Brett Shavers's Avatar

Brett Shavers

@brettshavers.bsky.social

Fell off a cliff. Swam with sharks. Dined with hitmen. Hung out with crime bosses. Bought and sold a ton of drugs. How the heck am I still here? DFIR USMC ๐Ÿš“

1,110 Followers  |  172 Following  |  4,710 Posts  |  Joined: 08.08.2023  |  1.8315

Latest posts by brettshavers.bsky.social on Bluesky

Post image

I was on Darknet Diaries Ep. 165! Learn about dumb buildings with malware, how going to the dentist can get you in hot water, and that sharing breach information can you get buy in with software developers.
YouTube: https://twp.ai/9PYHxj
Or any podcast platform

06.12.2025 03:56 โ€” ๐Ÿ‘ 12    ๐Ÿ” 3    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
Legal Unpacked E3: Proving who was holding the phone: Drafting warrants that explain the need for user attribution - Magnet Forensics Knowing what happened on a device is only half the storyโ€”proving who was behind the activity is critical.

On Dec 3, join us for our next episode of #LegalUnpacked, where Justin Fitzsimmons will focus on how to draft search warrants specifically designed to uncover evidence of user attribution.

Save your spot here: ow.ly/hRSM50XALPi

#DFIR

02.12.2025 16:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Week 48 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 48 - 2025 #DFIR
thisweekin4n6.com/2025/11/30/w...

30.11.2025 11:02 โ€” ๐Ÿ‘ 2    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
DF/IR Investigative Mindset Course

If you want to develop how you think, not just what to click in DFIR work, this is it.

On-demand course, take it anytime over the next year.
One-day opportunity, Black Friday only.
Only 50 spots, because Iโ€™m only printing 50 signed hardcovers.

www.suspectbehindthekeyboard.com/mindset

#DFIR

24.11.2025 15:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I fell in love at first sight.
Then I realized the timestamp was in UTC and I was mistaken.

21.11.2025 21:00 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

In this #CustomerStory, find out how Vigo County High Tech CyberCrime Unit is using #MagnetReview to get #DigitalEvidence into the hands of their investigators faster than ever.

Want to dive deeper into their story? Read the written case study here: ow.ly/3MQx50XtNI4 #DFIR

18.11.2025 21:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

You'd think, right?

14.11.2025 23:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

I spent two years in litigation hell. Trial was worse.

Thirty years of courtroom experience made me cocky, but the court fixed that.

This is the first and only time I talk about this case, as this is the case that made me think of quitting DFIR.

brettshavers.com/brett-s-blog...

14.11.2025 18:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

In case you missed it last week, a new Arsenal Image Mounter (v3.12.331) has been released with a long list of improvements for #DFIR practitioners including Arm on Arm virtualization. You can see some highlights in our Insights article at arsenalrecon.com/insights/qui....

05.11.2025 16:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Fighting City Hall: DFIR Lessons from a Pro se Plaintiff

I once beat a 20-year DFIR forensic expert in court. Not because I was better, but because I had a $1,500 certificate. โ†’ www.suspectbehindthekeyboard.com/fighting-cit...

03.11.2025 20:22 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

TBH. I enjoy seeing typos in anything online. It is a subtle hint that a human wrote it and made a human error with a human touch that AI cannot reproduce (yet).

The prose layout of perfected AI content with "em dashes" and "brutal truths" are tiresome and speak to no one.

03.11.2025 18:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Are you a #DFIR practitioner in the New England area? Want to see Arsenal Image Mounterโ€™s new functionality in person? Contact us & letโ€™s set something up soon so you can see Arm on Arm virtualization, AIM Remote Agent enhancements, & more! arsenalrecon.com

03.11.2025 14:17 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Week 44 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 44 โ€“ 2025 #DFIR
thisweekin4n6.com/2025/11/02/w...

02.11.2025 11:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Do you have a digital forensics workstation running Windows on Arm (WoA) in your lab yet? We have some thoughts about this towards the end of our latest Insights article at arsenalrecon.com/insights/qui.... Letโ€™s discuss! #DFIR

02.11.2025 18:54 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Video thumbnail

I got a little luv and a wink today.
www.youtube.com/watch?v=K5D1... @abrignoni.com @charpy4n6.bsky.social #DFIR

31.10.2025 00:08 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I'm charging my client 2x for making me miss this today. www.youtube.com/watch?v=K5D1... @abrignoni.com @charpy4n6.bsky.social #DFIR

30.10.2025 23:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Time is almost up to participate in our State of Enterprise #DFIR survey!

Complete the survey before Oct 31 to let us know your thoughts on the latest developments in DFIR along with emerging threats, operational challenges, and areas for improvement: ow.ly/6hV750XgYic

30.10.2025 20:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Keep in mind, AIM Remote Agent also runs on Windows on Armโ€ฆ so in addition to attaching WoA disk images & actual physical disks to AIM locally, WoA disks can be connected to AIM across a network when their hosts are booted safely with (e.g.) WinFE! #DFIR

29.10.2025 14:58 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Ever wonder what happens when a DFIR investigator ends up on the other side of the case file?

I fought city hall, literally, and learned DFIR lesasons no training ever covered.

www.suspectbehindthekeyboard.com/fighting-cit...

28.10.2025 18:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Ever try to out-document a team of Harvard attorneys?
Itโ€™s like fighting gravity with paper cuts.

Still, it works if you know the rules.

28.10.2025 02:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

DFIR comes down to one thing.

26.10.2025 21:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Week 43 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 43 โ€“ 2025 #DFIR
thisweekin4n6.com/2025/10/26/w...

26.10.2025 12:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Your Lab Is Ready: Free Evidence Samples + Free Software to Work Practice Cases. Yesterdayโ€™s release of the free forensic test images and CTFs took off fast. Downloads, shares, and discussions across social media havenโ€™t slowed down. Over 38,000 views in just 2 days. Goodness.Tha...

Need free or demo forensic tools to go through that data? Here you go!

www.dfir.training/blog/your-la...

24.10.2025 22:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Forensic Test Images & CTFs

If you got no plans for the weekend....here's this!

TERABYTES OF FREE FORENSIC TEST IMAGES AND HUNDREDS OF CTFs!
www.dfir.training/downloads/te... #DFIR #digitalforensics

24.10.2025 22:05 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Week 42 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 42 - 2025 #DFIR thisweekin4n6.com/2025/10/19/w...

19.10.2025 09:42 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
AI Assisted Forensics & Forensics on AI Systems at DFRWS APAC! ๐Ÿง  Papers on LLMs timeline analysis, investigating local AI apps, & new comms data tools. See the full program!

๐Ÿ‘‰ Reserve your seat: https://dfrws.org/conferences/dfrws-apac-2025/
#research #dfrws #DFIR #apac #digitalforensics #seoul

AI Assisted Forensics & Forensics on AI Systems at DFRWS APAC! ๐Ÿง  Papers on LLMs timeline analysis, investigating local AI apps, & new comms data tools. See the full program! ๐Ÿ‘‰ Reserve your seat: https://dfrws.org/conferences/dfrws-apac-2025/ #research #dfrws #DFIR #apac #digitalforensics #seoul

AI Assisted Forensics & Forensics on AI Systems at DFRWS APAC! ๐Ÿง  Papers on LLMs timeline analysis, investigating local AI apps, & new comms data tools. See the full program!

๐Ÿ‘‰ Reserve your seat: buff.ly/JV23sUN
#research #dfrws #DFIR #apac #digitalforensics #seoul #korea

13.10.2025 04:01 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Week 41 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 41 - 2025 #DFIR
thisweekin4n6.com/2025/10/12/w...

12.10.2025 11:22 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

#DFIR is facing a huge inflection point and no one knows that like those who are living it day in and day out.

Weโ€™ve just opened our survey for our State of #EnterpriseDFIR Report until Oct 31 and your insights are incredibly valuable: ow.ly/NBsa50X9eCv

09.10.2025 15:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Week 40 โ€“ 2025 Inside the Salesloft-Drift Breach: What It Means for SaaS & Identity SecurityIn this session, Permisoโ€™s CTO will cover:- How attackers moved from GitHub โ†’ AWS โ†’ Salesforce using stolen OAuth toโ€ฆ

Week 40 - 2025 #DFIR

thisweekin4n6.com/2025/10/05/w...

05.10.2025 08:09 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Introducing the new Magnet Nexus hybrid collection agent Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

The new #MagnetNexus hybrid collection agent gives #DFIR teams the flexibility to collect data from remote endpoints using either cloud-powered workflows with Nexus or on-prem workflows with #AxiomCyber, all with a single, lightweight endpoint agent: ow.ly/kKWr50X6gsW

03.10.2025 15:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@brettshavers is following 20 prominent accounts