Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

Forensics First. AI Second.

By Brett Shavers
May 17, 2026
0

AI found it. You prove it. From Artifact to Defensible Casework Decisions.

I bought an AI-ready computer for testing and started running a local LLM against test data and CTFs. It’s a little more complicated

than that to get set up, but once you get everything connected….oh my.

I have not been this excited and this disappointed at the same time.

The speed is hard to describe unless you see it in front of you. It can run through data, summarize, group, compare, and surface things faster than a person could manually work through the same material. That part is really incredible. Anyone pretending this technology is not going to change DFIR work is fooling themselves.

The problem, and it’s a big one

Once I moved from broad data review into natural-language questions tied to investigative processes, the LLM risks and failure were there. These are scary failures because an LLM will fool you. It’s optimized to be “helpful” and agreeable, even if it is completely off base.

For example, I intentionally gave it bad prompts. I guided it toward wrong answers. I already knew the truth from the test data and CTFs, so I knew when the answer was wrong. I intentionally drove the LLM to wrong conclusions as a test and it did not disappoint.

The problem was that the answers the LLM gave me were plausible, and believable. And that is the danger of DFIR+AI for practitioners. With automation (filtering, carving, etc), we instinctively check and figure out the answer, because the data by itself is not an answer. With an LLM, it is telling you “an” answer and will defend its answer, even if wrong.

If you already know the case, the evidence, the investigative process, and the limits of the data, AI can help you move faster. It can help organize your thinking. It can help find weak spots. It can find anomalies, outliers, patterns, and things you’d likely miss. This is the incredibly useful part.

But if you do not know what the answer should roughly look like, you may never know whether the AI was right, wrong, or misleading you to make you feel better. That is where examiners are going to get into trouble; relying on what a computer tells you. This is the incredible danger to the case and to a career.

DFIR+AI

A few weeks ago, I gave a DFIR + AI webinar. 554 registered! About 200 watched live. Another 200 or so watched the replay. The rest missed both. But there were lots of questions afterward, some of which I haven’t responded yet because I didn’t yet know the answer..

Because of what I am seeing with what AI and LLMs can do with evidence, the interest in a basic DFIR+AI webinar, I am giving a training workshop on the three pillars that I think will matter most in the DFIR + AI future:

DFIR Investigative Mindset    |    Casework    |    DFIR + AI.

I’m not going to talk about AI tricks, or prompt engineering, or completely not using AI or completely using AI for casework. But I will give you a system that has been ‘battle tested’ (if you consider legal casework and trials as ‘battle tested’) that AI fits into. We’ll get into the bloody battle of AI evidence issue too.

AI Found It. You Prove It.

Live Online Training Workshop
May 22, 2026 | 11:00 AM Mountain Time| $39

Register Here

 

 

I so much believe in a DFIR investigative mindset, that I will give you the PDF version of my DFIR Investigative Mindset book as part of this workshop. The print version is best (and when you read the book, you will know why), but if nothing else, I want you to get the PDF version.

The reason I believe in this system is that it helps you build cases (regardless if civil, criminal, national security, or breaches), future-proofs your career (you can run any case with any tools), and the end result is justice for the victims based on truth. Tools change. Data changes. AI will change. But the core skill does not.

For those in DFIR who are keeping up with AI in (1) what is happening now, (2) what is possible, and (3) what are the survival odds of your role if you don’t keep up, you will probably be fine.  Ride the wave, in control.

Everyone else will be passed by, or worse, forced out because of bad casework.

The workshop is limited to 40 live attendees. There is a 90-day replay if you miss some or all. You get the PDF edition of the book regardless (you can’t get the PDF version anywhere else, and the book is $59.99).

As of right now, there are already 23 registrations. I want to literally give you the key to the investigative castle with my book. It’s that important.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

That Time I Bought Coke on a Skateboard

Next

Don’t Marry the Suspect

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.