theft and LLM agents in Threat Hunting. Fourteen SANS training courses follow the Summit, Oct. 17-22.

Registration

Summit-only registration is $525 in person or free live online. The Summit is held at the Hilton Arlington Rosslyn The Key. For more information and to register, visit sans.org/cyber-security-training-events/digital-forensics-summit-2026.

To learn more about Joshua Wright's book, Dynamic Incident Response, visit sans.org/engage/dynamic-incident-response. For more on the new DFIR AI frameworks from Heather Barnhart, visit sans.org/go/ai-assisted-human-led-trusted-investigations.

About SANS

The SANS Institute was established in 1989 as a cooperative research and education organization. Today, SANS is the most trusted and, by far, the largest provider of cybersecurity training and certification to professionals in government and commercial institutions worldwide. Renowned SANS instructors teach more than 85 courses at in-person and virtual cybersecurity events and OnDemand. GIAC, an affiliate of the SANS Institute, validates practitioner skills through more than 50 hands-on technical certifications in cybersecurity. The SANS Technology Institute, a regionally accredited independent subsidiary, offers master's and bachelor's degrees, graduate certificates, and an undergraduate certificate in cybersecurity. SANS also delivers a wide variety of free resources to the InfoSec community, including consensus projects, research reports, webcasts, podcasts, and newsletters; it also operates the Internet's early warning system, the Internet Storm Center. At the heart of SANS are the many security practitioners representing varied global organizations, from corporations to universities, working together to support and educate the global information security community. www.sans.org


Jenn Elston
SANS Institute
301-654-7267
jelston@sans.org

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Andorra Business Ledger

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.