
ISS World Europe is the world's largest gathering of Regional Law Enforcement, Intelligence and Homeland Security Analysts, Telecoms as well as Financial Crime Investigators responsible for Cyber Crime Investigation, Electronic Surveillance and Intelligence Gathering.
ISS World Programs present the methodologies and tools for Law Enforcement, Public Safety, Government and Private Sector Intelligence Communities in the fight against drug trafficking, cyber money laundering, human trafficking, terrorism and other criminal activities conducted over today's telecommunications network, the Internet and Social Media.
Track 1: Lawful Interception and Criminal Investigation Training
Track 2: LEA, Defense and Intelligence Analyst Product Presentations
Track 3: Social Network Monitoring, Artificial Intelligence and Analytics Product Training
Track 4: Threat Intelligence Gathering and Cyber Security Product Training
Track 5: Investigating DarkWeb, Bitcoin, Altcoin and Blockchain Transaction
Track 6: Mobile Signal Intercept Training and Product Presentations
Track 7: Electronic Surveillance Training and Product Presentations
Track 8: 5G Lawful Intercept, Tracking and Forensics Product Training
Plus Special Training Seminars lead by Law Enforcement Officers and Ph.D. Scientists
Training Seminars Led by Law Enforcement Officers and Ph.D., Computer Scientists
20 classroom training hours, presented by Law Enforcement Officers and Ph.D. Scientists
Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
(9 classroom hours)Jerry Lucas (Ph.D., Physics), President, TeleStrategies
(1 classroom hours)Matthew Lucas (Ph.D., Computer Science), VP, TeleStrategies
(4 classroom hours)Vladimir Vesely (Ph.D., Computer Science) Researcher, Brno University of Technology
(3 classroom hours)
Tuesday, 1 June 2027
Seminar #1
08:30-15:05Online Social Media and Internet Investigations
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police08:30-09:15
Proxies and VPNs: Identity Concealment and Location Obfuscation
09:30-10:15
Tor, onion routers, Deepnet, and Darknet: An Investigator's Perspective
10:30-11:15
Tor, onion routers, Deepnet, and Darknet: A Deep Dive for Criminal Investigators
11:30-12:15
Cellular Handset Geolocation: Investigative Opportunities and Personal Security Risks
13:15-14:00
Ultra-Wideband Geolocation and Cyber OSINT
14:15-15:00
Collecting Evidence from Online Social Media: Building a Cyber-OSINT Toolbox
Seminar #2
08:30-09:20Understanding Mobile 2G, 3G, 4G, 5G and 6G Infrastructure and Law Intercept for Technical Investigators
Presented by: Dr. Jerry Lucas, President, TeleStrategiesThis session addresses the infrastructure evolution of 2G to 3G to 4G to 5G NSA and the impact on lawful interception.
Seminar #3
09:25-10:15Understanding 5G/5GA/6G LI for Investigators
Matthew Lucas (Ph.D, Computer Science), VP, TeleStrategiesThis session addresses the challenges facing law enforcement and ISS vendors responsible for intercept on 5G networks.
Seminar #4
10:35-11:25AI Technology Basics and LEA Use Cases
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesSeminar #5
11:30-12:20Generative AI Use Cases and Capabilities for Law Enforcement and Intelligence Agencies
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesSeminar #6
13:20-14:10Agentic AI - Deployment Options and Approaches
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesThursday, 3 June 2027
Seminar #7
8:30-9:15Unmasking Hidden Evidence: Metadata & EXIF for Digital Investigators
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #8
10:15-11:00Push Tokens in Criminal Investigations: Tracing Digital Footprints & Uncovering Evidence
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #9
11:30-12:15Understanding the Implications of Online Social Media for OSINT During Critical Incidents
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PolicePre-Conference Sessions Description At The End of Agenda PostinG
Welcoming Remarks and Top Ten Challenges
Wednesday, 2 June 2027
8:15-8:30 Tatiana Lucas, ISS World Program Director, TeleStrategies
8:30-9:00
Top Ten Internet Challenges Facing Law Enforcement and the Intelligence Community and Who at ISS World Europe has Solutions
Dr. Jerry Lucas, President, TeleStrategies
ISS World Europe Exhibit Hours:
Tuesday, 1 June 2027
10:00-18:15Wednesday, 2 June 2027
10:00-18:15
Thursday, 3 June 2027
10:00-14:00
Track 1: Lawful Interception and Criminal Investigation Training
This track is for Telecom Operators and Law Enforcement/Intelligence/Defense Analysts who are responsible for specifying or developing lawful intercept network infrastructure.
*Note: Sessions open to only LEA/Government attendees in this track will have (Open to LEA and Government attendees only) above their title.
Tuesday, 1 June 2027
14:15-15:05
Automated Compliance & e-CODEX: Navigating the New Era of Data Retention
This session delves into data retention automation, preservation orders, and e-CODEX compliance. Discover how an agile platform handles shifting regulations and "data freezes" with ease, featuring lightning-fast IP-searches in a hybrid reality and automated disclosure processes. Using real-world CSP insights, we show how to mitigate legal risks while reducing operational costs. Discover how leveraging multi-source network data from CDRs, passive probes and more empowers CSPs to deliver enriched and secure results with efficiency, seamlessly transferring insights to law enforcement agencies.
Presented by Subtonomy
16:10-17:00 Session B
400G SmartNICs: Accelerating Security and AI at Line Rate
Presented by Napatech
Wednesday, 2 June 2027
15:00-15:40 Session B
Analyzing Social Networks
BREVIS and OSINT Plugin for i2 Analyst Notebook. Analyze Social Networks – Twitter, Facebook, Linkedin, YouTube, VK, Instagram, TikTok, Telegram, WhatsApp and Pipl.
Presented by MKCVI
Thursday, 3 June 2027
9:15-10:00 Session A
Thou shalt wirelessly intercept your neighbor: Leveraging WiFi and Bluetooth in operative
In this talk, we shall discuss various security mechanisms used in WiFi and Bluetooth networks and how to abuse them to obtain mission-critical intel. Apart from explaining all principles, we will demonstrate them (hopefully live) on our tactical device! Starting with an access point and client scans, we will continue with client targetted jamming and total Denial-of-Service of the whole network that may even result in authentication handshake capture. This handshake contains information to recover the WiFi password to access the targeted network. Once inside the network, we will show essential hacking tools to conduct IP-level reconnaissance. But we will not limit ourselves to WiFi and demonstrate how Bluetooth can be leveraged to notify you about a person's presence or exploit various IoT devices.
Vladimir Vesely (Ph.D., Computer Science), Jan Pluskal (Ph.D., Computer Science), Matej Gregr (Ph.D., Computer Science), researchers, Brno University of Technology9:15-10:00 Session B
Unmasking Hidden Evidence: Metadata & EXIF for Digital Investigators
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police11:00-11:40 Session A
DEEPFAKE FORENSICS: DEFENDING OURSELVES AGAINST MULTIPLE THREATS
Synthetic imagery and video creation comes in different flavours: Generative Adversarial Networks, diffusion models, text-to-image generators, image-to-image generators and AI integration in popular off the shelf image and video editors (such as Adobe Photoshop, Premiere etc.). Each of these may require different detection strategies. In this presentation we will discuss and demonstrate the typical forensic workflow for detecting deepfakes, including metadata analysis, processing history, geometrical analysis and AI based detection
Emi Polito, CFVA, Forensic Analyst, Amped Software11:00-11:40 Session B
Push Tokens in Criminal Investigations: Tracing Digital Footprints & Uncovering Evidence
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police11:00-11:40 Session C
Beyond the Signal: Following the Money Trail by uncovering Hidden Owners, Shell Companies & Criminal Infrastructure
Yarden Bilovich, Moody's11:45-12:30 Session A
Trending Topics in Cryptocurrency Forensics
Bitcoin, Ethereum and other cryptocurrencies are becoming mainstream for financial interactions and standard tools when conducting cybercrime such as scams, frauds, ransomware, darknet markets, sextortion, etc. LEAs also adapted to a new situation, and many investigators are already familiar with cryptocurrency basics and how to trace transactions on publicly available blockchain explorers. This session aims to extend the knowledge of participants about more advanced topics such as: a) address clustering techniques and their applicability to various cryptocurrencies; b) monitoring of cryptocurrency networks and their peers with the help of network intelligence; c) geolocating cryptocurrency transaction with IP address or originator; d) overcoming obfuscation of transactions entering and leaving mixers; e) correlating activities on darkweb with blockchain events. Each subtopic will be thoroughly explained, including currently existing methods and tools for addressing associated challenges.
Vladimir Vesely (Ph.D., Computer Science), Jan Pluskal (Ph.D., Computer Science), Matej Gregr (Ph.D., Computer Science), researchers, Brno University of Technology11:45-12:30 Session B
Understanding the Implications of Online Social Media for OSINT During Critical Incidents
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
13:00-13:40
Mastering the password cracking
This session will cover the use of passwords in digital life, exploring cracking techniques such as dictionary, rule-based, brute-force, hybrid and association attacks. We'll provide benchmarks for state-of-the-art password recovery hardware and discuss their feasibility. Finally, we'll look at how leaked personal information can aid password discovery and enhance hacking efforts.
Vladimir Vesely (Ph.D., Computer Science), Jan Pluskal (Ph.D., Computer Science), Matej Gregr (Ph.D., Computer Science), researchers, Brno University of Technology
Track 2: LEA, Defense and Intelligence Analyst Product Presentations
This track is only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, 1 June 2027
9:25-10:15 Session A
From Mobile Forensics to Countering National Security Threats: AI-Powered Data Fusion
This session explores how national security teams can transform mobile forensic extractions into comprehensive, multidomain investigations by fusing device data with OSINT, leaks, CDRs, geospatial movement, and crypto intelligence within a single collaborative workflow. Rather than treating forensics as a standalone lab function, Falkor turns extracted data into shareable, AI-driven investigative intelligence. This helps analysts uncover facilitators, meeting points, influence networks, and funding trails faster across local and national levels.
Presented by Falkor9:25-10:15 Session B
The Future of Criminal Analysis: One Platform, Generative AI, Data Fusion, Digital Forensics, Biometrics, and 20+ Analytical Tools.
Presented by 4Sec10:35-11:25 Session A
Decoding the Digital Shadows: AI powered Investigations
Presented by Datafusion Sytems10:35-11:25 Session E
Finding needles in Terabit-sized haystacks: Application filtering on live OTU4/1000GbE/400GbE+ networks
The challenges of searching through huge volumes of traffic on transport links have never been greater. Learn how wide-view visibility of the whole network pairs with focused traffic filtering to provide unparalleled insights. Explore how to filter on layer 7 applications, form targeted rule sets and ultimately focus on only the traffic of interest, discarding all unwanted data. Understand how to identify and deal with encrypted traffic types (QUIC, TLS and others), expose terminal IP sessions from inside deep tunnelling structures (MPLS, VLAN etc) and ultimately find the crucial needles of actionable intelligence.
Alan Anderson Ph.D., Chief Technology Officer, Lumacron Technology
11:30-12:20 Session A
From Insight to Safety: The Intelligence Behind Major Event Security
Presented by Rayzone Group13:20-14:10 Session A
Introducing the I Family - Where Identifiers Become Complete, Actionable Identities
Presented by Rayzone Group13:20-14:10 Session B
Turning Insights into Action: Leveraging Dark Data and Risk Intelligence Databases
Presented by CHAPSVISION13:20-14:10 Session E
Hunting in the Dark: From Covert Channels to C2 Attribution
Adversaries hide inside encrypted sessions, trusted protocols, and low-and-slow communications that evade traditional monitoring. This session shows how DNS, TLS/JA4, and SSH metadata can expose covert exfiltration, map C2 infrastructure, and identify suspicious tools — without decrypting user content. Attendees will learn how these signals can feed AI-assisted analytics to surface weak indicators faster and turn high-volume network activity into actionable intelligence.
Presented by NetQuest14:15-15:05 Session A
Enhancing Real-time Intelligence from Seized Devices with Tactical Location Analytics
During missions, field agents confiscate devices with crucial location data and valuable, timely intelligence insights – but if they can't analyze it in the field, opportunities are wasted. Tactical location solutions that require no internet, operate on a laptop, and offer drag-and-drop ingestion help transform seized data into real-time, actionable intelligence.
Presented by SS8
14:15-15:05 Session B
Agentic AI for Law Enforcement and National Security: Tales of Extraordinary Impact from 6-Month Deployments with EU Forces and Beyond
Presented by Octostar14:15-15:05 Session C
Markland: Acquire and fuse Intelligence at ultrahigh speeds
Hear about the latest innovation in our intelligence platform for acquiring, decoding and fusing data from multiple sensors at ultrahigh speeds, incl. satcom, high-speed IP links, structured and unstructured data sources. See what it a unified intelligence picture can do for you, and how easy it is populated with information automatically extracted and labelled via AI content analytics.
Mark Uldahl, CTO, XCI15:25-16:05 Session A
Digital Crime Scene Essentials: Cybercrime Tools, Analysis, and Forensic InfrastructureFocused exploration of cybercrime investigations, analysis tools, advanced forensic software, and specialized hardware solutions for lab and field use.Presented by mh-service GmbH15:25-16:05 Session B
Actionable intelligence on the Edge
This session dives into the latest innovations shaping modern investigations — from unlocking devices and cutting through terabytes of data, to drone evidence and AI-assisted analysis. Whether you’re in law enforcement, a forensics lab, or a specialised unit, we’ll show you how agencies are turning overwhelming volume into clear, actionable intelligence — faster than ever before.
Andrew Martin, Head of EMEA Solution Engineering, Cellebrite15:25-16:05 Session C
Lessons Learned: Deploying AI Speech Technologies in Air-Gapped Environments
Drawing from several years of real-world deployments, this session shares lessons learned implementing and supporting automatic speech recognition (ASR) and translation tools in high risk, on-premises environments at scale. We’ll dive deep into the end-to-end offline speech processing pipeline, exploring the tradeoffs around ASR accuracy, speed, and hardware costs, their downstream impacts, and where this technology is headed next.
Sean Thibert, Senior Product Manager, AI Solutions, JSI15:25-16:05 Session D
VPNz – Unveiling and Locating VPN Users
VPN users often assume their connections grant full anonymity and protection from tracking. This VPNz challenges that assumption by exploring how such users can still be identified and located
Presented by Targeteam15:25-16:05 Session F
OVINT: The Future of Intelligence for the Video-First Era
As the world shifts from text to video, traditional intelligence methods are falling behind. In this talk, we introduce OVINT (Open Video Intelligence) — a new paradigm for collecting, analyzing, and understanding massive volumes of online video in real time. Discover how next-generation platforms can transform fragmented visual content into actionable insights, enabling governments and organizations to detect threats, monitor events, and make faster, more informed decisions in an increasingly video-driven world.
Presented by Senai16:10-17:00 Session A
CDRs, Financial Records, OSINT, Device Forensics: One Target Was Hiding Across All Four. Nobody Knew.
Presented by ClearTrail16:10-17:00 Session C
One Investigation, Many Sources: Validating CDRs, Live LI, Mobile Forensics and Field Data in a Single AI-Assisted Intelligence Platform
Use cases and demonstration.
Presented by AREA16:10-17:00 Session D
VASTech Orca: A cutting-edge, modular, end-to-end system for fibre, satellite, and signals intelligence fusion.
Presented by VASTech16:10-17:00 Session E
Spyder Space: Movia's Revolutionary Platform for Real-Time Decision Intelligence
Cutting-edge data fusion technology breaking through delayed analytics, powered by the innovative force of AI!
Presented by Movia16:10-17:00 Session F
Closing the Gaps: Multi-Layered Intelligence for Border & Maritime Threats
Border and maritime security agencies face increasingly sophisticated threats. This session presents a multi-layered intelligence framework that integrates signals, analytics and operational workflows to address today’s complex challenges. Discover how combining technologies and intelligence disciplines improves threat detection, border monitoring and response capabilities.
Boris Pashayev, Cognyte
Wednesday, 2 June 2027
09:10-10:00 Session B
Digital Crime Scene Essentials: Cybercrime Tools, Analysis, and Forensic InfrastructureFocused exploration of cybercrime investigations, analysis tools, advanced forensic software, and specialized hardware solutions for lab and field use.Presented by mh-service GmbH
09:10-10:00 Session C
The 5G-Ready Cyber Intelligence Monitoring Centre: Centralizing Lawful Interception, Electronic Surveillance and Investigative Analytics
Use cases and demonstration.
Presented by AREA
13:00-13:40 Session A
Drones Redefining Tactical SIGINT
Presented by Ateros13:00-13:40 Session B
Advanced Geo-Location Intelligence and IP-Mapping for Investigations
This session focuses on advanced investigative functionalities designed for modern intelligence needs. We demonstrate live how Cross Location Analysis, IMSI Comparison, and Timing Advance Cell Tracing can pinpoint targets in real-time and historically with surgical precision. Learn how to identify the users behind complex IPv4/IPv6 mixed environments with speed and accuracy. See how multi-source network insights turn complex data sets into the evidence needed for successful prosecutions, supported by full audit trails for total transparency.
Presented by Subtonomy13:00-13:40 Session C
“Stargetz – Unmasking Starlink Terminal Users”
Starlink users often believe satellite connectivity makes them invisible. This session demonstrates how that assumption breaks down, revealing methods to uncover user location and link activity to real-world identities.
Presented by Targeteam13:45-14:30 Session B
Spyder Space: Movia's Revolutionary Platform for Real-Time Decision Intelligence
Cutting-edge data fusion technology breaking through delayed analytics, powered by the innovative force of AI!
Presented by Movia13:45-14:30 Session C
Acquire to Act - Operationalising Intelligence across the Investigation Lifecycle
From lawful data acquisition through monitoring centre analysis to decision and operational coordination, this session shows how intelligence is turned into real world action.
Jez Nelmes, Product Manager, BAE Systems Digital Intelligence13:45-14:30 Session D
IP Intelligence at Scale: Smarter Investigations, Faster Answers
Operators and analysts today are not lacking in IP data. They are lacking timely answers. This session explores how next generation IP decoding helps reduce time to insight by turning IP data into clear, actionable intelligence through an intuitive and scalable approach. It enables faster understanding of relationships, locations, patterns of digital activity, including crypto-related activity, without requiring specialized expertise. The result is reduced analysis time and a more efficient path from data to actionable intelligence.
Yanir Zolotov, Director of Product Management, Network Intelligence, Cognyte13:45-14:30 Session E
From Device Control to Operational Control: Rethinking Mobile Operations
Mobile devices are widely secured with encryption, management tools, and policies—yet real-world operations still fail from a security perspective. The core issue is that security often relies on user decisions and changing environments that cannot be fully controlled.
This session explores how mobile security must evolve from device-level control to true operational control—where device behavior, connectivity, and communications are enforced consistently. The focus is on removing unsafe choices and ensuring predictable, secure operations in real-world conditions.
Presented by Bittium
15:00-15:40 Session A
Unmasking Cybercriminals: Intelligence Fusion for Modern Cybercrime Investigations
Cybercriminals often operate behind aliases, fragmented online identities, encrypted channels, and stolen infrastructure. But even the most careful actors leave traces across underground communities, open sources, compromised accounts, infostealer logs, and operational activity. In this session, KELA will explore how modern cybercrime investigations use intelligence fusion to connect these scattered signals and expose the actors behind the activity. By combining cyber threat intelligence, OSINT, AI-driven analysis, infostealer intelligence, and compromised account data, investigators can move beyond isolated usernames or indicators and build a clearer picture of threat actor identities, networks, behaviors, and intent. Attendees will learn how this approach supports faster investigations, stronger attribution, and more actionable intelligence for law enforcement, government agencies, and security teams working to disrupt cybercrime operations.
Or Lev, KELA15:00-15:40 Session B
MOBILedit Forensic: From Smartwatch Evidence to AI-Driven Intelligence
Digital forensics is evolving—from extracting data to truly understanding it.
This session introduces MOBILedit Powered by AI, a composite analysis engine designed specifically for forensic workflows. Unlike generic AI approaches, it builds conclusions grounded in real data, with every insight supported by traceable evidence paths that clearly explain how and why results are produced.
See how advanced analysis can reveal hidden connections, contextual relationships, and meaningful patterns across complex datasets—helping investigators move from raw data to verified intelligence.
Alongside this, explore the latest advancements in MOBILedit Forensic ULTRA, including powerful phone unlocking and security bypassing, as well as industry-leading smartwatch forensics. Learn how data from health metrics, location tracking, and activity logs provides critical context for modern investigations.
From smartphones and smartwatches to AI-powered analysis, discover a complete forensic workflow—from extraction to defensible conclusions.
Presented by Compelson15:00-15:40 Session C
REFLECTED IDENTITIES: The Target May Be Silent. The Ecosystem Is Not
Mr. Aviel Lev Astanovsky, BOLD Intel15:00-15:40 Session D
Locating the Invisible: Geo-Intelligence in Cybercrime and Counter-Terror Operations
Presented by Rayzone Group
15:00-15:40 Session E
REVEL·IO by Synacktiv : Accelerating digital evidence accessWhat if you could unlock phones faster by leveraging GPU performance?What if brute-force attacks could be offloaded to a dedicated server?What if you could benefit from a European mobile forensic solution that significantly reduces the time needed to access phone data?What if you haven’t discovered REVEL·IO yet?
Presented by Synaktiv15:00-15:40 Session F
CDRs of WhatsApp, Signal, Telegram, and other encrypted VoIP messaging applications
Presented by ClearTrail15:45-16:25 Session E
VASTech Orca: A cutting-edge, modular, end-to-end system for fibre, satellite, and signals intelligence fusion.
Presented by VASTech15:45-16:25 Session D
The Impact of AI on End-to-End Lawful Intelligence: Opportunities and Challenges
Investigators need efficient tools to help extract critical intelligence from vast databases. AI technologies like video and voice analytics, facial recognition, and automatic number plate readers are revolutionizing lawful intelligence, but introduce challenges. We must harness the transformative potential of these platforms while remaining vigilant for bias and misleading conclusions.
Presented by SS8
16:30-17:15 Session A
The ADINT Fusion Trap: Why Modern OPSEC Must Avoid Correlation, Not Just Hide IP Addresses
Investigators and analysts must operate online — yet staying anonymous is harder than ever. Reporting in May 2026 confirmed the threat once more: commercial tools can locate and identify anyone by fusing advertising IDs (ADINT), app telemetry and browsing traces — without breaking encryption. Single-layer protection fails because modern attribution correlates around it, not through it.
This session presents an infrastructure-first architecture — centrally managed multi-hop egress, sandboxed workspaces, persona separation — engineered to keep investigators invisible by design. Field insights included.
Presented by slinf AG16:30-17:15 Session B
Cutting Through the Noise: Enhancing Lawful Interception with Intelligent IP Traffic Profiling.
High-bandwidth networks like LTE, 5G, and fiber introduce significant processing challenges for lawful interception systems. Most traffic—such as video streaming or OS updates—carries no investigative value. This session shows how IP Traffic Profiling helps isolate relevant data and reduce costs while boosting operational efficiency.
Presented by Group 200016:30-17:15 Session C
Instant deployment of a multi-audio streaming system with live speaker identification and speech analysis.
Presented by Gedion16:30-17:15 Session D
Beyond RAG: Designing Agentic Applications for Investigations
This session reviews the patterns and techniques used to build agentic applications in high-risk, on-premises environments. We’ll cover real-world investigative use cases, then dive into the practical considerations that determine success: LLM selection, retrieval and analysis pipelines, agentic frameworks, benchmarking, and hardware considerations.
Sean Thibert, Senior Product Manager, AI Solutions, JSI16:30-17:15 Session F
Raw PCAPs and IPDRs to Patterns-of-Life: What Took Weeks Now Runs on a Laptop in Hours
Presented by ClearTrailThursday, 3 June 2027
08:30-09:10 Session B
Password Cracking on FPGA Infrastructure
Short introduction to the math behind encryption complexity. Overview of options to overcome encryption, highlighting password and key search on FPGA-infrastructure. Focus on practical recommendations for resource selection. Audience should have general technical interest, but expert-knowledge is not necessary.
Presented by SciEngines08:30-09:10 Session C
Jomsborg: Lawful Interception with unmatched decoding capabilities
Stuck with an old LI system? Missing out on all the communication in the IP domain. Hear about the latest features in a modern LI system that has all the traditional features plus unmatched encrypted communications decoding capabilities. Ensure you do not miss out on your target’s activities.
David Butler, Product Manager, XCI
09:15-10:00 Session C
Beyond the Search Bar: Automated Social OSINT for Large-Scale Intelligence Ops
Manual OSINT doesn't scale. When dealing with mass data, analysts need tools that think like investigators. Join us for a technical walkthrough on how to automate the collection and analysis of social media traces at scale. We will explore advanced correlation algorithms that identify hidden connections between targets across multiple platforms, transforming chaotic social data into a clean, actionable intelligence feed for command centers and field agents.
Presented by Prelysis11:00-11:40 Session B
Extracting RAM and Breaking the BFU Barrier in Mobile Phones with XRY Pro
Presented by MSAB11:45-12:30 Session A
VASTech Orca: A cutting-edge, modular, end-to-end system for fibre, satellite, and signals intelligence fusion.
Presented by VASTech
*Track 3: Social Network Monitoring, Artificial Intelligence and Analytics Product Training
Sessions in this track are only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees, unless marked otherwise unless marked otherwise.
*Note: Sessions open to all attendees in this track will have (Open to all attendees) above their title.
Tuesday, 1 June 2027
08:30-09:20 Session A
The ultimate AI-driven Intelligence to monitor and extract meaningful information from Social Media and Traditional Media like TV and Radio to improve national security. A live demo.
Presented by IPS
08:30-09:20 Session D
Social Media De-anonymization in Practice: DNI’s Identity Correlation Engine (ICE)
Presented by DNI Solutions08:30-09:20 Session E
The Impact of AI with OSINT
This presentation will explore the emerging impact of artificial intelligence, including generative AI, on opensource intelligence (OSINT) workflows. We will explore the evolution of AI as it relates to OSINT and look at the future for how practitioners can do more with less using Gen AI techniques for tasks such as image analysis, creating your own OSINT tools, geo-spatial processing, and reporting. Analysts are more important than ever, and this talk will highlight the critical requirement for analysts to verify & validate information, whilst creating efficiencies with emerging technologies that will change how they interact with data in the future. Finally, this talk will explore bad actors & the evolution of disinformation in a deep-fake world with voice cloning, video & image generation along with tonally & grammatically accurate text-based replication.
Markus Auer, Vice President Sales, OSINT Combine08:30-09:20 Session F
Harnessing the Network for Criminal Investigations and Intelligence
The session reveals how law enforcement and intelligence agencies can leverage the Vehere AI Monitoring Center to transform network metadata and signals into actionable intelligence
Presented by Vehere09:25-10:15 Session A
WhatsApp, Telegram, Facebook...how IPS helps you to locate most wanted targets with LI
Presented by IPS09:25-10:15 Session B
Real Intelligence powered by AI – Data to Decisions
Presented by Datafusion Sytems
09:25-10:15 Session C
From Monitoring to Protection: How AI-Powered OSINT Changes Law Enforcement Investigations
Manual OSINT and traditional monitoring were built for a slower investigative environment. Today, criminal actors use automation, LLM-powered workflows, leaked credentials, fresh vulnerabilities, and fragmented open-source data to move faster than many law enforcement teams can investigate. By the time an alert becomes a case, suspects may have changed accounts and infrastructure, victims may already be affected, and critical evidence may be harder to preserve.
This session shows how monitoring and investigations can evolve from separate, reactive stages into one continuous operational workflow. You'll see how law enforcement teams can start from a single lead and move through a unified workflow toward a complete picture of threats—with proactive social media monitoring, deep automated OSINT investigation, and consequential intelligence-led protection.
Dmitry Danilov, CPO, Social Links09:25-10:15 Session E
The Italian Way, Chapter 2: AI-Driven Counter-Terrorism Intelligence. See how it works
Presented by SIO10:35-11:25 Session A
From Digital Chaos to Clarity: Unifying all Evidence Layers for Faster, Smarter Case Resolution
Investigations today generate massive digital evidence —from devices, forensics, social media, financials, and OSINT.
PLX, a comprehensive evidence analysis platform, brings all investigation layers together in a single, intuitive view so teams can move fast and stay focused.
With real-time integrations, support for 1,000+ formats, and advanced visualizations, PLX helps surface hidden connections, patterns, and leads.
Powered by CoAnalyst GenAI assistant for judiciary data, natural language search accelerates the path to impactful insights.
From complexity to clarity, the mission outcome you need is now just a few clicks away.
Presented by Penlink10:35-11:25 Session C
(Open to all attendees)
The AI Propaganda War: Iran’s Digital Battlefield
Cyabra investigated tens of thousands of fake accounts to uncover how Iran leveraged generative AI to push manipulated war footage to over 145 million viewers during the 2026 conflict. This data-driven session breaks down the anatomy of that cognitive warfare campaign, equipping attendees with actionable strategies to detect coordinated bot behavior, understand deepfake distribution, and neutralize today’s most sophisticated disinformation networks.
Presented by Cyabra
11:30-12:20 Session B
Analyst Training: Foundations for Investigator Excellence
Real world training for professionals to acquire theoretical framework, practical skills and core competencies.
Jared, RAKIA Group11:30-12:20 Session C
The Untapped Domain: Turning User-Generated Video – Seized, Shared, and Collected into a Single AI-Driven Intelligence Workflow
Stop watching videos. Start extracting intelligence.
The challenge isn’t lack of data - it’s time wasted reviewing it while critical signals remain your blind spot; this session demonstrates how agentic AI fuses video across sources to detect emerging threats earlier.
Presented by Airis Labs
11:30-12:20 Session D
Beyond Collection: Rethinking Investigative Tradecraft with Agentic AICollection used to be the hard part. It isn't anymore. Practitioners and analysts today are overwhelmed by fragmented signals, massive volumes of open-source data, and threats evolving at machine speed. The challenge is no longer finding information. It is correlating signals, assessing credibility, and producing conclusions that hold up under operational, legal, and oversight scrutiny.At the same time, many investigative workflows remain heavily manual and optimized for gathering more data rather than improving analytical outcomes.In this session, we examine how investigative tradecraft is evolving in the era of agentic AI and what separates modern investigative operations from outdated workflows. Drawing on real-world investigations in national security and critical-sector environments, the discussion explores four key areas shaping the future of investigations:
Data access and correlation across fragmented sources Agentic AI workflows that accelerate collection, triage, and analysis Transparency and governance for explainable, defensible investigations Investigative tradecraft designed to augment, not replace, human judgmentUsing practical investigative scenarios and operational examples, the session provides a framework for understanding where agentic AI can meaningfully improve investigative speed and effectiveness, where human expertise remains essential, and how organizations can modernize investigations without sacrificing trust, accountability, or rigor.
Pat Butler, Executive Vice President, Strategic Engagement, Babel Street14:15-14:40 Session B
Automatic Exploitation of Social Network, Deep and Dark Web to complement traditional Lawful Interception Infrastructure for Target Profiling.
Presented by IPS14:15-15:05 Session C
Shadow Tracking: Unmasking High-Value Targets Through Social Media Intelligence
Stop chasing ghosts. In an era of fragmented digital identities, social media remains the primary leak for operational security (OPSEC) failures. This session demonstrates how our OSINT tool pivots from a single handle or post to map an entire criminal ecosystem. We will showcase real-time identification of threat actors, link analysis between disparate profiles, and how to turn "noise" into a structured intelligence landscape for immediate tactical advantage.
Presented by Prelysis14:15-15:05 Session E
Standing Up an Election-Integrity Operations Centre in 90 Days: Deepfake Detection, Coordinated-Inauthentic-Behaviour Mapping, and Court-Admissible Handoff to the Election Commission
European democracies are entering a 24-month window of contested elections under industrial-scale information operations. Most election-integrity tooling either stops at analysis - you see the disinformation but cannot act on it - or stops at takedown, where the platforms react but the evidence chain dies. This session walks through the 90-day stand-up of a sovereign election-integrity operations centre: deepfake and synthetic-media detection on candidate impersonation, coordinated-inauthentic-behaviour mapping across Telegram, TikTok, X, and domestic platforms, narrative-escalation tracking, and court-admissible handoff with full chain of custody to the election commission and the prosecutor's office. Worked example anchored on publicly-known 2024-2026 EU interference patterns. Sovereign-deployed, OSINT-led, lawful by design.
Presented by Blackscore14:40-15:05 Session B
Sentinel AI – from Chaos to early Strategic Decision. Transforming vast, multi-domain media streams into real-time, actionable intelligence, empowering decision-makers to detect, understand, and respond to critical events before others do.
Presented by IPS
15:25-16:05 Session A
Telegram AI based content monitoring and Analysis
How to extract intelligence from millions of chaotic, unstructured inputs, in real time.
Presented by Wave Guard Technologies15:25-16:05 Session B
Unveiling the invisible: SIO advanced intelligence in action
Presented by SIO16:10-17:00 Session A
(Open to all attendees)
See what others miss: multi-domain visualization for actionable intelligence
Jan Girman, Product Manager, Cambridge Intelligence
Wednesday, 2 June 2027
9:10-9:35 Session A
Beyond Social Media: The New Era of Wide OSINT
This session explores how to avoid the trap of relying on a single intelligence discipline, and how to shift from relying solely on SIGINT to leveraging multi-source intelligence. OSINT is back! And it can provide insights and answers far beyond social media.
Omer Frenkel, Director of Intelligence Solutions, Cognyte9:35-10:00 Session B
Countering Hybrid Cognitive Warfare Campaigns with OSINT, SIGINT and AI-Driven Intelligence
This session presents a practical approach for the detection and countering of cognitive warfare in an era of hybrid conflict, which involve both online influence as well as physical violence and sabotage operations.
Such campaigns spread weak signals across social networks, financial transactions, communication channels, and physical domains. By combining OSINT, SIGINT and additional data sources into an AI-driven decision intelligence framework, agencies can identify patterns of hostile activity, the agents that conduct them, and the channels by which they are orchestrated and funded.
Gilad Ben-Ziv, VP Business Evangelist, Cognyte9:10-10:00 Session B
Introducing CoAnalyst-360: Multi-Agent Investigative Platform
This session unveils CoAnalyst-360, a multi-agent intelligence platform that redefines how investigative workflows are executed end to end.
Built on orchestrated AI agents, CoAnalyst 360 autonomously interprets investigative goals, performs reasoning, and generates insights across OSINT, digital evidence, and forensic data.
It enables analysts to define objectives in natural language, with the platform translating intent and executing complete workflows into a full investigation with structured, traceable, and explainable reports.
Attendees will explore how this agent-driven platform adapts to real-world missions and transforms digital intelligence operations at scale.
Presented by Penlink9:10-10:00 Session C
AI Redefining Data Analytics for Law Enforcement
Presented by Rayzone Group9:10-10:00 Session D
GEO Intelligence for Modern Law Enforcement
Integrating Multi-Source Intelligence on a Single Operational Map
Lorenzo Giombini, RAKIA Group13:00-13:40 Session A
Deanonymizing people, accounts & crypto wallets: OSINT/SIGINT practice
Maxim Avdyunin, 7Generation13:00-13:40 Session B
Who Understands the Algorithms Will Control the Future
This presentation explores how algorithms, AI systems, and automated decision engines are no longer just tools, but active forces shaping perception, behavior, and strategic outcomes. As human and machine decision-making become increasingly intertwined, power shifts from those who control infrastructure to those who understand how influence, narratives, and optimization models drive real-world actions. The session will examine how this impacts cybersecurity, intelligence, business, and national security, and why the next competitive advantage will come from mastering human–algorithm dynamics, not just technical defense.
Presented by Penlink13:45-14:30 Session B
Target De-Anonymization: Leveraging Social OSINT to Disrupt Criminal Networks
Intelligence is useless if it doesn't lead to disruption. This LEA-focused session deep dives into the transition from digital monitoring to physical intervention. Learn how to bypass common obfuscation techniques used by organized crime on social platforms. We will demonstrate through a simulated case study how social media OSINT provides the "missing link" in encrypted communication investigations, allowing agencies to identify, locate, and neutralize threats before they escalate.
Presented by Prelysis13:45-14:30 Session C
VIDINT at Scale: Operational Intelligence Across Citizen Video, Live Streams and Authorised Sensors
Modern security operations generate more video than any analyst team can process - spanning agency-authorised CCTV networks, drone feeds, body cameras, social media platforms, and open-source streams across multiple languages and geographies. The intelligence is in there, but only if the platform can ingest at scale, unify across sources, and surface what matters before the window closes. This session walks through a live VIDINT pipeline: continuous multi-source ingestion fusing agency-authorised infrastructure with open-source video, automatic speech-to-text across 50+ languages, biometric and visual matching against authorised reference data, geolocation including indoor environments where GPS is unavailable, and real-time detection of persons, objects, vehicles and threat indicators across the full archive - all queryable in plain natural language, no coding required. From a multi-source result set the analyst pivots into a single unified timeline that connects faces, locations, associates and movement patterns across investigative windows. The result is a new layer of situational awareness that scales with the volume of video your investigators already cannot keep up with. Demonstrated live on a synthetic case anchored on publicly-reported threat patterns.
Presented by Blackscore15:00-15:40
AI in OSINT Investigations: From Hype to Control
AI is transforming OSINT - but for law enforcement and national security, speed without control is a risk. In scenarios like monitoring the online information space around elections, how do we apply AI to noisy, unstructured, and potentially deceptive data? We will show a practical EU-grounded approach through real Use Cases.
Mathijs Homminga, CTO, Web-IQ
15:45-16:25 Session A
From Data Overload to Intelligence Advantage: How AI is Reshaping OSINT Exploitation
Presented by CHAPSVISION
16:30-17:15 Session A
Leveraging OSINT 0-days to investigate a person of interest
When most people think of OSINT, they often associate it with basic Google searches or web scraping. However, OSINT is much more than that, it involves a diverse set of techniques that go far beyond surface-level information gathering.
One powerful but often overlooked method is reverse engineering. In this talk, we will explore how reverse engineering, alongside other advanced OSINT techniques, can be leveraged to uncover hidden information and identify criminal activities.
Sylvain HAJRI, Epieos
Thursday, 3 June 2027
09:15-10:00 Session A
Hunting with OSINT: Identify, Investigate, Monitor and Analyze
Join renowned OSINT expert and investigator Nico Dekens as he walks through a real-world OSINT investigation — from zero to insight. You'll see how to start with a single digital breadcrumb and follow it through to a detailed understanding of your target.
Presented by ShadowDragon
11:00-11:40 Session A
OSINT & Media Monitoring with Intelion
In this session we will show how Intelion can be used to monitor the international public OSINT news space (broadcast and Internet), find specific keywords as well as the current sentiment regarding certain news topics. We will also show its alarm, summary, report and automated workflow functionalities.
Presented by ISID11:00-11:40 Session C
The Intelligence Mosaic in the AI Era:
How OSINT, Data Fusion, and AI Agents Enable Real-Time Intelligence for Decision Makers
Presented by RAKIA11:45-12:30 Session D
OSINT Investigations with AI
Presented by Sahar
13:00-13:40 Session A
From Where’s Waldo to Who’s Waldo: Completing the Identity Picture with Biographic IntelligenceBiometrics have transformed how we locate and verify individuals – from facial recognition at the border to fingerprints in law enforcement. But knowing where someone is or that they were there isn’t always enough. What if you also need to know who they are across aliases, affiliations, and history?This session explores how biographic data – names, networks, behavior, and patterns – complements biometric methods to create a fuller, more actionable picture of identity. Using the playful theme of “From Where’s Waldo to Who’s Waldo,” Babel Street will walk through how advanced biographic intelligence strengthens identity resolution across languages, data silos, and time.In different countries, Waldo from the "Where's Waldo?" books is known by various names. In the UK, he's called Wally, while in France, he's Charlie. Germany knows him as Walter, and in Sweden, he's Hugo. Other names include Holger in Denmark, Vallu in Finland, and Ubaldo in Italy. In the US and Canada, he's known as Waldo.Follow this international man of mystery and intrigue as we walk through the value proposition of biographic intelligence at the borders.Key Takeaways:• Discover how biographics enrich biometric data with context, history, and connections• Learn how modern systems connect fragmented identity trails across structured and unstructured data• See real-world examples where biographic intelligence closes risk gaps in onboarding, threat detection, and complianceThis session is for anyone focused on identity, risk, or mission success – and how to move from surface-level identification to deep understanding that moves at the speed of threat.
Presented by Babel Street13:00-13:40 Session D
Reveal the suspect behind the data
Presented by Elephantastic
Track 4: Threat Intelligence Gathering and Cyber Security Product Training
This track is only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees
Tuesday, 1 June 2027
11:30-12:20
Tracking and Unmasking Cybercriminals Active on Hidden Channels
Sunhyung Shim, S2W13:20-14:10 Session B
Ransomware, C2, and Botnet Activity Hiding in Network Traffic: A Portable, Passive Assessment You Can Run Anywhere
Presented by ClearTrail14:15-15:05 Session A
Cognitive Attack Analytics: Turning OSINT & AI into Actionable Threat Intelligence
Presented by FutureSpace15:25-16:05 Session B
Mobile Threats That Don’t Look Like Attacks
Not all mobile security risks involve malware, or visible attacks. In many real-world operations, the most significant risks come from normal, everyday behavior—such as switching networks, using different communication methods, or making quick user decisions in the field.
This session explains where these hidden risks come from, why they are difficult to detect, and how organizations can better address them by focusing on user behavior and real operational scenarios instead of traditional attack detection.
Presented by BittiumWednesday, 2 June 2027
13:00-13:40
The Era of Exponential Risk Decoding Hybrid Warfare
Dominik Kampmann & Simon Puxley, Moody's15:00-15:40
Feeding the AI: Why Contextual Network Intelligence Is Critical for Modern Cyber Threat Hunting
As encryption limits traditional payload inspection, modern threat hunting increasingly depends on rich, protocol-aware network metadata that reveals behavior, infrastructure, and intent. This session explores how contextual signals such as DNS activity, JA4 fingerprints, application identity, routing intelligence, and session behavior can be transformed into AI-ready datasets for detecting botnets, command-and-control, exfiltration, and coordinated malicious activity at scale.
Presented by NetQuest15:45-16:25 Session A
Leverage DPI-Based Traffic Visibility for Cyber Defense at 100Gbps and Connected Drone Defense
Discover a new generation of DPI-based cyber and IDS/File extraction sensors that leverage years of experience in network visibility and cyber defense environments to raise the performance of government-run Security Operations Centers (SOCs). Find out how ENEA technology can also be used for Connected Drone Defense.
Osvaldo Aldao, Chief Technology Officer, Enea Software
Nicolas Duteil, Pre-Sales Team Leader, DPI & Traffic Intelligence, Enea Software15:45-16:25 Session B
Making Threat Infrastructure Visible: The Power of NetFlow and CTI Fusion
Threat actors rely on dynamic infrastructures to evade detection, and scale cyber operations. But when internet telemetry and cyber threat intelligence are fused together, that infrastructure becomes much harder to conceal.In this session, KELA will demonstrate how combining internet NetFlow data with proprietary cybercrime intelligence enables analysts to move beyond isolated indicators and expose the broader infrastructure behind malicious activity. The session will show how defenders can uncover C2 servers, management consoles, proxies, VPNs, botnets, jump servers, infrastructure chains, and potential victims - turning fragmented signals into a complete investigative picture. Attendees will learn how intelligence fusion can accelerate investigations, support attribution, and help security teams and law enforcement move from reactive IOC analysis to proactive disruption of threat actor operations.
Ron Breger, KELA16:30-17:15 Session A
Detect, Connect, Act: Intelligence for the Digital Threat Environment
Presented by GerulataThursday, 3 June 2027
9:15-10:00
Introducing LADOS: The Low Altitude Defense Operating System
Presented by Sentrycs
Track 5: Investigating DarkWeb, Bitcoin, Altcoin and Blockchain Transaction
This track is for law enforcement and private enterprise investigators who have to monitor and investigate the DarkNet along with Bitcoin transactions associated with criminal activities
This track is only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, 1 June 2027
9:25-10:15
Lifting the Lid on Tor: Evolving Techniques for Dark Web Investigation and Evidence Collection
As the Tor dark web remains central to criminal operations, investigators must continually adapt their methods. This talk examines recent advancements in defeating Tor operators, collecting evidence, and disrupting illicit activity. Drawing on real-world techniques and evolving tradecraft, it provides practical insight into how law enforcement can improve visibility and investigation across Tor.
Gareth Owenson, CTO, Searchlight Cyber10:35-11:25
Beyond Breaches: Leveraging Compromised Credentials in OSINT and DarkINT Investigations
This session explores how breached records and other datasets with compromised PII gathered from the Deep and Dark Web can significantly enhance corporate and law enforcement investigations. We will begin by exploring the various types of breached datasets from hacked databases and combolists to stealer logs and scrapes. We will then provide insights into where these datasets can be located and highlight the critical information that can be extracted from them. Finally, we will demonstrate the practical application of compromised records in a live investigation in which we track down one of the FBI’s Ten Most Wanted individuals.
Matteo Tomasini, Founder & CTO at District 4 Labs13:20-14:10 Session A
Live Demonstration of DarkOwl Vision: Darknet Intelligence Discovery and Collection
Lindsay Whyte, Regional Director, DarkOwl, LLCWednesday, 2 June 2027
13:45-14:30
From Intelligence to Attribution: Navigating Dark Web Investigations
Law Enforcement Agencies (LEA) demonstrated remarkable agility in adapting to the rise of digital forensics. However, progress has significantly slowed since the advent of the "Cyber Tsunami." This slowdown is rooted in the overwhelming challenge of translating powerful intelligence gathered in the digital domain into the actual, legally admissible attribution required for successful prosecution. Criminals have aggressively migrated to a plethora of encrypted platforms, including Telegram, Tox, Session, and Tor, and rely heavily on criminal infrastructure and a large volume of forums, creating an unprecedented barrier to attribution.
Have we reached an operational plateau? This session explores the critical juncture facing modern LEA. It argues that niche and novel capabilities are now the only means to achieve that final push for attribution. We will discuss the new and often complex problems these advanced capabilities introduce, particularly concerning the evidential pathway. Crucially, we will address the resulting question for agencies without these capabilities: what is left for obtaining attribution when conventional methods fall short?
Danny Bates, LEA Fellow and Strategic Advisor, Searchlight Cyber
Thursday, 3 June 2027
08:30-09:10
Cutting Through the Noise: Hybrid Data Fusion for Faster, Smarter Investigations
The session will explore how hybrid data fusion can help investigators work more effectively with fragmented and high-volume data. By combining structured and unstructured sources in a single AI-assisted analytical environment, investigators can uncover hidden connections, reduce information overload, and generate actionable intelligence faster.
Miroslav Nečas, TOVEK
Track 6: Mobile Signal Intercept Product Training and Presentations
This track is for Law Enforcement, Interior Security and the Government Intelligence Community who must work with cellular and mobile satellite operators regarding mobile location, electronic surveillance and RF intercept.
This track is only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, 1 June 2027
8:30-9:20 Seminar Session
Understanding Mobile 2G, 3G, 4G and 5G NSA Infrastructure, Intercept and Cryptography
Dr. Jerry Lucas, President, TeleStrategies10:35-11:25
Next-generation Hybrid cellular locator
Presented by Septier
11:30-12:30 Session A
From Sensors to Knowledge: Fusing tactical and strategic assets for superior satellite communications intelligence
Presented by Rohde & Schwarz11:30-12:20 Session B
Measurement instruments for Wi-Fi, Bluetooth – SmartTags, and Cellular
Presented by S.E.A. Science & Engineering Applications Datentechnik GmbH11:30 - 12:20 Session C
Mission First: Intelligence That Delivers in Any Operational Scenario
Schlomo Schwartz, Cognyte13:20-14:10 Session A
One Tactical Solution. Total Cyber Intelligence.
RCS presents The Swiss Army Knife of Cyber Intelligence: the all-in-one platform built to perform across the most demanding operational environments.
Presented by RCS15:25-16:05
Measurement instruments for Wi-Fi, Bluetooth – SmartTags, and Cellular
Presented by S.E.A. Science & Engineering Applications Datentechnik GmbH
Wednesday, 2 June 2027
15:00-15:40
Operational Intelligence: From Insights to Tactical Action
Robet van Bosbeek, Dep. GM, Europe and Africa, CognyteThursday, 3 June 2027
8:30-9:10 Session A
Smartphone-Only Edge AI Solutions for Surveillance and Tactical Operations
Presented by Coverty11:00-11:40
Forensic Location Intelligence
Turning WiFi, Bluetooth, and 5G signals into movement timelines, patterns, and investigative leads
Presented by Combain
Track 7: Electronic Surveillance Training and Product Presentations
This track is for law enforcement investigators and the government intelligence community who are responsible for deploying video, audio and GPS surveillance products and only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Wednesday, 2 June 2027
13:00-13:40 Session A
Crime-as-a-Service: The Evolution of Crime and How Data with AI Can Spot Them
Presented by SIO and Blu5 Labs15:00-15:40 Session A
Covert Drilling
Covert drilling is a deployment methodology for installing miniature surveillance equipment through solid building materials without access to the target side whilst generating a minimum of noise.
Because sometimes the target is not connected and takes all the right measures to prevent access to his house or premises.
Our complete solution enables you to install Audio and Video surveillance equipment through any building material.
With our equipment you can install video surveillance from 0,25mm for full frame video.
Presented by Caminos15:45-16:25 Session A
Beyond Traditional Interception: Solving Encrypted Communication challenges with Integrated Cyber Intelligence
Presented by AREA15:45-16:25 Session B
Innovative Audio Surveillance for Moving Targets in Large Areas
Presented by CommeshThursday, 3 June 2027
9:15-10:00
Redefining Intelligence Production from VISINT for modern operations
As threats evolve and environments grow more complex, visual intelligence must adapt. This session explores how advanced visual sources, AI-driven analysis, and remote operational capabilities are reshaping how agencies generate timely and actionable intelligence.
Presented by Interionet11:00-11:40
Innovative technologies for covert access to vehicles for Law Enforcement and Service applications
Presented by AG Group 007
Track 8: 5G Lawful Interception Product Training
This track is only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, 1 June 2027
9:25-10:15
Understanding 5G/5GA/6G LI for Investigators
Matthew Lucas (Ph.D, Computer Science), VP, TeleStrategies
13:20-14:10
Portable 5G Intelligence for Every Mission Environment
A session on how evolving mission demands are redefining portable operations—and what a modern, low‑SWaP system must deliver in terms of capability, flexibility, and scalability.
Presented by Octasic14:15-15;00
Portable 5G Intelligence for Every Mission Environment
A session on how evolving mission demands are redefining portable operations—and what a modern, low‑SWaP system must deliver in terms of capability, flexibility, and scalability.
Presented by Octasic15:25-16:05
Building a tech ecosystem for digital investigation
Presented by Group 2000 x Forensic Analytics16:10-17:00
Full spectrum intelligence: from lawful intercept to OSINT
Presented by Rohde & Schwarz
Wednesday, 2 June 2027
09:10-10:00 Session B
Survival of IMSI-catchers in 5G Networks
With transition to 5G Mobile Networks, 3GPP has introduced advanced security mechanisms that significantly increase resistance against rogue base stations – effectively shutting down conventional IMSI catchers. Nexburg’s 5G ID Associator empowers intelligence services, agencies and police to overcome these challenges, enabling the continued and effective use of IMSI-catcher capabilities in 5G and future mobile networks. The solution is fully aligned with 3GPP standards and delivers advanced functionality through modular options, allowing adaptation to country-specific requirements while maintaining maximum integration flexibility.
Presented by Nexburg13:00-13:40 Session A
Satellite communications – the emerging threat to lawful interception
As satellite services transition from highly specialised systems to commodity scale consumer platforms, they introduce new operational, technical, and legal challenges for law enforcement and intercept authorities. This session will provide a structured overview of those challenges and outline how standards bodies and industry are responding.
Chris Young, Product Manager, BAE Systems Digital Intelligence13:00-13:40 Session B
Seamless Monitoring of Inbound Roaming Voice
Mobile operators are adopting modern roaming architectures, based on S8HR and N9HR (5G-SA), to simplify deployment and accelerate time-to-market. However, in consequence intercepting IMS voice calls (VoLTE/VoNR) from visitors in your country can present technical challenges. Nexburg tackles these challenges with a comprehensive lawful interception solution of mobile roamers, fully compatible with both S8HR and N9HR deployments. This ensures mobile operators maintain full regulatory compliance while enjoying operational flexibility in today’s roaming environments.
Presented by Nexburg15:45-16:25
Command the Spectrum at the Tactical Edge with Modular Airborne payload
For RF missions on the tactical edge, this session will address how modular payloads and AI‑accelerated sensing reduce time‑to‑mission while enabling rapid re‑role across airborne and tactical platforms
Presented by Octasic16:30-17:15
Optimized Cell Site Simulation in today's and tomorrow's cellular networks
All-in-one identity catching and DF solution by EXFO, meeting the needs for 2G/3G/4G/5G and LTE-M.
Taisto Niiranen, Senior Product Line Manager, EXFO Homeland SecurityThursday, 3 June 2027
11:00-11:40
Adapt and Advance: Enabling IMSI Catchers and Direction-Finding in 5G Standalone Networks
The 5G SA architecture encrypts identifiers, making traditional over-the-air surveillance techniques ineffective without adaptation. This session explains what is required to make IMSI catchers and direction finders work in this new environment. We also introduce architectural options for multi-CSP and multi-LEA support to enhance interoperability and future-readiness.
Presented by Group 2000
Training Seminars Led by Law Enforcment Officers and Ph.D Computer Scientists
Tuesday, 1 June 2027
Seminar #1
08:30-15:05Online Social Media and Internet Investigations
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police08:30-09:15
Proxies and VPNs: Identity Concealment and Location Obfuscation
09:30-10:15
Tor, onion routers, Deepnet, and Darknet: An Investigator's Perspective
10:30-11:15
Tor, onion routers, Deepnet, and Darknet: A Deep Dive for Criminal Investigators
11:30-12:15
Cellular Handset Geolocation: Investigative Opportunities and Personal Security Risks
13:15-14:00
Ultra-Wideband Geolocation and Cyber OSINT
14:15-15:00
Collecting Evidence from Online Social Media: Building a Cyber-OSINT ToolboxSeminar #2
08:30-09:20Understanding Mobile 2G, 3G, 4G, 5G and 6G Infrastructure and Law Intercept for Technical Investigators
Presented by: Dr. Jerry Lucas, President, TeleStrategiesThis session addresses the infrastructure evolution of 2G to 3G to 4G to 5G NSA and the impact on lawful interception. Specifically;
Network Architecture Evolution from 2G to 3G, 3G to 4G, 4G to 5G regarding radio technology (TDMA, CDMA, OFDM and MIMO), network core from CSFB to VoLTE and SS7 to Diameter.
Encryption, Target Identification and Location: SIM and eSIM cards, IMSI and Target ID, encryption algorithms (A3, A5, A8 and Ki) and basically how user authentication and traffic encryption is accomplished.
Target Location Tracking with CDR analysis, MAC address farming, MITM attacks, SS7 access, IMSI catchers and IT intrusion.
4G to 5G Transition Specifics Understanding 5G Non Stand Alone (NSA) vs. SA 5G, the IMSI catcher issue (myth vs. realities), 5G Cryptography (ECC, SUPI, SUCI), 5G target location enhancement and LTE/NR Internetworking and Co-existance.
5G Spectrum What can 5G deliver with mid vs. high frequency spectrum and what new spectrum bands are soon to be auctioned off
SA 5G Infrastructure Features: NFV, SDN, Edge/Cloud Computing and Network Slicing
Seminar #3
09:25-10:15Understanding 5G/5GA/6G LI for Investigators
Matthew Lucas (Ph.D, Computer Science), VP, TeleStrategiesThis session addresses the challenges facing law enforcement and ISS vendors responsible for intercept on 5G networks.
Seminar #4
10:35-11:25AI Technology Basics and LEA Use Cases
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesThis session gives LEA, intelligence and other practitioners a primer on AI technologies. Topics covered include how AI technology is being leveraged in our industry (e.g., image recognition, classifying unstructured data, natural language processing, document summarization, and more); traditional AI approaches (heuristics, indicators); basics of machine-learning systems (models, training, neural-networking); generative AI systems (OpenAI, Anthropic, Grok, others); the strengths and weaknesses of each AI model; and how the LEA/IA/ISS vendor communities are leveraging AI to increase the efficiency and accuracy of their network data, OSINT, location, image and natural language operations/applications.
Seminar #5
11:30-12:20Generative AI Use-cases and Capabilities for Law Enforcement and Intelligence Agencies
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesGenerative AI (GAI) is revolutionizing network data and OSINT analytics – with the end-goal of enabling investigators to effortlessly engage, analyze, visualize large datasets and “connect the dots” that would traditionally require enormous manual effort from teams of analysts and IT personnel. This session will cover the key issues related to GAI platforms: how they are/can be used; what models are available; who are the key players; how to integrate GAI systems with your datasets (RAG); dealing with accuracy and hallucinations; data embeddings and citations; integration standards; data orchestration and more
Seminar #6
13:20-14:10Agentic AI - Deployment Options and Approaches
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesThis session will cover Agentic-based AI platforms, the technology and challenges facing LEAs/IAs looking to incorporate Agentic AI platforms in their operations. Topics covered include hosting platform options; small/local model options; operational costs; implementation requirements; security; regulatory considerations; aligning and fine-tuning models; optimizing agentic AI platforms for ISS workflows; and ongoing development advances to watch.
Thursday, 3 June 2027
Seminar #7
8:30-9:15Unmasking Hidden Evidence: Metadata & EXIF for Digital Investigators
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #8
10:15-11:00Push Tokens in Criminal Investigations: Tracing Digital Footprints & Uncovering Evidence
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #9
11:30-12:15Understanding the Implications of Online Social Media for OSINT During Critical Incidents
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police