Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

DF/IR Isn’t About Computers. It’s About Hunting Humans.

By Brett Shavers
September 13, 2025
0

Data is the trail. Humans are the quarry.

This is my opinion response to a solid LinkedIn post that asks a very important question: “How do we fix DF/IR so different paths don’t lead to different answers?” (paraphrased)

Humans first. Technology second.

Digital Forensics/Incident Response isn’t about computers. It’s about hunting humans. We seem to forget that we use technology to investigate other humans who used technology to cause or facilitate an event. That’s the top line item.

The bottom line items dive into a myriad of supporting questions, like “why are we investigating someone” and “what do aim to accomplish by this investigation?”  Everything below the top line item are supporting details (logs, packets, timelines, etc…).

Humans are practically unpredictable and never repeat themselves exactly. Which is why DF/IR is part science, part art, and entirely a craft. If this field was only analyzing computerized data, it would be a 100% scientific method.

Why Science Alone Doesn’t Work

Science is essential when we’re parsing data. Hypothesis, testing, replication, peer review; it works with disk images, memory captures, and logs. The scientific rigor of DF/IR ensures that the fundamental data are parsed and analyzed accurately

But science assumes repetition. And repetition is where DF/IR breaks if you are strictly and solely focused on the data. Science also doesn’t take human nature into account. Science can prove a file was deleted. But the investigator finds out why it was deleted (ie: motive and intent).

Humans don’t repeat. They improvise. They lie dormant for months before activating malware. They swap tactics mid-intrusion. They make irrational choices, sometimes out of ignorance, or stupidity, or mistakes, or intentionally as red herrings.

That unpredictability is why DF/IR isn’t just about computers. The scientific method is necessary but not sufficient by itself.

The DF/IR Spiderweb

I have always seen investigations like a spiderweb. As an example, in the criminal investigation world, imagine that there is a criminal organization in your hometown (there probably is in reality…). Many times in law enforcement, two investigators in different agencies unknowingly work the same criminal group from opposite ends. Eventually, they cross paths and realize they’re chasing the same target. Different paths, same truth.

DF/IR is not that much different. If you and I are given data to find the truth of a matter, there is virtually no chance that the way we will use the same tools, pressing the same buttons, running the same scripts, in the same order.  BUT, we should end up at the same place. Otherwise, two different conclusions to the one ‘truth’ means one of us is wrong. Nuances of course, but the conclusions should match. Differing paths are acceptable. Differing conclusions are not.

web

This is where art and science converge. The science ensures each step on the spiderweb is documented and verifiable. The art (specifically, the investigative mindset) is in deciding which threads are strong leads, which are broken, and which are distractions.

Why This Matters

Oversimplify DF/IR as only science, and you create false expectations for clients, courts, and companies. Reduce it to only art, and you undermine its credibility in front of those same audiences. Success requires both scientific rigor and the art of judgment.

DF/IR is a hybrid discipline. Science validates the steps. Art interprets the incomplete, contradictory, human side of the evidence. Ignore one and you risk being the one that is wrong. DF/IR is the craft of hunting humans through technology.

Fixing this DF/IR problem

My answers to the question of “How do we fix DF/IR so different paths don’t lead to different answers?” are to:

1. Stop preaching that DF/IR is only a science of data analysis. It is so much more than log parsing.

2. Focus on the human, not the machine. You’re not investigating “what the data did.” You’re after what the human did with the data.

3. Don’t stop at the machine. Finding out what happened on the machine is just one step toward the DF/IR objective. If you stop there, your work to that point might be technically competent, but it is incomplete.

4. Develop an investigative mindset. Tool skills are a part of DF/IR, not all of it.

PS: Ignore all of this if your job is data analysis for data analysis’s sake. That’s analytics, not forensics.

DF/IR is a spiderweb investigation centered around a human, having many paths in, but leading to one truth. Act like it.

———————

*Note: I’ve been told that it is too inciteful and ‘mean’ to say that DF/IR is for “hunting humans” but I’m telling you, that is exactly what DF/IR has always been, what it is in practice, what it is intended to do, and how it should always be seen as.


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
article
Previous

Lazy* police work results in arresting an innocent person.

Next

Every Monster Leaves Teeth Marks. Some Go to the Bone.

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.