AI-Assisted. Human-Led. Why DFIR Needed Its Own AI Frameworks. 

If we have crossed paths at a summit, in a classroom, or in an email thread over the past year, there is a good chance you asked me some version of the same question: can I actually use AI in my investigations, and if I do, will my findings hold up? Do we think AI will replace us? Is AI a joke? I got asked so many times that I stopped answering one person at a time and put the answers into two frameworks instead. 

They are the Digital Forensics + AI Investigations Framework and the Incident Response + AI Investigations Framework, both free from SANS. The digital forensics framework aligns with SWGDE Best Practices for Digital and Multimedia Evidence and walks the full forensic lifecycle, from identification through reporting and presentation. The incident response framework maps to the phases IR teams already work, preparation through lessons learned. Same philosophy in both, tuned to how each discipline actually operates. 

Why build these at all? Because AI adoption in DFIR is already happening, with or without formal policies. Teams are using it to triage evidence, correlate logs, and draft timelines right now, and most of them are doing it without governance models, validation standards, or defensible practices behind them. That gap is the problem. Nobody wants to be the examiner explaining on the stand why an unvalidated AI conclusion made it into a report. We needed risks associated to AI integration in formats we understand. 

The biggest danger I see is not AI. It is people trusting it too much. AI output sounds confident whether it is right or wrong, and as that assertion of confidence climbs, the risk compounds if you have no guardrails. So, the frameworks start from a principle I will keep repeating until everyone is sick of hearing it: AI is a force multiplier, not a replacement for trained analysts and examiners. It accelerates work. It does not own conclusions. The human examiner is always the authority. 

To make that practical, both frameworks organize every phase of an investigation into risk levels with explanations. Human in the loop means you approve AI actions before anything executes, which is where containment approvals, and several phases of digital forensics live. Human on the loop means AI acts while you monitor in real time and can step in, which fits detection, triage, examination, and analysis in incident response and some digital forensic cases. Human over the loop is governance, where AI operates inside boundaries you defined, which covers areas like preparation, policy, and identification. Each phase also gets weighed against two kinds of risk: reversibility (can this action be undone if it touches evidence or systems?) and accountability (does this decision require a human to own it legally and professionally?). Keep in mind, AI in DFIR is not one size fits all investigations. Digital forensics is not the same as incident response, per se. Every case is different. Every lab is different. As with all tools, AI is not plug and play. 

Some lines do not move no matter how good the tools get. AI never independently determines attribution. AI never makes legal or evidentiary conclusions. Testimony and final reporting belong to human experts, because expert witness credibility cannot be transferred to a system. And every AI-assisted action gets documented, because transparent records of where and how AI was used are what make an investigation defensible. The boundary I want tattooed on the community’s collective brain: AI cannot put a human behind an artifact to prove attribution. Your tools can only get you so far. It is still your job to determine how the data got there and to stand behind every line of your report. 

I am not anti-AI. There are places where it genuinely helps, and the frameworks call those out too: timeline reconstruction across large datasets, evidence triage and scoring, flagging additional evidence sources for the examiner, and report drafting with a human authoring and signing off. Start with the low-risk use cases, build your governance, then expand. That order matters. 

One more thing, and anyone who has read this blog for a while knows this caveat is coming. These are living documents. AI technology, legal precedent, and industry practices are all moving, and the guidance will move with them. Always confirm the content is current before you rely on it. And if you think a line is in the wrong place, tell me. If we were all the same, this would be a boring community, and these frameworks get better the same way everything in DFIR gets better: practitioners pushing back and conducting new research! 

Both frameworks are free to download here: sans.org/go/ai-assisted-human-led-trusted-investigations 

A special thanks to Ovie Carroll, Josh Hickman, Steve Anson, Taz Wake, Josh Wright, and David Bianco for their input and investment into both frameworks!  

Grab them, put them in front of your team, and mark-up what you would change. Remember, you need foundation skills or you will be doing yourself harm. Know the data and remain current. See you in class soon! 

Leave a Reply

Your email address will not be published. Required fields are marked *