Manage episode 516829503 series 3505865
This episode digs into the habits that actually hold up: learning from CTF wins and post-event reviews, exploring scholarships and Reno trainings that build technical muscle, and walking through expert-witness prep that turns courtroom stress into structured, confident testimony.
We’ll unpack Brett Shavers’ reminder that truth alone doesn’t win cases—procedure, documentation, and bias-aware methods do. Clear writing matters too; vague language can undermine solid work.
On the tools side, RabbitHole v3 now recovers deleted SQLite records and rebuilds them into query-ready databases—speeding validation and reporting without losing traceability. We’ll also demo the new Android Logical Extractor: pull device info, logs, and scoped chat data with hashes and ready-to-file PDFs. It’s ideal when consent is limited or full file systems aren’t on the table, and integrates cleanly with downstream workflows.
Throughout, we emphasize one idea: tools are abstractions. If you can’t explain how a result was produced or reproduce it, you don’t own the finding. That’s especially true with AI. Generative models are nondeterministic—useful when documented, risky when their prompts or scope stay hidden. We’ll cover prompt disclosure, reproducibility, and how to write about “deleted” data with precision: previously existing, marked deleted, not referenced—describe state, not intent.
If you’re serious about improving testimony, validating results, and adopting new tools without losing forensic footing, join us. Then share your take on AI prompts and language precision—what will you change in your next report?
Notes:
IACIS Scholarships
https://www.iacis.com/awards-and-scholarships/will-docken-scholarship/
https://www.iacis.com/awards-and-scholarships/womens-scholarship/
Training Opportunities!
IACIS Reno
https://www.iacis.com/events/in-person/reno-nv/
Free DFIR Test Images + Industry Tools to Analyze Them
https://www.dfir.training/downloads/test-images
New Blogs from Brett Shavers!
https://www.linkedin.com/pulse/theres-lot-more-trial-than-you-may-know-even-have-100-brett-shavers-br4sc/
https://www.linkedin.com/pulse/case-almost-made-me-quit-dfir-shouldve-news-brett-shavers-pie1c/
https://www.linkedin.com/pulse/i-when-digital-forensics-lost-its-soul-brett-shavers-otkec/
https://www.linkedin.com/pulse/end-dfir-again-dfir-training-ab5jc/
https://www.linkedin.com/pulse/how-wreck-your-report-affidavit-testimony-one-word-brett-shavers-qkyvc/
Free Webinar
https://www.suspectbehindthekeyboard.com/fighting-city-hall-dfir-lessons-from-a-pro-se-plaintiff
Rabbithole Update
https://www.linkedin.com/posts/rabbithole-dataviewer-sqllite-ugcPost-7384144022065274880-0d0D
https://www.cclsolutionsgroup.com/forensic-products/rabbithole
ALEX Release
https://github.com/prosch88/ALEX
https://github.com/RealityNet/android_triage
Chapters
1. Halloween Banter And Warm-Up (00:00:00)
2. What Alexis has been up to. (00:02:55)
3. CTF Highlights And Post-Event Practice (00:06:00)
4. Scholarships And Training Opportunities (00:08:15)
5. Expert Testimony Skills And Moot Court (00:12:20)
6. Test Images, Community Blogs, And Validation (00:19:30)
7. Bias, Procedure, And Surviving Court (00:24:50)
8. DFIR’s Soul: Foundations Over Checklists (00:28:40)
9. AI, Indeterminism, And Responsible Use (00:34:20)
10. The Word “Deleted” And Language Precision (00:39:45)
11. Tool Update: RabbitHole v3 SQLite Recovery (00:46:20)
12. New Tool: Android Logical Extractor Demo (00:52:00)
13. Meme Of The Week And Closing (01:02:10)
40 episodes