Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

The way you look at devices will affect what you find on them.

By Brett Shavers
February 8, 2025
0

Every DF/IR investigator has missed something. It is virtually impossible to find every bit of relevant evidence. Some are gone forever, others are comingled in a sea of electronic data that is easy to miss, and some have been intentionally hidden. Considering that this is common, what have you missed? Maybe a critical artifact, an overlooked connection, or a wrong assumption sent your analysis in the wrong direction.

Your Brain is Screwing You Over

Your Reticular Activating System (RAS) is your biggest weakness and biggest strength. It decides what gets your attention and what gets ignored. Think of it as a searchlight. Whatever’s in the beam is crystal clear and targeted, but everything outside? Pitch black.

Test it. Start talking about red cars. You’ll begin to see them everywhere. They were always there; you just weren’t looking. But remember, you will be missing all the blue cars..

1595538484295Now apply that to your investigations. If you’re not controlling your RAS, it’s controlling you by blinding you to evidence outside your tunnel vision and seeing “witches” everywhere. Be aware if you are wearing blinders.

Two mistakes we make

The first mistake? Looking at a device as just a piece of hardware with data instead of a story waiting to be uncovered by considering the whole of artifacts.

The second mistake? Neglecting to ask who owns the device to determine how much effort they may have put into hiding or deleting evidence, if at all.

Too often, we are given a limited data set or individual device without knowledge of its background. On the one hand, we start with an objective mindset going in blind, but on the other hand, we might miss an important clue had we known who used that device, and how did they use it.

The owner’s knowledge, intent, and preparation determine what evidence you’ll find. If you don’t factor this in, you’re already behind.  How you approach the device affects how you plan and create objectives for your case.

Four Types of Device Owners

The type of device owner changes everything about how you approach evidence. Their knowledge, intent, and preparation impact what you will and will not find.

1. The Innocent Owner

 Evidence Type:

  • Regular user activity, with no deliberate attempts to hide or delete anything.
  • Clear history, normal digital patterns, and unaltered metadata.

 Investigator Mindset:

  • Look for external actors: Was their device used remotely? Was it compromised? Is it a distraction device (planted by a guilty user)?

2. Unprepared Guilty Owner

 Evidence Type:

  • No signs of anti-forensic behavior.
  • Incriminating data left fully intact with complete unintentional self-incrimination.

 Investigator Mindset:

  • Look for accidental evidence: messages, emails, financial transactions, or metadata showing unintended illegal activity. This one if fairly straightforward.

3. Forensically Aware Criminal

 Evidence Type:

  • No encryption, but some attempt at data deletion (half-hearted or unskilled).
  • Potentially damning files moved, renamed, or deleted but not entirely wiped.

 Investigator Mindset:

  • Look for sloppy deletion, recent clearing of logs, or missing files that should be present.

4. The Guilty Owner Prepared for a Forensic Examination

 Evidence Type:

  • Strong encryption, full-disk wiping tools, and hidden partitions.
  • Dummy accounts, misleading filenames, and planted false evidence.

 Investigator Mindset:

  • Look for system logs, registry changes, remnants in swap files, and forensic misdirection. Look for connected devices for additional leads. If nothing of the crime can be found, the device usage history may be important to prove/disprove alibis or identify co-conspirators.

The 10 Ways You’ve Mishandled Evidence Without Even Knowing

1. Assuming a device isn’t important because it wasn’t used in the crime. Just because a device wasn’t the attack vector doesn’t mean it’s irrelevant. Messages, synced data, location history—this is where suspects screw up. Obviously, with many devices to exam, triage and exam the low hanging fruit, but don’t completely neglect this type of device.

2. Thinking a suspect knows how forensics works. Most people don’t. They delete browser history and think they’re Edward Snowden. Their GPS, cloud backups, and auto-saved files will hand you most everything that you need. Just because you didn’t find the evidence on the device does not make it “complex” or that the suspect “highly sophisticated.”

3. Giving up because you see encryption or wiped data. Encryption doesn’t mean no evidence. Even if files are gone, the system logs their absence. A wiped drive isn’t invisible. It’s suspicious. The trick is figuring out what should be there but isn’t.

4. Seeing a destroyed device and thinking it’s a dead end. A smashed hard drive or a burned phone is not game over. Data recovery and chip-off forensics from damaged devices exist for a reason. If they went to the trouble of destroying it, it mattered.

5. Ignoring secondary devices like routers and IoT gadgets. You don’t need the suspect’s phone to prove they were home at 2:00 AM. The router, the Nest thermostat, the Apple Watch on their wrist are all snitching on them.

6. Assuming the device owner is the guilty party. Just because their device was used doesn’t mean they did it. Remote access, compromised accounts, and family members borrowing laptops require you to cross-check logins and access patterns before you risk burning an innocent person.

7. Not separating evidence from multiple users. One device doesn’t mean one person. A shared computer, shared user accounts, a work laptop, and a family iPad contain mixed data. If you don’t isolate users, you might be pinning a crime on the wrong person.

8. Thinking everything you need is on one device. It’s not. Cloud storage, external backups, and synced accounts. Half the evidence isn’t even local. If you only look at what’s in front of you, you’re missing everything stored elsewhere.

9. Believing everything you see. Some suspects leave false trails, rename files to mislead, and create fake accounts to throw off investigators. If the evidence looks too obvious, start digging into timestamps and metadata.

10. Trusting that a device belongs to the person using it. What if it was planted? What if a suspect put it there to frame someone? The question isn’t just what’s on the device; it’s who put it there and why.

Final Thoughts: Look Where No One Else is Looking

Your tools won’t save you if you’re only looking for what you expect to find. Control your searchlight. Stop making assumptions. Categorize the device, analyze the owner’s mindset, and figure out what’s missing. The difference between a good investigator and a great one isn’t just the tools. It’s how they think and how they control their thinking.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
expert
Previous

Are you a DF/IR Expert Witness or Just a Useful Pawn?

winfe
Next

Think You Don’t Need WinFE? Wait Until You Do.

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.