Brigs Profile picture
Jun 13 9 tweets 4 min read Twitter logo Read on Twitter
🔥 Hot take 🔥
If you only pump out tool reports because you don't have time to do actual #DigitalForensics the only person you are fooling is yourself.

Cases dropped or plead low because the examiner couldn't be inconvenienced with looking into a database. Image
Acquittals because the examiner never took the time to understand the artifacts so they could be properly understood by the jurors.

But wait, you say, I press that Generate Report button like it's going out of business and that has never happened to me.

To that I say... Yet. Image
Do we need to do this on all artifacts on all cases?
Of course not! But if the artifact matters YOU, the examiner, needs to verify that it is correct and if there is more to it than what the tool shows you. Image
We practice constantly to keep our marksmanship skills high for something that hopefully might never come to pass. That is a good thing.

Am I being lax on my digital forensics skill usage & development? Lax on something that affect cases, victims, & the accused on a daily basis? Image
As managers, are we really measuring the effectiveness of our programs?
Are we spreading the load fairly?
Are we striving to develop our folks beyond sending them to a class here or there?
Are we making sure we meet the high expectations of our citizens? Image
As managers, are awards & recognitions meaningful expressions of gratitude for outstanding work or have they become the new participation trophies? Image
And to be clear this is not really a tool problem.
Tools are great.
They focus our examination but what they produce is not the examination itself.
The tool doesn't testify, the examiner does!
Tool reports are not the data. The data is the data. Validate everything that matters. Image
With all this being said there are tons of resources available. Courses, educational orgs, peer groups, websites, tools & more to be the best examiners we can and should be.

I use tools but I never forget that I am the biggest tool. Digital forensics tool that is. So can you. 😜 Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Brigs

Brigs Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @AlexisBrignoni

Mar 8, 2022
#DFIR thoughts 💭
Expectations from paid multipurpose #DFIR tools (#4n6 focused):
🔂 Ingest multiple images at the same time or sequentially in a automated fashion. If the GUI doesn't allow it provide for a way to script it. Terminal / CMD line at a minimum.
1/
🪵 Support well know data sources natively in a report they gives context. Ex. If the field is called 'abcd' but the data in it is a Last Modified Timestamp call it as such in the report. For context tie the item to a particular app, service, or function if known.
2/
🖼 Provide general purpose viewers for well known file types. Bonus if there is a way to pick and choose keys and values for custom report generation.
3/
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(