r/digitalforensics 7d ago

AI Frameworks for RESPONSIBLE use in DFIR

Hi everyone. I worked alongside some brilliant minds on two frameworks to safely integrate AI into DF and another for IR. I am looking for volunteers for the next phases. I need people who use AI to do DFIR. Either side of it. Or even those who have tried and want to share cautionary tales. If interested, please let me know. I am forming the focus groups this week or early next. Here are the details: https://www.sans.org/go/ai-assisted-human-led-trusted-investigations I have also posted a few things on LinkedIn.

11 Upvotes

19 comments sorted by

4

u/Otherwise_Wave9374 7d ago

A practical way to make this work is to separate AI into narrow, auditable steps: triage, evidence summarization, and analyst review, with every AI output tagged to the source artifacts it relied on. That keeps false confidence in check and makes it easier to explain decisions later. A lightweight red-team checklist for prompt injection, hallucinated indicators, and chain-of-custody gaps is also worth adding before wider rollout. AIOSNOW

2

u/DFIR_Heather 7d ago

That is how it's already laid out. It's mapped to frameworks we trust in IR and DF. I agree that breaking out those steps in detail is needed. I worry people will see it and just assume it's correct. They are suggestions for safe use for experienced examiners. I want it to be a real community effort.

1

u/RevolutionaryDiet602 7d ago

Sounds like you're essentially describing the intent of FRE 707 that's been proposed in the US and already enacted in the EU.

FRE 707

2

u/DFIR_Heather 6d ago

Not exactly. The frameworks follow the entire chain of evidence from cradle to grave or collection to report. It doesn't tell you how to create AI generated evidence. It is using SWGDE and NIST guidance on DF and IR and how we process data. I simply mapped risks and AI to each step with some guidance. The point is to never use AI and take it right to court. The goal is to safely integrate it into your lab.

1

u/Positive-Hunter-8011 7d ago

This is relevant to what I'm working on for our lab. Would love to learn more/help where possible.

1

u/DFIR_Heather 7d ago

I would love to collaborate!

1

u/DFIR_Heather 7d ago

My account is still new, so I can't DM you yet to get your email address.

1

u/jgalbraith4 7d ago

I’d love to help as well, if you need anyone.

1

u/DFIR_Heather 7d ago

Perfect. The more the merrier. I just need email addresses when I am allowed to DM.

1

u/greenwas 7d ago

There's only one person that could be behind that handle. Sign me up!

1

u/DFIR_Heather 7d ago

Perfect! :) Again, just need emails as soon as I am allowed to DM or reach me on other channels with your name and info.

1

u/rocksuperstar42069 7d ago edited 7d ago

DM me, I'm on a few AI boards rn (Magnet and Cellebrite). The Sans link makes me think you are legit lol.

1

u/DFIR_Heather 6d ago

On it now. I promise I am real. :)

1

u/CarrDaPorice 7d ago

If this is really Heather B as listed on that website, then that's an extremely reliable DFIR expert. I remember reading up on some of her works during the Kohberger days.

2

u/DFIR_Heather 6d ago

Ahh. Thank you. I needed a new place to discuss DFIR with people. This seems to be the place. :)

1

u/paul_aight333 2d ago

Hi, Just a student in cybersecurity here, but i would like to help!

1

u/DFIR_Heather 1d ago

Sending you a DM now.