Brett Shavers's Blog, page 3

March 29, 2025

Coming in 2025: Placing the Suspect Behind the Keyboard: DF/IR Investigative Strategies, Volume 3

After dozens of rewrites, fresh starts, and scrapped chapters, I’ve finally locked into the version of Placing the Suspect Behind the Keyboard: DF/IR Investigative Strategies (Vol. 3) that I know needs to be written. And yes, you'll be able to order ...

 •  0 comments  •  flag
Share on Twitter
Published on March 29, 2025 00:25

March 21, 2025

You Don’t Belong in DF/IR

Trying to get into DF/IR breaks most people. So, you’re not going to make it.  If you’re offended by the title of this post, good. That’s step one in figuring out you’re probably not cut out for this work. I’ve seen too many people get excited a...

 •  0 comments  •  flag
Share on Twitter
Published on March 21, 2025 07:14

March 10, 2025

DF/IR is not dying. It's just harder than ever.

The cybersecurity competence bar’s dropped so low it’s in the basement. Companies don’t want experts; they want button-pushers who’ll work cheap. DF/IR’s soul, placing the suspect behind the keyboard, is getting lost in the automation and artifi...

 •  0 comments  •  flag
Share on Twitter
Published on March 10, 2025 17:44

February 13, 2025

Think You Don’t Need WinFE? Wait Until You Do.

In 2008, Troy Larson gave me the build instructions for WinFE (Windows Forensic Environment). Troy figured out how to make a Windows winpe boot in a forensically sound manner with registry changes. At the time, the concept of a Windows-based forensic...

 •  0 comments  •  flag
Share on Twitter
Published on February 13, 2025 15:40

February 8, 2025

The way you look at devices will affect what you find on them.

Every DF/IR investigator has missed something. It is virtually impossible to find every bit of relevant evidence. Some are gone forever, others are comingled in a sea of electronic data that is easy to miss, and some have been intentionally hidden. C...

 •  0 comments  •  flag
Share on Twitter
Published on February 08, 2025 12:50

February 5, 2025

Are you a DF/IR Expert Witness or Just a Useful Pawn?

There’s a hard line between working toward an objective and chasing a result, and if you don’t know which one you are doing, you are already lost. The most glaring issue I see when peer reviewing DF/IR reports* is when the examiner/analyst/investigat...

 •  0 comments  •  flag
Share on Twitter
Published on February 05, 2025 10:21

February 2, 2025

Cross-examination will Go in Raw, Wreck Your Credibility, and Leave You Begging for a Safe Word



TL:DR “Opinions are like assholes; everyone has one, and they all stink.” – One of my Bootcamp Drill Instructors Expect your credibility to be attacked in court. Opposing counsel isn’t just looking to poke holes in your findings but to obliterate you...

 •  0 comments  •  flag
Share on Twitter
Published on February 02, 2025 10:56

January 28, 2025

How Mistakes Shape DF/IR Investigations

Every investigation hinges on one critical factor: human error. As a DF/IR investigator, your ability to spot and exploit those errors while avoiding your own is what separates success from failure, and you from your adversary. Let me show you how to...

 •  0 comments  •  flag
Share on Twitter
Published on January 28, 2025 21:21

January 24, 2025

The Human Element of DF/IR (YOU!)

The clock is racing. A global breach is unraveling on one side of the room; millions siphoned in real-time, systems crashing, and reputations crumbling by the second. On the other, the unthinkable: a child has been taken. A predator lured her online,...

 •  0 comments  •  flag
Share on Twitter
Published on January 24, 2025 14:02

January 17, 2025

Do IT Pros Make the Best DF/IR Investigators?

The field of DF/IR attracts professionals from all walks of life, from law enforcement, academia, private industry, and even IT pros. One of the trends over the years is the number of IT professionals transitioning into the world of digital forensics...

 •  0 comments  •  flag
Share on Twitter
Published on January 17, 2025 08:41