Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

DF/IR was built in a garage

By Brett Shavers
April 12, 2025
0

Why DF/IR Professionals Need to Set the Standards Before It’s Done for Us

DF/IR wasn’t built in a lab. It was built in a garage. Not a cleanroom. Not a courtroom. Not a classroom. Not a conference room full of policy makers. A garage. By people like us, people who had to figure it out fast, because there wasn’t a manual and every time seeing something was the first time.

Today, a growing crowd of bureaucrats, legal advisors, and policy writers, most of whom have never touched a forensic image are standing at the garage door with clipboards and checklists. And they’re ready to write the rules.

I’m not against rules. I actually believe we need them. But I do believe this: those rules better come from people who actually do this work or the rules won’t work for those doing the work.

garage

The Garage Forensics Era Is Real and It Still Works

DF/IR started with people figuring out how to clone a drive, recover deleted data, and follow digital footprints with almost no guidance.

The first forensic investigators wrote scripts to recover deleted files when no tool could. They used software that was designed for one thing and used it for another thing. They imaged drives in less-than-ideal conditions. They created triage methods in the field, under pressure, with no time to wait for “approval.”

They did it fast. They did it (mostly) right. They documented it. And it worked (mostly). Mistakes were made and some processes created back then wouldn’t hold up today. That’s the garage forensics mindset, and honestly, it’s still the best part of this field. Innovation is at its best when nothing restrains it.

We’re building tools, testing them in real cases, and sharing what works. That’s community-led innovation. And it’s what keeps DF/IR moving forward at a pace to keep up with technology and the adversary.

But the freedom to innovate won’t last forever. Enjoy it while it lasts and innovate!

Standards Are Catching Up And That’s (Mostly) a Good Thing

Since 2016, the field has grown up. NIST and SWGDE have helped shape how tools should be validated. ISO 17025 is the gold standard in many forensic labs. Courts now use Daubert to test whether you actually understand your tools or are just pushing buttons. And some college programs are starting to teach more than “click here, export there.”

That’s progress. We need it.

But not all standards are equal, and not all standards are law.

Standards Are Not Regulations

This part gets messy. People assume if you don’t follow a standard, your evidence is toast. That’s not true.

Most DF/IR standards today come from non-government groups great organizations doing important work. But here’s the thing:

SWGDE? Excellent best practice, but not law. ISO 17025? Highly respected, but not required everywhere. SOPs from one lab? Useful, but not universal.

You can step outside a standard and still be forensically sound if your method is reasonable, documented, and defensible. That’s not sloppiness. That’s real-world problem-solving.

Forensic Soundness Is About Context

Let’s say you had to grab volatile memory before it disappears. Or triage a phone during a live incident. Or analyze cloud data before the user wipes the account.

If you do it carefully, document your steps, and can explain your decisions in court, you’re solid. Courts want to know: Did you preserve the evidence? Did you act reasonably? Can your process be trusted?

That matters way more than whether you followed a checklist from a 300-page PDF written six years ago.

Yes, Some Labs Are Regulated, But That’s Not the Whole Story

Government forensic labs are regulated. They have ISO. Oversight. SOPs. QA managers. And clipboards. Lots of clipboards.

Most DF/IR work doesn’t happen in those labs. It happens in the field, in corporations, in small agencies with no lab at all, and during live incidents where there’s no time to wait for policy approval.

That’s where the garage forensics mindset saves the day. But it’s also where we risk getting buried if the wrong people start writing the rules for us.

Why Is Everyone Working in Silos?

You know what surprises me most? Almost every major player in DF/IR is working in a silo.

One org writes its standards with another writes its own standards. Another certifies tools. A third hosts conferences. A fourth builds ethical frameworks. But no one’s talking to each other in a meaningful way.

At the same time, academia writes degree programs with little input from the field. Vendors create tools without always checking what examiners actually need (they have to guess!). Agencies develop policies disconnected from what’s happening on the ground.

And this isn’t just me venting. This was called out nearly a decade ago:

“DF practitioners have created multiple [professional associations]… This hodgepodge of efforts has likely contributed to explaining why DF has not yet become a profession.” — Losavio, Seigfried-Spellar, & Sloan (2016)

That was 2016. Not much has changed. Before bashing me, yes, I know there are exceptions, great ones.  But we need the exceptions to be the rule, not the other way around.

Everyone’s working hard but everyone’s working alone.

This field is too important to stay fragmented. We need unified guidance. Shared goals. A coordinated effort to define what DF/IR is and what it must become.

What About Global Standards?

I’ve been reading here and there that we need international standards and laws in DF/IR work. And yes, that’s possible partly.

How to image a drive. How to validate a tool. How to document analysis steps. These are technical processes. They can and should be agreed on across borders.

But let’s stop pretending we’ll ever have international legal standards. That’s a fantasy. Countries have different privacy laws. Different rules of evidence. Different ideas about what “reasonable search” means.

We’re not going to get 2 or 3 countries (let alone 195!) to agree on who can access cloud data or how long logs should be kept. So let’s focus where we can: build global technical unity. Accept legal diversity. Work with it.

Yes, I Support Regulation, But It Has to Come from Us

Let me say it loudly for those in the back:

I believe in regulation but I do not believe in regulation written by people who’ve never done this job.

This work is too important to leave to non-DF/IR lawyers and lobbyists who don’t understand digital evidence, timelines, or testimony.

If we want to protect the future of DF/IR, we have to write the rules now. I know, I hear you. We have NIST and SWEDGE and DFRWS and HTCIA and IACIS and ABCDEFG and HIJKLMNOP and QURSTUVand WXYZ each writing their own ‘rules’ but again, these are not rules. They are suggestions for best practices, written in silos.

We Still Have the Garage. Let’s Use It

We still have time to get this right.

We can build standards that make sense. We can create ethics that match reality. We can document methods that hold up in court. We can mentor, teach, and grow the next wave of digital examiners.

The garage era is still here but the clock is ticking. When regulation comes (and it will), things will slow down. Innovation will take a backseat to policy.  That’s when writing your own tool might be required to be validated, verified, corroborated, and tested through an extensive system BEFORE use in real life.

If we build the foundation now, we’ll control the future. If we don’t? Someone else will. And they won’t get it right.

What do we do next?

Or, do we just sit back, enjoy the ride, and hope for the best? Or do we do something?

Citation: Losavio, M., Seigfried-Spellar, K.C., & Sloan III, J.J. (2016). Why digital forensics is not a profession and how it can become one. Criminal Justice Studies, 29(2), 143–162. https://doi.org/10.1080/1478601X.2016.1170281

 Source:


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
reacher
Previous

Why Acting Like Jack Reacher in DF/IR Will Land You in Court, Not on a Bestseller List

murderingmood
Next

Your Mood Is Murdering Your DF/IR Investigation and You Don’t Even Know It

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.