2026-09-10 –, Großer Saal
Every Windows release quietly introduces new places where the operating system writes things down, and Windows 11 is no exception. While most DFIR playbooks still lean on the same artifacts we've relied on for a decade, the modern Windows stack has been busy generating evidence in places few investigators routinely check. Timelines end up with gaps that didn't need to be there, and execution evidence sits untouched on disk.
Drawing on recurring patterns across hundreds of Windows 11 investigations, this talk maps the evidence surface that standard triage misses. We'll spend time with Recall and the near-continuous record it keeps of user activity on Copilot+ devices, follow the SMS and call history that Phone Link pulls from paired Android phones onto the Windows host, and read through Copilot conversations where user intent is often spelled out in plain English. From there we'll move into the secondary telemetry channels that keep writing long after Event Logs are cleared.
For each artifact, we'll cover where it lives, what it records, how long it persists, and the common misreadings that lead investigators astray. Attendees will leave with a mental model for where Windows 11 records user activity outside the classic artifact set, a working understanding of how to parse each source, and a feel for the interpretation pitfalls that matter most at triage time.
With over 10 years of experience in cybersecurity, Maurice Fielenbach started on the offensive side before moving into defensive security. He has worked hundreds of cyber investigations, including major ransomware and APT cases across industries affecting millions of people. Among them was one of the largest ransomware incidents in German history, targeting a communal IT service provider and disrupting public infrastructure at scale.
Today he focuses primarily on threat intelligence and malware analysis. He is the founder of Hexastrike Cybersecurity, where he trains blue teams in digital forensics, malware analysis, and threat hunting through hands-on, scenario-driven sessions built from real incidents.
His research is regularly featured in leading cybersecurity publications and cited by industry peers. He speaks at security conferences and contributes open-source tooling and detection content used by security teams worldwide.
