From Hours to Minutes: Automating Incident Response Triage with Open-Source Tools

Description

Learn how to automate incident response triage using open-source tools. This talk shows how to go from forensic collection to collaborative analysis in minutes, with real-world workflows and cloud-based automation.

Markus Einarsson

Markus Einarsson is a Security Architect and Incident Response Lead at Sectra in Sweden, where he secures cloud-hosted environments for healthcare customers worldwide. With over a decade of experience in cybersecurity, Markus specializes in incident response, digital forensics and security architecture.

As part of the Sectra Hunt and Incident Response Team, he has extensive hands-on experience with forensic workflows and modern DFIR toolchains. Markus holds multiple GIAC certifications including GEIR, GCDA, GCFE, GCFA, GRID, GNFA, GCIA and GCIH. He is passionate about scalable incident response methodologies and advancing open-source forensic tools.