Investigating at scale: Lessons from three DFIR leaders
Brief
Key takeaways:
- Identity is often the most overlooked artifact in an investigation: sign-in logs, OAuth tokens, and persistence mechanisms can outlast an “obvious” fix like a password reset
- The fastest-moving teams during an incident have playbooks specific enough to actually follow, and knowledge that lives in a shared repository, not just in one or two people’s heads.
- Forensic readiness happens before the incident, not during it: logging turned on, baselines set, and tabletop exercises that pull in legal and leadership, not just the SOC.
- AI is good at surfacing patterns in a mountain of data. It’s not good at deciding what to do about them — that’s still on a person, especially before any high-stakes action.
Incident response teams are managing more investigations and more complex ones.
