Experts review DFIR challenges and solutions from Locked Shields 2026

From 2–4 June, the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) hosted the annual Locked Shields Forensic Workshop, where experts reviewed the Digital Forensics and Incident Response (DFIR) track challenges from Locked Shields 2026 and presented the methods used to solve them.

Held shortly after Locked Shields, the world’s largest live-fire cyber defence exercise, the event brought together forensic challenge developers from partner companies and CCDCOE, giving participants a rare behind-the-scenes view of one of the exercise’s most technically demanding tracks.

As part of the post-exercise knowledge-sharing cycle, the workshop provided expert-led walkthroughs of the scenarios, analytical techniques, and investigative reasoning behind the correct findings.

This year’s workshop placed particular emphasis on the breadth of the Locked Shields 2026 storyline, which spanned compromised personal devices, corporate networks, cloud environments, operational technology, and critical national infrastructure. Each challenge family was presented by its developers, with technical deep-dives covering acquisition methodology, artifact interpretation, attribution reasoning, and reporting.

Contributing Partners
The DFIR track of Locked Shields 2026 was made possible through the collective effort of academic and industry partners, each of whom presented their contributions during the workshop:

  • University of Krakow – Delivered the mobile forensics challenge, bringing strong academic expertise to one of the most demanding evidence domains of the track.
  • CyberDefenders – Delivered a series of DFIR challenges aligned with the Locked Shields 2026 storyline, covering host- and network-based investigation scenarios.
  • Hack The Box – Contributed a series of scenario-driven DFIR challenges, supported by platform-side expertise in exercise content delivery.
  • Hex-Rays – Delivered two storylines focused on malware analysis and reverse engineering, providing a critical technical uplift for the RE component of the track.
  • ICS Range – Delivered two storylines centred on Industrial Control Systems and Operational Technology forensics, expanding the OT dimension of the exercise.
  • National University of Singapore (NUS) and National Cybersecurity R&D Laboratories (NCL), Singapore – Longstanding partners of CCDCOE, contributed a storyline based on an airport runway lighting system, introducing a new critical-infrastructure domain to the forensic track.
  • retooling – Developed the Live Forensics challenge, bringing a real-life acquisition scenario to the DFIR track, and additionally delivered a dedicated workshop component.
  • Security Blue Team Labs – Delivered a series of DFIR challenges aligned with the Locked Shields 2026 storyline, contributing significantly to the depth and breadth of the track.

Together, these partners played a defining role in raising the technical complexity of the DFIR track and ensured that participants were tested across a wide spectrum of forensic disciplines.

The Forensic Workshop closed with reflections on the lessons learned during Locked Shields 2026 and on directions for future iterations. As cyber threats continue to evolve in sophistication and scope, the workshop reaffirmed the importance of community-driven content development and shared expertise in building exercises that prepare defenders for real-world incidents.

CCDCOE extends its gratitude to all contributing partners, whose dedication, expertise, and time made both the DFIR track and the Forensic Workshop possible.

Locked Shields has been organised annually by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) since 2010. The realism and effectiveness of the exercise rely on close collaboration with academia and industry partners, whose contributions are essential to its design and execution.