, 9 tweets, 2 min read
My Authors
Read all threads
Let's talk about forensic evidence specialties. If you work on the blue team side, you probably feel a lot more comfortable with either host or network evidence. As a matter of fact, vote in this poll and tell me which one. 1/
The evolution of the industry dictated these specialties early on. AV beget host based tools, IDS beget net based tools, and encryption + other things beget more host based tools. Your specialty is likely based in some part by when/where you started your career in this cycle. 2/
Here's the thing though -- you can't be a great investigator without expertise in both host and network-based forms of evidence. It's a false dichotomy that is mostly perpetuated by the way training orgs segment knowledge and the history of the industry. 3/
We don't rely on course programs too much in our field. Instead, we rely on ad-hoc courses to fill gaps. Training companies know this and they cater to it, which often means a lot of artificial segmentation of knowledge. 4/
On the academic side, no thorough skill assessment of the digital forensic analyst role exists. So, degree programs are often unbalanced and rarely cover evidence realms in meaningful or thorough ways. 5/
It's reasonable to segment coursework based on evidence types, but it is not reasonable to only take one of those courses or ignore certain types of evidence. You've got to take the full gamut. 6/
I break evidence up into five categories: network, host, memory, threat intel, and friendly intel. You need a baseline knowledge in all of these to be really good. 7/
Evidence is the thing that helps us answer the investigative questions we ask. The more you know about varying evidence types, the more diverse questions you can ask AND answer. 8/
An analyst is only as good as their ability to ask and answer questions. That's how you build a timeline and make decisions. Learn to ask questions, then learn evidence types to broader the scope of your question asking abilities. 9/9
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Chris Sanders

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!