Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

Intent, Not Tools, Defines the Discipline

By Brett Shavers
July 16, 2025
0

If you work in cybersecurity (in any of the many roles under the cybersecurity umbrella), odds are you think you have a decent grasp of the cybersecurity field.

But you might not.

You probably have a solid grip on your slice of it, your role, your tools, your environment. But unless you’ve worked across multiple domains, and I mean actually done the work, not just read about it or make assumptions, then your perspective is partial at best and dangerously biased at worst.

This isn’t an insult. It’s a warning.

We’ve all become victims of what I call the fence-line illusion, mistaking the narrow view we have for the entire picture. And nowhere is that more obvious than in the ongoing confusion between Digital Forensics, Incident Response, and eDiscovery.

The Fence-Line Illusion

Picture a football game with a full stadium, screaming crowd, and two teams running back and forth on the field. Now imagine dozens of people standing outside the stadium, each peering through a narrow slit in a wooden fence. One sees the 40-yard line. Another sees the sideline. Someone else sees the end zone.

cyberfield

Each one assumes they’re watching the game. Each one is wrong. That’s cybersecurity seen by each of us.

You work in a SOC. Someone else works IR. Another does mobile forensics. Someone’s knee-deep in eDiscovery. Each sees a slice and assumes it’s the whole. You interpret everything through that slit. And if you stare long enough, you forget it’s even a slit.

When Narrow Perspective Becomes Dangerous

I recently published a book on investigative thinking in DF/IR. Shortly after, a trainer from the IR/SOC world accused me of plagiarism.

Not because he’d read the book (he admittedly did not read the entire book..).  Not because he had evidence. But because of two things: One, I didn’t cite his dissertation and two, one of his students told him that my book “sounded similar” to what he teaches. That was enough to spread that accusation to several others without verifying anything, or reaching out to me. When I called him to ask what he was talking about, he eventually admitted that I didn’t plagiarize anything, but that I should have cited his work.

My book was based on practical investigative work; not academic cognitive theory and the concepts he claimed ownership of were either public domain or thousands of years old (think Socrates). Everything else I had cited or had developed myself from personal experience in criminal investigations.

The biggest misunderstanding was our perspectives between DF and the IR. His was that “IR = DF” and mine was “IR might = DF, but only if it is DF.”  

In his view, the terms of digital forensics, incident response, and even electronic discovery can be used interchangeably as if they mean the same thing or are the same thing. I disagree still.

Why did this happen?

Because his slice of the field, theoretical investigative models applied to IR and SOC environments, had become his definition of all investigative thinking. He couldn’t imagine someone writing from a perspective he hadn’t lived. And because he hadn’t worked a forensic case through the legal system, he saw my work as derivative rather than different.

He mistook his slit in the fence for the entire game.

I bring this up today because I still get messages about cognitive theories being the same as an investigative mindset…and all referring me to a dissertation or courses that are marketed as digital forensics but are incident response. Misstating IR as DF or DF as IR confuses everyone who do not understand the difference.

The Problem with Misusing Labels

This goes beyond personal drama. It affects the integrity of the professions. One of the most common and corrosive issues in cybersecurity today is the sloppy conflation of terms, especially “Digital Forensics.”  But even misused terms like “deleted” can completely derail a case in trial or lead an investigator or analyst down rabbit holes.

People throw the word “forensics” around like pineapples on a pizza. But here’s the problem (besides putting pineapples on pizza): Using forensic methods doesn’t mean you’re doing Digital Forensics.

Hashing a disk, using write blockers, and preserving logs are good practices. But unless the intent is to support a legal process (criminal, civil, regulatory, administrative), it’s not forensics. It’s just careful work. At best, it is forensically sound processes but even that does not make it “forensics.” It only makes it preservation + integrity + documentation, and only if done correctly.

This matters a lot.

  • If you’re working a ransomware event and there’s no intention of using the evidence in court, that’s incident response.
  • If you’re collecting evidence to hand to an attorney, regulator, or judge, that’s forensics.
  • If you’re sorting through millions of documents for production in a civil matter, that’s eDiscovery.

Same tools? Sometimes.  Same data? Possibly.  Same purpose? It depends on the intent.

Calling all of it “forensics” dilutes the term and misleads people who rely on the difference, like judges, attorneys, clients, and yes, other practitioners. If someone tells me that they work in Digital Forensics, my assumption is that they work legal cases, not that they use forensically sound processes in non-legal work.

The Blind Spot We All Have

This has nothing to do about who is smarter or more skilled. You might be brilliant in your domain (DF or IR or __). But deep knowledge in one area often blinds you to the limits of your perspective.

I’ve spent decades in digital forensics. I’ve authored search warrant affidavits, made arrests, sat in court, defended findings under oath, and dealt with judges who didn’t know a hard drive from a ham sandwich. I’ve also worked with IR teams, SOC analysts, and eDiscovery vendors. And I still have blind spots and always will.

I’ve never worked in a 24/7 SOC. I’ve never led red team ops. If I tried to teach those areas, I’d be half right and half wrong. Actually, I’d be more than half wrong. The IR world is different from the DF, and it scares me a little bit because IR practitioners are amazingly more technically skilled in areas that I know little about.

But the same is true in reverse.

If you’ve never testified, never been deposed, never handled evidence with a defense attorney breathing down your neck, never had a judge question your processes in trial, then there are things about forensics you simply don’t know, no matter how well you hash your data or document your process or learn it by watching it play out on tv.

And when you don’t know what you don’t know, that’s where the danger lives.

Real-World Damage

When people confuse their domain with someone else’s, bad things happen:

  • DF practitioners may view IR work as less structured, as it prioritizes rapid containment over legal admissibility; different goals, not lesser ones, and many times more important!. Meanwhile, IR teams might call their work ‘forensic’ without realizing this implies courtroom readiness, creating confusion when DF is needed.
  • IR analysts assume their logs are legally admissible without validation or even knowing how evidence is admitted as evidence.
  • SOC teams over-rely on automation and miss nuance in artifacts or assume everything is evidence without an investigation.
  • Execs make decisions based on buzzwords and blurred definitions, and make assumptions on what they are being sold, I mean, told.
  • Educators create frameworks that apply perfectly to their slice but collapse in other contexts yet profess their frameworks to fit what it doesn’t.
  • Those in DF assume that they know IR, and that is a recipe for disaster (same in reverse!).

Each of them thinks they see the game. But what they’re seeing is small part through a slit in the fence.

So, What Do We Do?

Be precise in terms because decisions are made on how we describe our work, not just on the work we did.

Remember that tools don’t define disciplines, purpose does. What matters is why you’re doing the work, not just how you are doing it.

Final Thought

Don’t confuse good habits with legal readiness. Don’t call your work “forensics” unless you’re prepared to defend it under oath. And don’t assume that the rest of the field is just a version of your job with different acronyms.

Can I say I’m in cybersecurity? Sure, but only in the broadest, umbrella sense. Just like a podiatrist is in medicine, or a criminal defense attorney is in law. The title fits, but it’s not specific. If I say I’m in DFIR, that’s a little more useful, but still vague because it’s a mashup of two very different disciplines. If I say I’m in DF, now we’re getting somewhere. That tells you my role probably involves legal processes, evidence handling, and possibly testimony. If someone says they’re in IR, I assume they’re dealing with threat actors, malware outbreaks, business continuity, and containment and not prepping affidavits and declarations or testifying in court. The more precise the label, the more honest the message. And if you’re using one label to mean another, you’re not just confusing others, you’re probably fooling yourself. But of course, if you do both, then you really are DFIR and not DF/IR, like a medical doctor is a general practitioner.

On DF/IR (the slashed term anyway)

Although I didn’t originate the slash, I agree with and advocate it. I’ve said often that I work in “DFIR”, all the while knowing that I will avoid touching IR engagements unless it is unavoidable and I’m there to help with the DF part of IR. I appreciate the slash because I am much more comfortable saying DF/IR as an umbrella and specifying that I am the DF, and not the IR.

As an anecdote, I once had this interview for a role advertised as DF and the entire day was actually being interviewed for an IR role. Mid-day, I said, “I think I am in the wrong place because you are looking for an IR person.”  They didn’t get what I was saying, but I decided to stay for the free lunch and use the rest of the day as a learning experience before saying no thank you. It would have been a bad fit, but an entire day gone because conflating DF with IR.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
dfirreview
Previous

I’m stepping away from DFIR…

betweenthem
Next

How Sitting in 14 Legal Roles Created My DFIR Investigative Mindset

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.