
ISS World North America is the world's largest gathering of North American Law Enforcement, Homeland Security, Defense, Public Safety and other members of the Government Intelligence Community as well as Telecom Operators responsible for cyber threat intelligence gathering, DarkNet monitoring, lawful interception, and cybercrime investigations.
ISS World Programs present the methodologies and tools for Law Enforcement, Public Safety and Government Intelligence Communities in the fight against drug trafficking, cyber money laundering, human trafficking, terrorism, and other criminal activities conducted over today's Telecommunications networks, the Internet, and Social Networks.
Track 1: Training Sessions Presented by Sworn Law Enforcement Officers and Ph.D Computer Scientists
Track 2: Lawful Interception, Digital Forensics and Mobile Signal Intercept Training Sessions
Track 3: Social Media, DarkNet and Cyber Security Monitoring Training Sessions
ISS World North America Exhibit Hours:
Tuesday, November 17, 2026: 11:00 AM-6:00 PM
Wednesday, November 18, 2026: 10:00 AM - 1:30 PM
ISS World North America 2026 Agenda at a Glance
Welcoming Remarks and Top Ten Challenges
Tuesday, November 17, 2026
8:45-9:00 AM Welcoming Remarks
Tatiana Lucas, ISS World Program Director, TeleStrategies9:00-9:30 AM Top Ten Challenges Facing Law Enforcement and the Government Intelligence Community and Who at ISS World North America has Solutions
Dr. Jerry Lucas, President, TeleStrategies
Track 1: Training Sessions Presented by Sworn Law
Enforcement Officers and Ph.D Computer ScientistsNote: Sessions in this track are only open to all attendees unless marked otherwise
Tuesday, November 17, 2026
9:35-10:20 AM Session A
Proxies and VPNs: Identity Concealment and Location Obfuscation
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
9:35-10:20 AM Session B
Understanding 5G/5GA/6G LI for Investigators
Matthew Lucas (Ph.D, Computer Science), VP, TeleStrategies
10:25-11:10 AM Session A
Tor, onion routers, Deepnet, and Darknet: An Investigator's Perspective
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
10:25-11:10 AM Session B
AI Technology Basics and LEA Use Cases
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategies1:00-1:45 PM Session A
Tor, onion routers, Deepnet, and Darknet: A Deep Dive for Criminal Investigators
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police1:00-1:45 PM Session B
Generative AI Use Cases and Capabilities for Law Enforcement and Intelligence Agencies
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategies
1:50-2:35 PM Session A
Cellular Handset Geolocation: Investigative Opportunities and Personal Security Risks
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police1:50-2:35 PM Session B
Agentic AI - Deployment Options and Approaches
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategies
3:35-4:20 PM Session A
Ultra-Wideband Geolocation and Cyber OSINT
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
4:25-5:00 PM Session A
Collecting Evidence from Online Social Media: Building a Cyber-OSINT Toolbox
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceWednesday, November 18, 2026
Open to LEA/Government Attendees Only
8:30-9:15 AM
Unmasking the Dark Web: Myth vs Reality
Explore what the Dark Web really is and the media myths. Dispel common myths about anonymity and illicit trade, understand the layered internet (Surface, Deep, Dark), and learn why Dark Web familiarity matters for investigators.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Open to LEA/Government Attendees Only
9:20-10:05 AM
Inside TOR: Tracing the Onion
Examine the TOR network’s architecture, access methods, and Tor’s role in obfuscating criminals’ identities. Learn forensic artifacts generated during TOR usage, how exit nodes behave, and what investigators can observe, log, and preserve legally.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Open to LEA/Government Attendees Only
11:15 AM-12:00 PM
Bitcoin & Beyond: How Digital Money Powers Hidden Markets
Understand how cryptocurrency operates within Dark Web marketplaces—beyond tracing transactions. Learn about payment mechanics, vendor trust systems, wallet practices, and common misconceptions about anonymity.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Open to LEA/Government Attendees Only
1:30-2:15 PM
Fieldcraft in the Shadows: Safely Engaging the Dark Web
Learn secure, covert engagement techniques for accessing the Dark Web, its forums and markets. Topics include persona development, OPSEC protocols, and other best practices.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Open to LEA/Government Attendees Only
2:30-3:15 PM
Web Bugs & Covert Tech: Tracing the Invisible
Dive into investigative technologies including web bugs, tracking pixels, browser fingerprinting, and covert probes. Learn how these tools can be used ethically to reveal suspect behavior, location, and activity across hidden platforms.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Open to LEA/Government Attendees Only
3:30-4:15 PM
Piercing the Veil: Identifying Anonymous Actors
Learn how covert actors slip up on the Dark Web and are uncovered using real-world investigative techniques. See how investigations have exposed hidden actors across encrypted channels and from fragments of digital behavior.
Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police Department
Track 2: Lawful Interception, Digital Forensics and
Mobile Signal Intercept Training SessionsNote: Sessions in this track are only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, November 17, 2026
9:35-10:20 AM
Vulnerability Research Tooling for the Agentic AI Era
Presented by Zealot Labs10:25-11:10 AM
Mission Intelligence: Transforming Investigations with Multi-Agent AI
Today's investigations demand more than faster searches—they require a smarter way to transform overwhelming volumes of digital evidence into actionable intelligence. Join Penlink for a first look at CoAnalyst360, an AI-powered mission intelligence platform that orchestrates specialized AI agents to analyze evidence, uncover hidden connections, automate investigative workflows, and generate continuously evolving intelligence reports. See how investigators and analysts can move from a single investigative question to decision-ready intelligence with greater speed, consistency, and confidence.
Presented by Penlink1:00-1:45 PM
The 5G-Ready Cyber Intelligence Monitoring Centre: Centralizing Lawful Interception, Electronic Surveillance and Investigative Analytics
Use cases and demonstration.
Presented by AREA1:50-2:35 PM
Amplified Intelligence: Merging OSINT with Evidentiary Data for more Efficient Investigations
In today's digital age, solving complex cases requires a multifaceted approach that combines Open-Source Intelligence (OSINT) and evidentiary data. This presentation delves into the critical importance of integrating both these sources to achieve an understanding of cases, making it clear that one cannot stand alone. We explore the value of gathering OSINT, including social media information. Plus, see how that can save your agency time and money in helping you discover what data to move forward with and to obtain through search warrants.
Presented by Penlink3:35-4:20 PM Session A
Time-Critical Digital Forensics: Finding the Evidence That Matters Before It’s Too Late
In today’s investigations and intelligence operations, the challenge is no longer collecting data, it is identifying the evidence that matters before it is too late to act.
Join us to explore how Detego’s patented rapid triage, selective extraction capabilities, intelligent workflow automation and AI-driven analytics enable investigators to identify and act on critical evidence across thousands of devices and apps in record time.
Designed for users of any experience level, Detego’s intuitive platform enables fast, forensically sound investigations with minimal training requirements. The session will also highlight covert investigation capabilities and flexible deployment options including field kits, kiosks, lab environments and digivans, demonstrating how Detego technology can be deployed in the most challenging conditions to deliver fast, forensically sound results.
Presented by Detego3:35-4:20 PM Session B
Beyond Traditional Interception: Solving Encrypted Communication challenges with Integrated Cyber Intelligence
Presented by AREA4:25-5:00 PM Session A
Following the Actor: From a Single Selector to a Cybercrime Ecosystem
What can a single fraud-actor selector reveal? Potentially, an entire criminal enterprise. This presentation follows an actor-centric cybercrime investigation as it expands from one identifying clue into a multidimensional map of aliases, digital identities, victims, infrastructure, financial activity, and interconnected fraud schemes. Rather than examining incidents in isolation, the investigation reveals how criminals acquire and operationalize identities, construct believable personas, exploit institutions across sectors, obscure their true location, and move proceeds through multiple channels. The result is a compelling view of fraud not as a series of disconnected events, but as an organized ecosystem held together by repeatable behaviors and shared operational infrastructure.
Duncan Edwards, Senior Investigator, SpyCloudOpen to All Attendees
4:25-5:00 PM Session B
Forensic Audio in Real Noisy Environments: Enhancement, Speech Extraction and Evidential Limits
Technical workshop and case examples
Presented by AREA
Wednesday, November 18, 2026
8:30-9:15 AM Session A
Revealing Intelligence Hidden Behind Encrypted Apps
Use cases and demonstration
Presented by AREA8:30-9:15 AM Session B
One Shared Number, One Thousand Identities: Investigating Fraud at Scale
Presented by SpyCloud11:15 AM-12:00 PM Session A
Staying Ahead of Privacy and Regulatory Changes With Location Intelligence
Jason Sarfati, Chief Privacy Officer & VP Legal, Venntel11:15 AM-12:00 PM Session B
Amplified Intelligence: Merging OSINT with Evidentiary Data for more Efficient Investigations
In today's digital age, solving complex cases requires a multifaceted approach that combines Open-Source Intelligence (OSINT) and evidentiary data. This presentation delves into the critical importance of integrating both these sources to achieve an understanding of cases, making it clear that one cannot stand alone. We explore the value of gathering OSINT, including social media information. Plus, see how that can save your agency time and money in helping you discover what data to move forward with and to obtain through search warrants.
Presented by Penlink1:30-2:15 PM
Operational AI in Lawful Interception and Forensics: What Works Today, What Must Stay Controlled
Open questions for the near future
Presented by AREA2:30-3:15 PM
One Investigation, Many Sources: Validating CDRs, Live LI, Mobile Forensics and Field Data in a Single AI-Assisted Intelligence Platform
Use cases and demonstration.
Presented by AREA
Track 3: Social Media, DarkNet and Cyber Security
Monitoring Training SessionsNote: Sessions in this track are only open to Law Enforcement, Public Safety and Government Intelligence Community Attendees.
Tuesday, November 17, 2026
9:35-10:20 AM
From Open Source to Actionable Intelligence — Integrating OSINT, AI, and Investigative Workflows
Presented by Carahsoft10:25-11:10 AM
DarkOwl DarkMark - Darknet Marketplaces - Enhancing intelligence for Law Enforcement and National Security Investigations
Presented by DarkOwl1:00-1:45 PM
Following the Digital Breadcrumbs — Disrupting Criminal Networks Across Social, Dark Web, and Crypto
Presented by Carahsoft1:50-2:35 PM
Leveraging OSINT Tools for Cross-Border Narcotics Investigations
Presented by KasewareWednesday, November 18, 2026
9:20-10:05 AM Session A
From Tip to Takedown: Unifying OSINT, Case Management, and Multi-Agency Data Sharing in One Investigative Platform
Presented by AREA
9:20-10:05 AM Session B
Early Warning in the Digital Domain — Identifying Threats Before They Become Incidents
Presented by Carahsoft
Advanced HI-Tech Cyber Investigation Training
Seminars Led by Law Enforcement Officers and
Ph.D Computer Scientists29 classroom training hours, presented by sworn law enforcement officers, Ph.D. Computer Scientists and nationally recognized cybercrime textbook authors and instructors. Distinguished ISS World Training Instructor sessions include:
Tuesday, November 17, 2026
Seminar #1
9:35 AM - 5:00 PM
Online Social Media and Internet Investigations
Presented by: Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police
This Seminar is open to all attendees but designed for practitioners who are actively collecting evidence and criminal intelligence, identifying unlawful online activity, and mitigating threats.
While Tor is the most common Darknet Service, it is not the only one. And, while Tor Hidden Service servers are the most well-known portion of the Darknet, there are other areas accessible through other tools. The first two sessions will give practitioners the foundation that they need to understand these tools and communities—both how they function and how they are exploited by criminals.
Mobile devices collect, store, and transmit an ever-increasing amount of information that includes handset geolocation information collected from a combination of GPS, Wi-Fi, cellular trilateration, BLE beacons, and ultra-wideband sensors. The afternoon sessions will take a deep dive into information being collected by mobile handsets, operating system developers, and social media companies.
9:35-10:20 AM
Proxies, VPNs, and Dark Web: Identity Concealment and Location Obfuscation10:25-11:10 AM
Tor, onion routers, Deepnet, and Darknet: An Investigator's Operational Perspective1:00-1:45 PM
How Criminals exploit Darknet Services and Dark Markets: A Deep Dive for Criminal Investigators1:50-2:35 PM
Tor, onion routers, Deepnet, and Darknet: Investigative Strategies & Case Studies3:35-4:20 PM
Device Geolocation through GPS, Wi-Fi Triangulation, Cell site Trilateration, BLE Beacons, and Ultra-Wideband: What Investigators Need to Know4:25-5:00 PM
Collecting Evidence from Online Communication: Building a Cyber-OSINT Toolbox
Seminar #2
9:35 - 10:20 AMUnderstanding 5G/5GA/6G LI for Investigators
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesSeminar #3
10:25 - 11:10 AMAI Technology Basics and LEA Use Cases
Matthew Lucas (Ph.D, Computer Science), VP, TeleStrategiesThis session gives LEA, intelligence and other practitioners a primer on AI technologies. Topics covered include how AI technology is being leveraged in our industry (e.g., image recognition, classifying unstructured data, natural language processing, document summarization, and more); traditional AI approaches (heuristics, indicators); basics of machine-learning systems (models, training, neural-networking); generative AI systems (OpenAI, Anthropic, Grok, others); the strengths and weaknesses of each AI model; and how the LEA/IA/ISS vendor communities are leveraging AI to increase the efficiency and accuracy of their network data, OSINT, location, image and natural language operations/applications.
Seminar # 4
1:00 - 1:45 PMGenerative AI Use Cases and Capabilities for Law Enforcement and Intelligence Agencies
Presented by: Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesGenerative AI (GAI) is revolutionizing network data and OSINT analytics – with the end-goal of enabling investigators to effortlessly engage, analyze, visualize large datasets and “connect the dots” that would traditionally require enormous manual effort from teams of analysts and IT personnel. This session will cover the key issues related to GAI platforms: how they are/can be used; what models are available; who are the key players; how to integrate GAI systems with your datasets (RAG); dealing with accuracy and hallucinations; data embeddings and citations; integration standards; data orchestration and more
Seminar #5
1:50 - 2:35 PMAgentic AI - Deployment Options and Approaches(1 Classroom hour)
Matthew Lucas (Ph.D., Computer Science, VP, TeleStrategiesThis session will cover Agentic-based AI platforms, the technology and challenges facing LEAs/IAs looking to incorporate Agentic AI platforms in their operations. Topics covered include hosting platform options; small/local model options; operational costs; implementation requirements; security; regulatory considerations; aligning and fine-tuning models; optimizing agentic AI platforms for ISS workflows; and ongoing development advances to watch.
Wednesday, November 18, 2026
Seminar #6
8:30 AM- 4:15 PM
(THIS SEMINAR IS ONLY OPEN TO LEA AND GOVERNMENT ATTENDEES)
A Real World Look at Dark Web Investigations
Presented by: Todd G. Shipley, CEO, Dark Intel, and CoAuthor of, Investigating Internet Crimes: An Introduction to Solving Crimes in Cyberspace and retired investigator, Reno NV, Police DepartmentThis intensive one-day training introduces law enforcement investigators to the knowledge, tradecraft, and operational safeguards required to navigate and analyze the Dark Web. Participants will progress from foundational understanding to advanced investigative techniques, including covert access, digital currency usage, and deanonymization strategies. Delivered with tactical clarity and real-world examples, this seminar empowers professionals to engage hidden environments safely, interpret technological artifacts, and build actionable intelligence. This is a Law Enforcement–Only training: investigative methodology, covert tactics, and operational tradecraft will be discussed in detail throughout.
8:30-9:15 AM
Unmasking the Dark Web: Myth vs Reality
Explore what the Dark Web really is and the media myths. Dispel common myths about anonymity and illicit trade, understand the layered internet (Surface, Deep, Dark), and learn why Dark Web familiarity matters for investigators.
9:20-10:05 AM
Inside TOR: Tracing the Onion
Examine the TOR network’s architecture, access methods, and Tor’s role in obfuscating criminals’ identities. Learn forensic artifacts generated during TOR usage, how exit nodes behave, and what investigators can observe, log, and preserve legally.
11:15-12:00 PM
Bitcoin & Beyond: How Digital Money Powers Hidden Markets
Understand how cryptocurrency operates within Dark Web marketplaces—beyond tracing transactions. Learn about payment mechanics, vendor trust systems, wallet practices, and common misconceptions about anonymity.
1:30-2:15 PM
Fieldcraft in the Shadows: Safely Engaging the Dark Web
Learn secure, covert engagement techniques for accessing the Dark Web, its forums and markets. Topics include persona development, OPSEC protocols, and other best practices.
2:30-3:15 PM
Web Bugs & Covert Tech: Tracing the Invisible
Dive into investigative technologies including web bugs, tracking pixels, browser fingerprinting, and covert probes. Learn how these tools can be used ethically to reveal suspect behavior, location, and activity across hidden platforms. *
3:30-4:15 PM
Piercing the Veil: Identifying Anonymous Actors
Learn how covert actors slip up on the Dark Web and are uncovered using real-world investigative techniques. See how investigations have exposed hidden actors across encrypted channels and from fragments of digital behavior.Seminar #7
1:30-2:15 PMUnmasking Hidden Evidence: Metadata & EXIF for Digital Investigators (1 Classroom hour)
Presented by:Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #8
2:30-3:15 PMPush Tokens in Criminal Investigations: Tracing Digital Footprints & Uncovering Evidence
Presented by: Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State PoliceSeminar #9
3:30-4:15 PMUnderstanding the Implications of Online Social Media for OSINT During Critical Incidents
Presented by: Charles Cohen, Vice President at NW3C, the National White Collar Crime Center, Professor in Practice Criminal Justice, Indiana University and Retired Captain, Indiana State Police