The Bitter Pill of DF/IR Hindsight
I once drove hours to hear minutes of a digital forensics presentation, one I felt was a waste of time. But, that one presentation was two decades ahead of me and taught me a valuable lesson about what happens when you think you know enough.
Hindsight #1: What I Missed
During the era of pagers (just so you know how far back this goes), I heard about a “breakthrough” forensic topic being presented a couple of hours away from my office. My partner and I convinced our Sgt of the importance, took the day and drove six hours round-trip, just to catch this one session. Classic use of government time…but in hindsight, worth every minute.
The presenter was someone from a cellular service provider, maybe it was AT&T or Cingular, I don’t remember. But I do remember his message: “Cell phones will become the future of investigations.”
Cell phone forensics? No thanks. I was deeply invested in analyzing dead-box computers and convinced I knew what mattered. Besides being able to make calls, I could only see playing Snake and using a calculator on my Nokia. I could get call logs and pen registers all the time anyway for my cases. I dismissed the entire presentation as being irrelevant.
Fast forward to today: Boy, was I wrong.
Today, mobile devices often tell the entire story: location, messages, deleted apps, behavioral patterns. I missed that early wave because at the time, I thought I knew enough and this presentation on cell phones had nothing for me to learn.
The regret, aka learning lesson, is not that I missed a trend, but that I believed there wasn’t more to learn outside of what I was already doing. My ego convinced me that I was smarter and better than I was. I sometimes wonder how much farther I would be today in mobile device forensics if I had taken that presentation seriously…
Hindsight #2: What I Got Right
Even when I got a tech prediction wrong, I got one thing right: I never stopped thinking like an investigator.
Not as a tool user. Not as a report generator. But as an investigator.
That mindset carried me through thousands of hours of casework across law enforcement, the private sector, and legal consulting. It shaped how I learned, how I taught, and how I chose my tools. It allowed me to work through cases that I had no prior training or experience in handling, but I was able to figure them out. It allowed me to create strategies that worked across domains.
The best tools enable me to do my best work. But they don’t replace the human element. You still must ask the right questions, recognize the patterns, and know what the evidence is trying to tell you.
Always Pursue Storylines Beyond The Digital Artifacts
DF/IR isn’t just about identifying evidence, it’s about connecting it. That means tracing:
- Actions to Actors
- Packets to People
- Sessions to Storylines
- Browsers to Behavior
- Timestamps to Truth
- Devices to Defendants
- Artifacts to Attribution
These aren’t metaphors. They’re how cases get built. It’s how suspects are placed at devices and how threat actors are placed inside the timeline.
The Lost Art of the Investigation
Here’s what no one wants to say or hear: We’ve lost the art of investigation in DF/IR*. We’ve gone from a field of investigators to isolated pockets of real investigation.
Some had it and let it slip. Others were never taught what it truly means to investigate and they forever flounder through cases or incident reports, blaming their tools, their training, or their dashboards. A few have learned it through decades of experience, the hard way.
I’m not just talking about critical thinking or soft skills. I’m talking about real investigative tradecraft, asking the right questions, correlating digital and physical evidence, documenting like your credibility is on the line, and building cases that stand up in a courtroom or a boardroom. It’s the art of seeing the totality of a case or event and being able to not only piece it together accurately, but to convey it to anyone.
And this failure doesn’t just show up in forensic labs. It appears in IR war rooms when logs are misread, when EDR data is misinterpreted, and when alerts are pursued without context (or worse, not pursued when they should be!). Real-time decisions are made in the heat of an incident. However, unless you’re treating the incident like an investigation, you’re merely reacting and not resolving it.
Checkbox forensics is not investigation. Clicking “Next” is not analysis. And exporting a report is not the same as building a defensible timeline of events, supported by correlated evidence and provable intent. Our tools have become so effective that we have given up control of our casework.
We need to fix that. That’s what I’ve been quietly building for years and speaking about even longer.
Which are you?
There are two kinds of DF/IR people:
- Those who already know everything.
They’ve hit their self-imposed ceiling and determined they know enough (ie: no one can teach them anything). - Those who stay hungry.
They listen. They study. They seek out the 1% that separates good from great (ie: they will learn from everyone).
Think of it like this:
Even Roger Federer, one of the greatest tennis pros of all time, hired many coaches who weren’t better tennis players than he was. But they were able to see what he couldn’t. Federer sought wisdom, training, and experience from others throughout his entire career. That’s the mindset DF/IR demands.
That’s a model worth copying in any field, including DF/IR. That’s the kind of effort that changes careers. And solves cases.
I’ll leave you with this
I’ve missed good ideas. I’ve made bad calls. But I’ve never regretted staying grounded in investigation. It’s what’s kept me useful in every case and every courtroom.
If you’re the kind of person who wants to be more than a tool user, someone who connects the dots, sees the story in the data, and drives cases forward, pay close attention to what’s coming.
I’ve been developing a training and book based on a field-proven framework used across law enforcement, private sector, and legal consulting. It’s not theory. It’s not fluff. It’s repeatable, flexible, and defensible.
I believe in it enough that I:
- Trademarked it.
- Copyrighted it.
- Published it as a small part as The DFIR Investigative Mindset book.
If you’re chasing truth over timestamps, this is your invitation and notice. No fanfare, no flashy sales. Just signal. Stay tuned.
It’s time to bring the investigation back.
Subscribe for updates. You’ll be the first to know.
*Good investigators are always learning and never believe they know it all or know enough.
The PSBK volume 3 book is now available for pre-order from Barnes and Noble, a few other retailers, and soon Amazon.
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.



