Brett Shavers's Avatar

Brett Shavers

@brettshavers.bsky.social

Fell off a cliff. Swam with sharks. Dined with hitmen. Hung out with crime bosses. Bought and sold a ton of drugs. How the heck am I still here? DFIR USMC πŸš“

1,126 Followers  |  209 Following  |  4,721 Posts  |  Joined: 08.08.2023
Posts Following

Posts by Brett Shavers (@brettshavers.bsky.social)

Thanks for joining!

25.02.2026 06:20 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

On Feb 24 at Magnet's FREE virtual summit, @dwmetz.bsky.social and I will be talking about DF and IR, but not about "DFIR", if you know what I mean. magnetvirtualsummit.com/registration... #DFIR

20.02.2026 17:45 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image

Investigative Decision-Making in #DFIR.
Thursday. Feb 5, 2026. 11AM PT.
A 24-hour replay, and then it's gone.
You will see attribution in a totally different light.
www.suspectbehindthekeyboard.com/offers/fUKjJ...

03.02.2026 22:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Eventually, human-created content (audio, visual, written word) is going to become really expensive.

22.01.2026 04:12 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ“’ Publication du FACT Attribution Framework v1.0 pour relier preuves numΓ©riques et attribution humaine
πŸ“ Selon la notice de publication of…
https://cyberveille.ch/posts/2025-12-10-publication-du-fact-attribution-framework-v1-0-pour-relier-preuves-numeriques-et-attribution-humaine/ #DFIR #Cyberveille

11.12.2025 10:30 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

accurate

16.01.2026 06:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Sharing #DigitalEvidence shouldn’t slow a case down. With Portable Case, you can securely share case dataβ€”without needing full forensic tools.

Learn about some of the most powerful features of Portable Case and see how they can be particularly effective for investigators: ow.ly/9aZQ50XXnmt

15.01.2026 17:45 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

haha because true!

12.01.2026 14:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The DFIR Three-Body Problem Let me first interject first this so you don’t miss it - Magnet MVS 2026 The Magnet Virtual Summit 2026 is free (Feb 23–26). When you register, you’re entered to win a full year of Magnet Forensics tr...

The same people who pushed you for speed during the primary incident will ask you, with a straight face, why you didn’t preserve the things they now need.
www.linkedin.com/pulse/dfir-t... #DFIR

12.01.2026 04:53 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 2    πŸ“Œ 0
Preview
Week 02 – 2026 No sponsor this week. If your organisation is interested, head over here to find out more. Akash PatelCase Studies: Building Effective Timelines with Plaso (Log2Timeline) Christian Peterβ€œFar over t…

Week 02 - 2026 #DFIR
thisweekin4n6.com/2026/01/11/w...

11.01.2026 11:53 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Week 01 – 2026 Strengthen Your Identity Posture Before Attackers Find the GapsIn this cheat sheet, you’ll discover:β€’ The four highest-risk identity categories to remediate today.β€’ A step-by-step ISPM maturity mod…

Week 01 - 2026 #DFIR
thisweekin4n6.com/2026/01/04/w...

04.01.2026 10:31 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

What a world where we have to edit 3x more than usual to make sure we don't sound like AI, then eventually, we start sounding like AI in our writing...

It's almost to the point of having to intentionally plant errors in our writing, but eventually, AI will do that too to avoid sounding like itself.

30.12.2025 20:29 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Your DF/IR Tool Can’t Tell You Who Did It. FACT Tells You When You’re Allowed To. DF/IR doesn’t usually fail on the technical work. It fails at the exact moment someone gets impatient and confuses activity with identity, and then confuses identity with attribution. β€œThis account di...

Your #DFIR report is fine… until you name a person.
brettshavers.com/brett-s-blog...

14.12.2025 23:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Week 50 – 2025 Strengthen Your Identity Posture Before Attackers Find the GapsIn this cheat sheet, you’ll discover:β€’ The four highest-risk identity categories to remediate today.β€’ A step-by-step ISPM maturity mod…

Week 50 - 2025 #DFIR
thisweekin4n6.com/2025/12/14/w...

14.12.2025 11:47 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Tie the Act to the Actor β€” DFIR Soundtrack (Official Music Video) - YouTube Track 1: Tie the Act to the ActorTrack 2: Pattern of LifeTrack 3: Tracing Criminals OnlineTrack 4: Investigative MindsetTrack 5: CaseworkTrack 6: Order of Vo...

Soundtrack for #DFIR get into the mood.
www.youtube.com/playlist?lis...

09.12.2025 01:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

An Attribution Framework for #DFIR.
zenodo.org/records/1774...

08.12.2025 21:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I was on Darknet Diaries Ep. 165! Learn about dumb buildings with malware, how going to the dentist can get you in hot water, and that sharing breach information can you get buy in with software developers.
YouTube: https://twp.ai/9PYHxj
Or any podcast platform

06.12.2025 03:56 β€” πŸ‘ 13    πŸ” 3    πŸ’¬ 2    πŸ“Œ 0
Preview
Legal Unpacked E3: Proving who was holding the phone: Drafting warrants that explain the need for user attribution - Magnet Forensics Knowing what happened on a device is only half the storyβ€”proving who was behind the activity is critical.

On Dec 3, join us for our next episode of #LegalUnpacked, where Justin Fitzsimmons will focus on how to draft search warrants specifically designed to uncover evidence of user attribution.

Save your spot here: ow.ly/hRSM50XALPi

#DFIR

02.12.2025 16:20 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Week 48 – 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permiso’s CTO will cover:- How attackers moved from GitHub β†’ AWS β†’ Salesforce using stolen OAuth to…

Week 48 - 2025 #DFIR
thisweekin4n6.com/2025/11/30/w...

30.11.2025 11:02 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
DF/IR Investigative Mindset Course

If you want to develop how you think, not just what to click in DFIR work, this is it.

On-demand course, take it anytime over the next year.
One-day opportunity, Black Friday only.
Only 50 spots, because I’m only printing 50 signed hardcovers.

www.suspectbehindthekeyboard.com/mindset

#DFIR

24.11.2025 15:59 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

I fell in love at first sight.
Then I realized the timestamp was in UTC and I was mistaken.

21.11.2025 21:00 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

In this #CustomerStory, find out how Vigo County High Tech CyberCrime Unit is using #MagnetReview to get #DigitalEvidence into the hands of their investigators faster than ever.

Want to dive deeper into their story? Read the written case study here: ow.ly/3MQx50XtNI4 #DFIR

18.11.2025 21:35 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

You'd think, right?

14.11.2025 23:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

I spent two years in litigation hell. Trial was worse.

Thirty years of courtroom experience made me cocky, but the court fixed that.

This is the first and only time I talk about this case, as this is the case that made me think of quitting DFIR.

brettshavers.com/brett-s-blog...

14.11.2025 18:34 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image

In case you missed it last week, a new Arsenal Image Mounter (v3.12.331) has been released with a long list of improvements for #DFIR practitioners including Arm on Arm virtualization. You can see some highlights in our Insights article at arsenalrecon.com/insights/qui....

05.11.2025 16:44 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Fighting City Hall: DFIR Lessons from a Pro se Plaintiff

I once beat a 20-year DFIR forensic expert in court. Not because I was better, but because I had a $1,500 certificate. β†’ www.suspectbehindthekeyboard.com/fighting-cit...

03.11.2025 20:22 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

TBH. I enjoy seeing typos in anything online. It is a subtle hint that a human wrote it and made a human error with a human touch that AI cannot reproduce (yet).

The prose layout of perfected AI content with "em dashes" and "brutal truths" are tiresome and speak to no one.

03.11.2025 18:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Are you a #DFIR practitioner in the New England area? Want to see Arsenal Image Mounter’s new functionality in person? Contact us & let’s set something up soon so you can see Arm on Arm virtualization, AIM Remote Agent enhancements, & more! arsenalrecon.com

03.11.2025 14:17 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Week 44 – 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permiso’s CTO will cover:- How attackers moved from GitHub β†’ AWS β†’ Salesforce using stolen OAuth to…

Week 44 – 2025 #DFIR
thisweekin4n6.com/2025/11/02/w...

02.11.2025 11:27 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

Do you have a digital forensics workstation running Windows on Arm (WoA) in your lab yet? We have some thoughts about this towards the end of our latest Insights article at arsenalrecon.com/insights/qui.... Let’s discuss! #DFIR

02.11.2025 18:54 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0