Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

The Two Bulls of DF/IR: Why Charging Ahead Still Loses the Case

By Brett Shavers
May 17, 2025
0

There are two scenes in the movie Colors that every DF/IR professional could learn from.

Sean Penn plays the rookie in both scenes, eager, aggressive, charging downhill. In the first scene, Robert Duvall plays the veteran, calm, methodical, deliberate.

Your browser does not support the video tag.

The lesson? Anyone can rush in. The wise investigator walks, thinks, connects, and finishes the job right. Penn’s character eventually gets it at the end of the movie, but only after his mentor is killed.

DF/IR Has Its Share of Bulls
Fast with tools. Loud in meetings. Quick to click, collect, and report.
And just as quick to miss the mark where it matters most: investigative thinking. My point is that you can avoid the arc of pain felt by Sean Penn’s character by being deliberate.

You did everything right, but you still lost the case.

I say this often to make a point. Doing everything technically correct, a good case does not make. You can play a musical instrument 100% correct technically, but it might be noise you are making and not music. Same goes with DF/IR work.

Like, you may have created a good image. Cracked the password. Found the evidence. Followed protocol. Followed the law. .

But the case still fell apart. Why?

Because you didn’t think through the bigger picture:

  • You didn’t connect that artifact to a person.
  • You didn’t explain why the evidence mattered.
  • You missed the motive or behavior.
  • You wrote a technical report, not a story that holds up to scrutiny.

How This Applies in Incident Response (IR)

Incident Response isn’t just about how fast you respond. It’s about how well you respond. Rushing to collect logs, isolate systems, and generate reports can feel like progress, but if you don’t ask the right questions or connect the technical actions to business impact and human behavior, your IR effort falls flat.

  • You may identify lateral movement, but did you correlate it to actual access or intent?

  • You may isolate a machine, but did you confirm that was patient zero?

  • You may generate a flawless timeline, but does it explain how the breach affected the organization?

Just like in forensic casework, tools and speed mean nothing without thought, logic, and context. An IR responder who acts like the “charging bull” may lock down systems and wipe drives, but leave critical gaps in containment or misattribute the attacker’s goals.

In IR, the fastest response isn’t always the best one. The one that survives after-action review, executive scrutiny, and legal challenge; that’s the one that mattered.

Fix it

Here’s what to fix right now:

  • Think like the defense. If your logic doesn’t survive a peer review, it won’t survive court.
  • Write like you’ll testify. Add: “I did this because…” to every step.
  • Tie it to behavior. Artifacts don’t commit crimes, people do.
  • Ask questions. Not just what, but why, and who.
  • Tools are just tools. Investigators solve cases, using tools, not just use tools.

A tale of two investigators

Here’s a bit of DF/IR trivia:

At the same time that I was working undercover internationally and investigating, wiretapping, and negotiating literal airdrops of hundreds of kilos of coke, Brian Carrier was:

  • Writing the book DF/IR foundational book File System Forensic Analysis,

  • Building The Sleuth Kit and Autopsy,

  • And earning his PhD at Purdue.

  • And telling us then what we still haven’t fully implemented…

brettandbrian

The point:

We were both chasing truth. One in the field. One in the filesystem. Both solving problems creatively.

CyberWebinarThat brings me to an incredible event (at least incredible for me!).

I will be on Brian Carrier’s webinar next week on May 22. I hope that I can keep up! This is quite the honor, especially since Brian Carrier is everything you hope he’d be: approachable, insightful, and grounded. I met him years ago at a conference. Total class act.

Topic: Endpoint Investigations 2025: How to Find the Clues You Need
When: May 22, 2025
Where: Online ? [SIGN UP to join in on the conversation with Brian Carrier → REGISTER ]

Final Thought
There are a lot of bulls in this field (I was one!). Charging at everything. Clicking everything. Running as fast as they can but solving nothing.

The experienced investigator?
They slow down.
They ask better questions.
They connect facts to people.
And get it done legally, tactically, defensibly.

In DF/IR, fast is fragile, smart is solid.

Those who take this advice early will jump farther ahead faster and cleaner than their peers and even their seniors.

posterholmes

Also, shoutout to Brian’s podcast promo poster—he has me playing the Watson to his Holmes.


And you know what?
Watson did all the work anyway. So this tracks. ?

Can’t wait. See you on the 22nd.

Seriously, I can’t wait.

Also, seriously, Watson did all the work…


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
bsx
Previous

From Why to What: The Decline of Investigative Thinking in DF/IR

hindsight
Next

The Bitter Pill of DF/IR Hindsight

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    • X
    • LinkedIn
    • Bluesky
    • Instagram
    • Mastodon
    • FACT Attribution Framework
    • https://www.dfir.training
    • https://winfe.wordpress.com
    • https://xwaysforensics.wordpress.com

    My recent interview on a really good DFIR podcast (Parsing the Truth).

    • X
    • LinkedIn
    • Instagram
    • Bluesky
    • Facebook
    • Mastodon
    • YouTube
    Copyright 2026 — Brett's Ramblings. All rights reserved.