Coming in 2025: Placing the Suspect Behind the Keyboard: DF/IR Investigative Strategies, Volume 3
After dozens of rewrites, fresh starts, and scrapped chapters, I’ve finally locked into the version of Placing the Suspect Behind the Keyboard: DF/IR Investigative Strategies (Vol. 3) that I know needs to be written. And yes, you’ll be able to order your copy of it this year.
One of the easiest things in writing is making something sound complex, especially if it is already a complex topic! The real work is turning complexity into clarity and making it land so subtly that the reader feels like they’ve always known it. This is why the book has been taking so long….
This isn’t a checklist book. It’s not a shallow tool walkthrough. This is a book for investigators, working in digital forensics and incident response, across criminal, civil, and corporate environments. Volume 3 is built to be readable, practical, and strategic, something you can revisit throughout your entire career, no matter what tools or titles come and go.
Not Just Buttons. It’s Thinking & Working the Case
Many DF/IR books and training play it safe: “See Artifact A? Push Button B.” That works until Artifact F shows up, or M, and no one told you what Button Z does. Even both editions of my X-Ways Forensics Practitioner’s Guide live in that lane. Useful? Sure. Necessary? Absolutely. But it leaves a massive gap. This book dives straight into that gap with the part no one teaches, where tools stop helping and real investigative thinking begins. Not just the “how” to investigative, but “when” to investigate. It’s meant to help you think, adapt, and investigate better, not just follow a workflow that breaks when the tool breaks or you get stuck in a case.
This book focuses on how to approach cases: how to uncover hidden leads, make sense of fragmented artifacts, build attribution, and stay grounded in reality. Whether you’re digging into an insider threat, a missing child case, a breach investigation, or a messy civil dispute, this book will speak to that work. Some examples will mirror your current work, and others you will be able to translate into what you do.
From the Same DNA as The DFIR Investigative Mindset
If you’ve read The DFIR Investigative Mindset, you’ll probably find some familiar DNA here. That book was originally just going to be a small part inside the upcoming Volume 3. But it grew into something bigger and more important than just a side note. Volume 3 carries the same kind of weight. Every chapter is designed to spark thought, challenge assumptions, and give real value that can be applied in the field.
Real Tools, Real Investigators
I am working directly with forensic software developers to ensure DF/IR Investigative Strategies includes practical examples of tools in action, applied to real-life case scenarios. This book isn’t theory. It’s not just war stories. It’s a case-driven, strategy-focused walkthrough of what matters in DF/IR.

And I am not doing it alone Let me brag a little.
Lee Harris returns as a tech editor, bringing deep experience from both law enforcement and the cybersecurity private sector. A former engineer for Dell, IBM, and AMD, Lee spent nearly a decade specializing in Linux and AIX development before transitioning to law enforcement. His technical background became central to his work on narcotics and federal task forces, where he applied DF/IR skills to cases involving trafficking, money laundering, sexual assaults, and homicides. Now a full-time DF/IR investigator, he focuses on Internet Crimes Against Children as part of the Southern Texas ICAC Task Force, while supporting CID and Narcotics teams with digital forensics and strategy.
Joining him is Craig Bowling, as a second tech editor, bringing decades of high-level investigative experience. With a 23-year career in federal law enforcement and as the Founder and President of Digitas Consulting, LLC, Craig has led groundbreaking cases, most notably a 13-year post-9/11 investigation into Al Qaeda-affiliated groups that resulted in convictions for terrorism and espionage. His digital forensics expertise supported investigations into the Times Square and Boston Marathon bombings, and his background spans intellectual property protection, insider threats, CSAM, human trafficking, money laundering, and VIP protection for U.S. presidents and dignitaries.
Between the two of them, I’ve got a forensic dream team reviewing this book to make sure it hits hard, reads clean, and helps you investigate better.
Beta readers
Soon, I’ll be asking for a handful of beta readers for those who want early access and contribute to making this book even better. Beta readers get a front-row seat, early previews, and a big mention in the acknowledgments (and a signed, hardcover edition of the book!).
So no, Volume 3 isn’t out today. And it won’t be next month. But it will be online to order this year.
It won’t be like the DF/IR books you’ve read before. This book is for investigators, not button-pushers. If that’s you, I think you’ll get a lot out of it.
More updates soon.
– Brett
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.