Tech skills are cheap. Legal knowledge is priceless. Mindset is everything.
Tech Skills
Question: Is there an easy way to find out if the Windows registry can be found in memory, and if so, can you collect it and if so, exam it with a forensic application?
Answer: Yes, yes, and yes.
A quick Internet search will give you URLs, book titles, and training courses that address this very thing. One example is from CyberTriage. Ask AI (ChatGPT, Gemini, etc…) and you’ll get not only URLs, but the actual “how to do it” from submitting a good prompt. Yes, I am aware of AI hallucinations and inaccuracies. My point is that you can type on a keyboard and get clues specific to that particular DF/IR tech skill in seconds.
These are types of things that you need to know before coming across them. It is the art of knowing what you don’t yet know, otherwise you will never find it.
Opinion: If you apply yourself, tech skills are easy to find sources of information, easy to learn, and easy to become basically competent. From YouTube to SANS, free or damned expensive, you can learn the basics in anything DF/IR in fairly a short time. Totally acceptable to not know something, but unacceptable to not be willing to learn the basics of that something in a week or two.
Legal Knowledge
Question: How do you know what the legal boundaries are to your data you have? How do you know if a policy violation, regulation violation, or crime occurred?
Answer: You need to have this knowledge before you start, otherwise you will never identify any violation or non-compliance to regulations or policies.
A basic understanding of legal boundaries is necessary in both Digital Forensics (DF) and rarely in Incident Response (IR). DF is legal work from the first keystroke. You are there because rules, policies, and laws matter. That’s the only reason you’re touching the data at all.
If you are not aware of the legal aspects, you will miss it, and by the time someone tells you that you missed it 3 days ago, evidence will be gone.
Opinion: Every new police (state, local, federal) academy graduate should be required to spend a week in court before ever stepping into a patrol car. Any trial, civil or criminal. Forty hours of watching the system they’re about to serve BEFORE they touch that system.
If you’ve never sat in a courtroom, you have no business touching evidence. Watching how cases live and die in front of a judge and jury is not optional, it’s foundational. In DF/eDiscovery, avoiding the courtroom experience is either laziness or arrogance. For the love of that is holy, if you refuse or can’t do that, at least do a mock trial, workshop, or read legal texts.
I give IR a pass, since it’s rarely legal work. But for everyone else, how can you claim to serve justice if you’ve never even watched it happen for real, in real-time?
Investigative Mindset
Your technical skills are the key that gets you to the front door. Legal knowledge is what tells you whether you’re allowed to unlock it and cross inside. The investigative mindset allows you take command of the whole house, every room, every floor, every hidden space.
Question: Where can you get this mindset?
Answer: You get it through reflection on your experience. There are shortcuts, like being told exactly what it is and how to develop it, but getting it requires the experience and reflecting on that experience. Those who don’t reflect will never get it.
Opinion: Law enforcement has an edge in this area (and the legal aspect) because it is the daily duties of investigating crime, knowing the boundaries of law, and figuring out who did what to whom, when, why, and how. Everyone else has to run to catch up to learn this.
Let me separate something about an “investigative mindset.” There is a difference between ‘investigating’ an alert or an artifact and that of investigating these things in relation to your overall objective in what you are being paid to do (ie: investigate a matter).
Side note: A non-LE examiner can become just as good and better than any LE-experienced investigator. It takes experience, application, mentorship, study, and reflection.
We let our competence slide
Digital (computer) forensics is a law enforcement invention. It simply is.
Yesterday, I spoke with an OG from the 80s who reminded me that early investigators treated electronic evidence as just another piece of evidence in an investigation. Today, we’ve turned it into a technical silo.
So, teaching this new field (“computer forensics”) was, and still is, mostly a technical education and not as one piece of the investigative function. Generations learned what hashing is but not taught how to tie disparate pieces of data to other pieces of data to a person or persons. I think the OGs assumed that the investigative mindset is a natural ability that doesn’t need training or education.
We had/have great investigators who developed and learned the electronic evidence aspect of investigations because they had to but only passed on the tech part of the investigative process. They/we created button pushers. AI will exacerbate this to the point of wrecked cases and careers.
A small part
As much as I would like to write about DFIR technical aspects, especially the really cool stuff I find (that everyone else probably already knew….), there is already so much available. But there is very little in the investigative or mindset aspect of this work. I am not advocating against taking technical training or writing about it (just the opposite!). I am in 1-3 training courses plus 1-3 conferences a year.
It’s why I wrote about this point in a book in 2013. Then wrote an entire book about one aspect of it last year. And why I’m writing another book that wraps it all together this year.
I am happy to see movement toward making scarily effective DF(IR) practitioners in the training and those who have purchased this book, were gifted the book, won the book in drawings, or earned it in my course . The total number is >5,000 who have this book in their hand with nearly a fifth of those spending a day in training with me. That’s a scary number of people who are adding a substantial skill to their abilities.
Comments:
My goal in every keynote, presentation, training, or book isn’t to flood you with information. It’s to give you something that shifts your path, whether by one degree or 180. I want people itching to run out halfway through just to put what they’ve learned into practice but staying glued to their seat because they know the next insight could transform them even more.
I have grown tired of information without transformation. We have oceans of information of more oceans of information. Literally overwhelming amounts of information to the point of not being able to see which is relevant.
I went through every comment in the mindset training course that I’ve given both live and recorded. I picked a few to make a point that taking a training course should transform you from one thing into another and not leave you forgetting on Monday what you learned on the previous Friday. Here are some of them that are meaningful to me.
———–
“To have an investigative mindset is to see what others cannot so that you can solve cases that no one else could.”
“ I’ve been doing it but never really conceptualized that I was doing it. ”
“Changing how I think about investigating. Has already provided benefits in my day job. ”
“You said “I want it to transform me, not inform me.” I think that’s something I’m going to apply to everything I’m doing day to day, not just professionally but personally as well. ”
“Thinking from Different Perspectives. This is usually something I have heard and tried to implore from time-to-time, however never truly valued the rational behind. I found the module covering this area truly depicts why this is truly valuable. ”
“To make training truly effective, it’s essential to personally invest in it by putting something meaningful at risk. This adds value to the effort, creating a psychological commitment that deepens focus and motivation.”
“There are no dumb ideas, only inspiration that comes from those ideas. Thinking outside of the box may not always bring out the exact answer, but it may bring about an idea that can get you on the right track in your investigations.”
“Learning the language behind all aspect of this course is what tied it all together.”
“For me, I think the most important aspect was realizing that good investigations aren’t a byproduct of fancy tools.”
“Ask questions until find a contradiction. Ask questions until find no contradiction.”
“The most important thing I found in the course was learning about myself and evaluating where I believe I am in the stages of competence.”
“I believe that this awareness marks a turning point in my career as a digital investigator.”
“Thinking deeply about the multiple levels of “peer review” from a colleague to academia and the importance of having the foresight to structure and detail investigations for the long haul.”
“Your case exists outside of the box” I think we as DF/IR investigators like to do things by ourselves. This is a huge mindset for solving cases.”
“I felt that the quote, “Be inspired by the dumb, terrible, and wild.”, was a much more impactful reminder to be open to change and consider all possibilities despite my initial reaction/thought. I also found the description of 7 levels of review was a great addition to this course.”
“Always humble yourself and know that you can always learn”
“A great reminder to take a step back, get your head out of the excel chart, and look at the “big picture.”
“To not lose the investigative mindset. It’s easy become just a button pusher when the focus is on back log and turn around times.”
We don’t need more oceans of information. We need investigators who transform information into cases that hold up in court. That’s the difference between a button pusher and a professional. That’s the line between wasted evidence and justice served.
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.
