DFIR
Digital Forensics and Incident Response
Digitale Forensik und Reaktion auf Sicherheitsvorfälle
DFIR combines two closely related disciplines: the response to an ongoing security incident (incident response) and the forensic clarification of what exactly happened (digital forensics). The goal is both at once — to stop the attack and to understand it in an evidentially sound way. DFIR is the operational answer to the worst case.
History & facts. The two sides are in tension: incident response pushes for rapid containment, forensics for the preservation of traces — premature rebuilding destroys evidence. Well-practised DFIR work resolves this conflict through methodology: secure first, then contain, document in parallel. Common phases are preparation, detection, containment, eradication, recovery and review (lessons learned). Threat behaviour is often classified against ATT&CK.
Outlook & recommendation. Under NIS2, the capability for incident handling — including the reporting and evidence duties towards the BSI — is no longer optional. Preparation is decisive: those who only begin to clarify responsibilities, contacts and acquisition workflows during the incident lose valuable time. DFIR is a core competence of NEOSEC — from evidentially sound preservation through analysis to authority-grade documentation.