Modern cyber incidents increasingly occur across interconnected ecosystems spanning cloud platforms, telecommunications networks, edge systems, IoT/IIoT devices, and operational technology. Traditional host-centric forensic methodologies are insufficient for reconstructing adversary activity in these distributed, identity-driven environments. CIFM is an investigative framework for reconstructing adversary activity across converged infrastructure ecosystems using identity-centric analysis, distributed telemetry, and human-validated reasoning.

| Format: |
|
| Topics: | |
| Published: | April 4, 2026 |
| License: | Creative Commons |
| Copyright: | © 2026 Kerry Hazelton ("Professor Kilroy"). This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0). |