Brett's Ramblings

ChatGPT destroys the planet
Brett Shavers
Digital Forensics
I read an article today about a “writer” who used ChatGPT to write their book. A little further digging found that apparently, there are hundreds of books on Amazon that are written by AI and marketed as such. I can only imagine how many “writers” that are not disclosing the content written by AI in the books.   Funny enough, the writer of thi...
DAIR: Digital Analysis/Incident Response?
Brett Shavers
Digital Forensics
Pure luck? One day in patrol, my district partner and I were having coffee on break (imagine that…cops were having coffee…) while I was watching a known high-crime corner. I spotted a drug deal, actually several and said "Look, a drug deal” while partner asked, "Where?" Pointing directly, I replied, "Right there." I went over, and soon enough, we h...
“I am neither a digital forensics practitioner nor do I play one on television.”
Brett Shavers
Digital Forensics
TL: DR (this is the important part) One day, your DFIR profession may be negatively affected by your behavior in your private life, judged by a third party’s ethical standard. And your creativity to solve cases will be restricted by only being allowed using approved processes. Oh yeah, this external party making judgment won’t be DFIR practitioners...
The DFIR Investigative Mindset
Brett Shavers
Digital Forensics
    We use cutting-edge tools to uncover the story of what happened on computing systems. This is awesome! But we often ignore attribution, which is difficult. I understand. Digital forensics alone can hardly identify the suspect (sometimes it does!). Forensics gives us the clues, but it's the DFIR investigative mindset that...
DFIR is a mindset, not a skillset.
Brett Shavers
Digital Forensics
I recently posted a webinar on the DFIR Investigative Mindset, which is a snippet of a program I’ve occasionally taught internally over the past years.  I distilled a major component of the DFIR Investigative Mindset for this post into seven words: DFIR is a mindset, not a skillset. That is pretty much all you need to know about getting into D...
This is an evidence storage device.
Brett Shavers
Digital Forensics
Mistakes in any career field are inevitable. And much like car accidents, the severity of a mistake can range from a simple ‘oops’ to something more disastrous and permanent.  In the DFIR field, errors and mistakes will usually fall in the more serious of the bad results because a DFIR investigation typically involves lif...
In this thing of ours, the world of digital forensics, there is one thread that ties us all together
Brett Shavers
Digital Forensics
In this thing of ours, the world of digital forensics, there is one thread that ties us all together: the truth. All else is malleable.  Processes improve. Technology changes. Laws are added. Training morphs.  But the thing that remains unchanging is the truth.  We must speak it. We must live by it.  We must defend it. I know th...
The truth hurts. But the other option is worse.
Brett Shavers
Digital Forensics
In 2013, I wrote a book and throughout the book, wrote of telling the truth as it relates to your investigations. One area of telling the truth that I should have covered more, was ensuring that your team also tells the truth. The only statement in this book that skims this advice is that of not letting someone else make mistakes IF YOU KNOW o...
I sued. It sucked. But I won. It still sucked, tho.
Brett Shavers
Digital Forensics
I recently finished a lawsuit, and it was the most time consuming process I’ve ever experienced.  I have been involved in lawsuits for about 30 years as a defendant, lay witness, expert witness, and now as plaintiff.  Let me break each of these down for you first: As defendant:  I have been named in several lawsuits as a p...
Like math, talking to people in DFIR is hard. But here is a tip.
Brett Shavers
Digital Forensics
I have a good friend who is a natural with people.  He makes you feel like you have known him all your life after having just met minutes prior.  I am totally not like that. Seems like many in this computing industry as a whole are generally not extroverted, and that impedes our personal and professional growth. Yes, there are plenty of e...
There I was, just getting ready for work....
Brett Shavers
Digital Forensics
I sometimes carried up to 10 cell phones at one time for work. Each phone had its own purpose. One or two of these phones were used for case calling criminal targets in one country. Another phone was used to call another target in a different country. One was used to call informants. Others used to call targets in different investigations locally. ...
The spark of a book
Brett Shavers
Digital Forensics
I believe that most every book begins by seizing upon the spark of an idea before the idea fades.  This book, the one that Mark Spencer and I are writing, is no different. But first, let me give credit where credit is due, for I will never take the spotlight from another who deserves it.  Mark is an extraordinary forensicator (I actually ...
That sliver of space between first and second place in the DFIR space
Brett Shavers
Digital Forensics
TL:DR The difference in skill and knowledge between the very best and everyone else is small but requires so much effort to obtain that most people don’t even try or quit trying. This post is intended to kick you in your butt.   A little bit more detail If you watch sports, a common theme is that wins are by thin margins of time or points, som...
A forensic book is not just a forensic book if you do forensics.
Brett Shavers
Digital Forensics
I just published the second edition of the X-Ways Forensics Practitioner’s Guide. If you use X-Ways Forensics in any sense of running the application, you should get this book.  I can’t say that any stronger than that.  But this post is not about the X-Ways book, at least not completely. If you want to see the book or buy it, ...
Been a long time coming, but now comes the second edition of the X-Ways Forensics Practitioner's Guide.
Brett Shavers
Digital Forensics
The short story: The book is done! Get it at $20 off during the 100-hour book launch coming up in a few days (but only a limited number of books will be sold in the 100-hour book launch). Free shipping in the USA. International is available to ship, but not free..sorry… The book will afterward be available for purchase on Amazon (and elsewhe...