Brett Shavers's Blog, page 5
October 16, 2024
AI in the DFIR Crosshairs
AI in the DFIR Crosshairs: How AI Fits into Digital Forensics One of the most important rules in science and in Digital Forensics and Incident Response (DFIR)—is repeatability. This means that if you follow the same steps under the same conditions, y...
October 14, 2024
Trust me. I’m an Expert.
We’ve all heard the phrase, “Trust the experts,” implying that advanced degrees and years of experience guarantee the correct answer. But experts are still human—and humans make mistakes. Throughout history, even the brightest minds have been wrong d...
September 26, 2024
Should DF Be Separated from IR?
Digital Forensics and Incident Response (DFIR) is a term frequently used in the cybersecurity world, often without fully understanding the distinct roles of Digital Forensics (DF) and Incident Response (IR). While these fields share tools, training, ...
September 25, 2024
Empowering 1,000 DFIR Professionals with a DFIR Investigative Mindset
Over the years, I've had the privilege of working alongside many talented individuals in the DFIR communities in both the public and private sectors. Our field is ever-evolving, with new tools and technologies emerging at a rapid pace. Yet, despite t...
September 8, 2024
Why DFIR Investigative Thinking is Critical—and Why It’s So Hard to Teach
Why DFIR Investigative Thinking is Critical—and Why It’s So Hard to Teach In DFIR, the investigative mindset is the difference between solving cases and missing crucial evidence. While we’ve become skilled at teaching tools, certifications, and degre...
September 3, 2024
Today, I rant
AKA: The Last Thing We Want in DF/IR is the First Thing We Need in DF/IR, Part Deux TL:DR DFIR standards are a mess—a confusing, convoluted, and chaotic disaster that’s doing more harm than good. And we have no one to blame but ourselves. Vendors, un...
July 21, 2024
Placing the Suspect Behind the Keyboard: How Full is Your Gas Tank?
One of the most critical tasks in digital forensics and incident response (DFIR) is attributing a cyber incident or crime to a specific suspect. This process, referred to as placing the suspect behind the keyboard, requires meticulous analysis, evide...
June 13, 2024
The key to DFIR mastery
Have you been spending years and thousands of dollars on training, earning certifications, getting degrees, testing tools, researching, and writing blogs? Have you been frustrated, stressed, and overwhelmed in searching for the mystical golden key to...
June 1, 2024
The Multiverse of a DFIR Case
I'm going to give a few tips to prevent you from wrecking your next case. First, consider that every case is like standing in a maze with an infinite number of doors, each leading an entry to a different universe with a different case outcome. All bu...
May 5, 2024
Ethics of Plagiarism Allegations
TL:DR I was wrongly accused of plagiarism, but the accuser has privately admitted their mistake. Due to the lack of a public retraction, I am compelled to clarify the situation myself. Overview In the spirit of transparency within our community, I am...


