Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

AI Will Have to Pry Judgment from my Cold, Dead Hands

By Brett Shavers
July 9, 2026
0

AI is not waiting outside your front door for permission. It is already inside your kitchen and eating your lunch. Now, what are you going to do about it?

Side Note: If you are the type of person who thinks a ‘polished’ AI report is a substitute for a thorough investigative process, stop reading. You’re already the person we’re testifying against.

AI is in the tools, vendor roadmaps, student work, examiner notes, attorney prep, courtroom, and the reports, whether people admit it or not. Some practitioners are using it carefully. Some are using it secretly. Some are using it like a second brain. More accurately, they are using it like it is their only brain. That last group is the problem. Criminals are using it too, but that is not as a serious threat as the practitioners who are not using their brain.

AI is not the threat by itself. Lazy reliance on AI is the threat. Weak practitioners hiding behind ‘confident’ output are the threat. Tool operators pretending fluent language equals reasoning are the threat. The practitioner who lets AI take the wheel of a forensic conclusion and then signs the report is not progressive, innovative, or ahead of the field. That practitioner is a walking liability. And the organization pushing AI on that practitioner without controls, training, validation, or accountability is helping load the gun.

The argument is no longer whether AI belongs in digital forensics. That argument is settled because it can help to organize, compare, summarize and even explain syntax. It can make a good practitioner faster. But it can also make a weak practitioner look competent right up until the case gets serious and decisions are questioned. That is the danger.

Cyber Triage is one public example of where this is going. Responsible vendors should be testing AI, limiting it, documenting it, and building controls around it before practitioners use it in the shadows with no validation, no scope, no method, and no notes. Brian Carrier exemplifies the risk-taking-scientist that innovates and motivates. His recent online AI Challenge was really cool having had some big names (Heather Barnhart, Filip Stojkovski, Alexis Brignoni, Eric Capuano) in on the online talk. *By “big names,” I mean “original sources” of information that impacts our work.

https://www.linkedin.com/posts/carrier4n6_dfirai-challenge-winners-the-results-activity-7480725627525070849-BGK- 

One tip I give to the DFIR newbie and the dinosaur: Pay attention to the names in this business who are taking risks, and putting their work and ideas in public to be tested and debated, because now, more than ever in the past, you have direct access to hear them live. You can listen and interact with the source, and that is a world of difference than reading a book or hearing it secondhand from someone else.

Uncontrolled AI use can end your career

The risk is not that vendors are experimenting with AI. The bigger risk is uncontrolled practitioner-level AI use inside real casework where nobody can tell what was human judgment, what was machine suggestion, and what was a grammatically correct but bad assumption. That is where DFIR gets gutted.

Ovie Carroll has already named the next version of the old SODDI defense: SAIDI, or “Some Artificial Intelligence Did It.” Ovie described a controlled test on a Windows 11 system using an autonomous AI agent, and the lesson for DFIR should be obvious to anyone not asleep at the keyboard: attribution just got harder.

https://www.linkedin.com/posts/oviecarroll_ai-did-it-forensics-must-not-outsource-judgement-ugcPost-7477080800786714624-HaQg/

Digital forensics has always been good at technical identification. We can show what happened, on what system, under which account, at what time, with which artifacts. That matters. That is the foundation. But technical identification is not person-level attribution. “Alice’s account did X” is not the same as “Alice did X.” If you cannot explain the bridge between those two statements, you do not have attribution. You have a guess and that shortcut has always been dangerous. AI makes it worse.

Placing the suspect behind the keyboard never only meant proving the suspect was physically sitting there at the exact second an action completed. A bomb can be set at noon to detonate at 2:00 p.m. The bomber may be ten miles away when it detonates. The question is not only whether the suspect was standing next to the bomb when it went off. The question is who, when, where, why, and how the person set the conditions that caused the later act. The same logic applies to AI agents.

If an AI agent modifies a file, moves data, drafts text, or executes a command later, the practitioner must work backward. Who launched the agent? Who configured it? Who authenticated the account? Who supplied the prompt, workflow, script, rule, timer, permission, or authorization? Who had motive, access, opportunity, knowledge, and control? The human may not have been behind the keyboard at the moment of execution.  The “who” could one or more persons at one or more times at one or more locations. Attribution is hard when you know what you are doing. It is virtually impossible if you don’t.

The human may have been behind the keyboard at the time of delegation. That distinction is going to matter in reports, affidavits, warrants, civil disputes, internal investigations, criminal prosecutions, and testimony. If your method cannot handle that distinction, your method is already behind.

This is why FACT matters. The FACT Attribution Framework exists because device activity, account activity, session activity, and person-level conduct are different layers. Collapsing those layers into one sentence because the report reads cleaner is not methodology. It is closer to being malpractice. FACT forces the practitioner to consider alternative actors and competing explanations, including another user, remote access, malware, automation, scheduled tasks, shared credentials, misconfiguration, and now AI agents.  This framework is only for attribution, but in digital forensics, attribution is everything.

https://doi.org/10.5281/zenodo.17745958

AI will agree you off a cliff

OpenAI publicly rolled back a GPT-4o update in 2025 because the model became overly flattering and agreeable, often described as sycophantic. OpenAI later explained that the problem was not only flattery. The model could validate doubts, fuel anger, urge impulsive action, or reinforce negative emotions in ways the company did not intend. Investigators should understand exactly why that matters.

A sycophantic AI in DFIR is like an overly helpful witness who wants to give you an answer even when the honest answer is, “I do not know.”

https://openai.com/index/sycophancy-in-gpt-4o/

That kind of AI can follow your theory too eagerly. It can validate your weak suspicion. It can help you build a story around evidence that only supports a possibility. It can sand down the doubt until the report sounds certain when in reality, it is not. That is how casework and careers get wrecked.

At each step with AI, the practitioner feels faster, thinks less, and believes themselves to be more productive and effective. Speed begins to feel like judgment.

The attraction of easy tool use is not just laziness. It is biology. Thinking burns energy, takes time, creates errors, and requires accountability on every decision. AI, automation, and push-button tools ask for almost nothing: stay awake just enough to click a button, accept the output, and call it work. That is seductive because it feels productive. It feels modern and like progress. But sometimes it is just the brain taking the shortest path to the nearest easy answer. AI fools you.

AI also creates a learning problem. Used well, it can help a practitioner learn faster. Used badly, it becomes a prosthetic brain for someone who never built their brain muscle. A 2025 study in Societies examined AI tool use, cognitive offloading, and critical thinking. It reported that cognitive offloading significantly mediated the relationship between AI use and lower critical thinking skills. That does not prove AI makes people stupid. But it supports a basic warning: if you keep delegating thinking, do not act shocked when your thinking gets weaker.

Skills not exercised will fade. If AI interprets for you, you practice less interpretation. If AI remembers for you, you practice less recall. If AI writes your reasoning, you practice less reasoning. If AI builds your conclusion, you practice less judgment.

There is a difference between using AI after you understand the work and using AI so you never have to understand it. One is assistance. The other is dependency. If you do not know the DFIR work and what the answer should be, you will not know when AI is wrong. You will not catch the bad assumption, the missing artifact, the fake certainty, the broken timeline, the unsupported identity leap, or the conclusion that sounds good but cannot survive questioning. That is not learning.

This is where the DFIR Investigative Mindset matters. The investigative mindset is not a motivational poster or a soft skill tacked onto the end of a tool class. It is the part of casework that keeps a practitioner from becoming a screenshot collector. It includes critical thinking, curiosity, skepticism, legal awareness, hypothesis testing, bias control, evidence interpretation, and judgment.

Recently, I had a really good conversation with Becky Passmore and Stacy Eldridge about the DFIR Investigative Mindset on their Parsing the Truth podcast. Take a listen on your way to work. That workday will be more productive for your casework mindset. It’s better than whatever podcast you’re half-ignoring right now because it’s useful.

https://youtu.be/F1pc7SmI1s8?si=M-F5CIsbiesUB_V9

Technical skill matters and nobody serious says otherwise. But technical skill without investigative judgment is a race car without wheels. Loud engine and cool paint job, but will make it over the finish line, let alone win a race.

The field teaches tools, artifacts, and tech skills with seriousness. We need all of that. But we do not teach thinking with the same force. Maybe there is a slide about bias or maybe a paragraph about critical thinking. Maybe an instructor says “do not jump to conclusions” before everyone goes back to the demo. That is not enough. This cruelly gives false confidence in that one has been “educated in thinking.”

The field often assumes thinking comes free with experience. It does not. Experience can sharpen judgment just as much as it can harden bad habits. A practitioner can spend ten years confirming the first theory that felt right and call it expertise. That is not expertise. That is repetition x10 years of bad experience thinking it counts.

The AI Reckoning

AI will expose the DFIR frauds, the lazy DFIR examiners and analysts, and those simply cull data. It will make them look better first because it’s fast. It will clean up the writing and organize the notes. It will fool them with the illusion of sharper reasoning. Then one day the conclusion will get questioned, and the examiner will have to explain what was observed, what was inferred, what was assumed, what was tested, what was rejected, and why the conclusion is proportionate to the evidence. That is where the button-clicker runs out of buttons.

This is why I am developing AIMED. AIMED is not a tool workflow. It is “aimed” at being a cognitive framework for reasoning under uncertainty: Assess. Interpret. Model. Examine. Decide. The point is to make thinking visible before the decision gets put in report language. It’s the OODA Loop for DFIR, an articuble framework for judgment.

Article content
Want a sneak preview of the framework? All I ask is your opinion and I’d love to hear it! Comment to let me know and I’ll send it.

Judgment is what AI cannot be allowed to touch. AI cannot take responsibility for a conclusion as AI is literally and legally unaccountable. Your name goes on the report. Your name goes on the declaration. Your name goes on the affidavit. Your name goes into testimony.  Not the AI model’s name. Yours.

That should bother anyone getting too comfortable with DFIR+AI. No one is coming to save you as to why you relied on an AI summary you trusted.

So yes, use AI. Use it aggressively where it helps. But keep it in its lane. Do not let AI decide what happened or who did it. If you are waiting to be trained on DFIR+AI, you are missing the train right now to get ahead of the wave that will crush you.

The future of DFIR is a real fight of judgment versus convenience.

AI can help DFIR while at the same it will expose frauds. It will expose the examiner who never learned attribution. It will expose the report writer who confuses good grammar with reasoning.

It will expose the practitioner who wants the title without the responsibility.

I say “good.”

Bring it the hell on now before we really get deep with DFIR+AI, because that day is coming fast.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

AI Can Build a DFIR Course in Minutes. So What Are You Really Paying For?

Next

Your DFIR Tools Are Not the Problem. You Are.

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.