Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

AI in the DFIR Crosshairs

By Brett Shavers
October 17, 2024
0

aicrosshairsAI in the DFIR Crosshairs: How AI Fits into Digital Forensics

One of the most important rules in science and in Digital Forensics and Incident Response (DFIR)—is repeatability. This means that if you follow the same steps under the same conditions, you should get the same result every time. But with the rise of AI tools, like ChatGPT, this rule gets a little tricky. Ask an AI the same question twice, and you might get two different answers. 

That unpredictability raises concerns for forensic investigations, where reliability is critical. Still, AI is already embedded in many of the tools we use today. So, what’s the deal? How can AI strengthen our investigations without risking our credibility or wrecking cases?

Oh yeah, just ask AI if AI is unfit for the scientific method. 

AISAYSNO

What AI Is Doing in DFIR Right Now

Most of the AI we see in DFIR tools is straightforward. It helps with tasks like sorting through vast amounts of data, finding patterns, and spotting things that seem off. For example, AI can categorize images by their content or help filter through files faster than you could manually. This is easy enough, but you still must manually (visually) go through each file to identify what is evidence.

But here’s the critical part: AI isn’t making decisions for you. It’s just organizing the data and pointing out things that might be useful. As the investigator, you still decide what’s relevant, what could be evidence, and how it fits into the bigger picture. In that sense, AI is just another tool in the toolbox—like keyword searching or file-type filtering.  You validate all your other tool’s findings, right?

AI as a Co-Pilot, Not the Pilot

Think of AI as a co-pilot, not the pilot. A co-pilot helps the primary pilot navigate, provides support, and assists in making the flight smoother and more efficient. But the co-pilot doesn’t make the final decisions about landing the plane—the pilot does.

copilotimage

Similarly, in DFIR, AI helps you navigate through massive datasets and can point you to potential evidence or patterns, but you are still the decision-maker. You must verify what AI brings to your attention, much like a pilot verifying all the instruments before making a critical decision. Relying on AI without human judgment can lead to a ruined career or, worse, injustice with a bad case.

The Risks of Relying Too Much on AI

As AI tools become more advanced, the temptation to rely on them for more decision-making is a genuine concern. This is particularly true with conversational AI like ChatGPT, which can produce insights or suggestions based on the data it’s given. However, any DFIR investigator or legal professional relying solely on AI’s output without personally verifying the results runs the risk of undermining the integrity of their work.

Misuse of AI in casework could taint the entire investigation, leading to flawed outcomes in legal proceedings. Even worse, a single misstep in a high-profile case could cast doubt on the legitimacy of using AI in DFIR altogether, causing ripple effects across the industry and hindering the development of more advanced AI-driven tools.

How AI Fits into the Scientific Method in DFIR

DFIR is both science and art. The science part is following proper forensic methods so your findings hold up in court. The art part is pulling everything together to tell the story of what happened based on the facts derived from the scientific method. When you bring AI into the mix, you must apply the scientific method to whatever AI gives you and validate it.

method

At this point, there aren’t any official rules for using AI in DFIR, but we should be thinking about setting some guidelines. AI can help suggest ideas or point out things we might have missed, but it’s up to us to validate and corroborate the AI’s findings using the scientific method. Without this rigorous process, we risk relying on AI as a “black box” solution that we cannot fully understand or trust.

Using AI Safely in DFIR

The safest way to use AI in your investigations is to treat it as an idea generator. Ask it for suggestions or let it help organize your data, but don’t take its results at face value. Think of it this way, if I tell you something and AI tells you something, don’t trust either of us. Check everything out for yourself.

In the end, you should be able to say, “I used AI to help find some leads, but I validated each one and only moved forward with the ones that checked out.” Whether your ideas come from AI or a colleague, they don’t really matter unless they can be proven and backed up with solid evidence.

AI is here to stay, and it’s already changing the way we work in DFIR. But like any tool, it’s only as good as how we use it. If we stick to solid forensic principles and make sure AI’s suggestions are backed by real evidence, we can use AI to make our investigations faster and more effective without risking our credibility.

Consider the following scenario that I gave ChatGPT:

atfault

Is ChatGPT correct? Do you now believe that you would be 100% legally accountable in this scenario? Or, would you further investigate this scenario by speaking with legal counsel before landing on a belief? Validate. Validate. Validate.

As a real-world example with personal knowledge, I know of a detective from an outside agency who called a detective in my agency. The outside agency detective said there was probable cause for a search warrant and provided information to the detective in my agency.  My agency’s detective wrote and served that search warrant.

Later, we found that the outside agency detective had not verified the information, and he even denied that he said there was enough evidence for a search warrant. Who do you think was at fault? 

AI is no different. Verify it. It is your name on the case.

AI in the DFIR Crosshairs: How AI Fits into Digital Forensics

One of the core principles in both science and Digital Forensics and Incident Response (DFIR) is repeatability. In forensics, if you follow the same steps under the same conditions, you should get the same results every time. But with the rise of AI tools, like ChatGPT, this standard becomes a bit tricky. Ask an AI twice, and you’re likely to get two different answers. And even AI will tell you that itself.

This variability raises some significant concerns for forensic investigations, where reliability is non-negotiable. We already rely on AI in many of the tools we use today. So how do we use AI to strengthen our investigations without damaging our credibility or, worse, wrecking a case?

What AI Is Doing in DFIR Right Now

Currently, most of the AI we see in DFIR is straightforward. It helps us manage huge amounts of data, find patterns, and detect anomalies. AI can categorize images, sort through files, and highlight things that stand out—all faster than you can manually. But there’s an important distinction to make: AI isn’t making decisions for you. It’s just organizing data and pointing out areas that might be worth a closer look.

Think of it like using a keyword search or file-type filter. It narrows down the data, but you still must comb through it, figure out what matters, and connect the dots. AI can hand you potential leads, but you’re still the one making the call on what is and isn’t evidence.

So, if you’re using AI and trusting it completely without validating its results—just like any other tool—you’re asking for trouble.

AI as a Co-Pilot, Not the Pilot

When thinking about AI’s role in DFIR, imagine it as your co-pilot, not the pilot. The co-pilot helps you navigate, offers support, and makes the process smoother. But it doesn’t land the plane—you do. Similarly, AI helps you sift through massive datasets, point out potential patterns, and identify anomalies. But you’re still the investigator, and you must verify everything it brings to your attention, just like a pilot checks instruments before making a critical decision.

Relying on AI without verifying its results is a recipe for disaster. At best, it could damage your credibility. At worst, it could ruin a case and lead to serious injustice.

copilot

The Risks of Relying Too Much on AI

As AI tools become more sophisticated, the temptation to rely on them to make decisions grows. This is especially true for conversational AI like ChatGPT, which can offer insights and suggestions based on the data it’s given. But here’s the deal: any DFIR investigator, or any legal professional for that matter, who depends solely on AI’s output without personally verifying the results is walking a fine line.

If you misuse AI in casework, you’re not just risking one investigation—you could taint the entire process. That ripple effect can hurt the reputation of AI tools in forensic investigations and slow down the adoption of more advanced AI-driven techniques.

AI and the Scientific Method in DFIR

At its core, DFIR is a combination of science and art. The science side involves following proper forensic methods so your findings stand up in court. The art is pulling together those findings to tell a coherent story based on facts and evidence. When introducing AI into the equation, you must apply the scientific method to anything AI gives you. That means validation, testing, and corroborating AI outputs like you would with any other evidence.

There aren’t formal guidelines for using AI in DFIR right now, but there should be. AI can help spark ideas or point out things you may have missed, but it’s your job to verify those findings. Without a rigorous validation process, relying on AI can feel like using a “black box” you don’t fully understand or control. And that’s a dangerous place to be.

Using AI Safely in DFIR

The safest way to use AI in your investigations is to treat it as an idea generator. Let it help you organize data and surface leads, but don’t take anything at face value. Think of it this way: If I tell you something and AI tells you something, don’t trust either of us. Check it out for yourself.

In the end, you should be able to say, “I used AI to help me find some leads, but I validated every one of them and only moved forward with the ones that checked out.” Whether your ideas come from AI, a colleague, or a gut feeling, it doesn’t matter unless they’re backed up by solid, defensible evidence.

Real-World Example: Responsibility in Action

Let me give you a real-world example to drive this home. I know of a case where a detective from another agency called one of our investigators and said they had probable cause for a search warrant. Our detective wrote up an affidavit and executed the warrant based on that conversation.

Later, it turned out the information the outside detective provided wasn’t verified, and the detective even denied saying there was enough evidence for probable cause. So, who’s at fault?

It’s the same situation with AI. You sign your name to the report. You present the facts. You uncover the truth. You are responsible if you fail to verify the information, whether it comes from another detective or AI. Support staff or tools might be involved, but ultimately, only one person swears to the facts in an affidavit: You. 

Final Thoughts

AI is here, and it’s already changing the way we operate in DFIR. But it’s like any other tool in the forensic toolbox—it’s only as good as how you use it. If we stick to solid forensic principles, apply the scientific method, and make sure AI’s suggestions are backed up by evidence, we can use AI to enhance our investigations without risking our credibility or the integrity of our cases.

In the end, AI is an assistive tool, not the investigator. And in DFIR, you are the investigator. Don’t let AI—or anyone else—take that responsibility away from you.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

Trust me. I’m an Expert.

2025
Next

DFIR Investigative Strategies

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.