SANS vs SKL DFIR AI Frameworks: When to Use Each
Brief
Heather Barnhart has done great work helping develop the SANS DFIR AI Framework . If you haven’t seen it, I recommend reading it.
That said, it differs from how we’ve been talking about AI.
This post dives into if the two views are actually in conflict or just looking at the problem from different angles.
TLDR: They’re complementary. The SANS framework is more helpful for an investigator to map AI to their process. Ours is more useful for thinking about what to validate.
The SANS / SWGDE AI Framework
Developed by Heather Barnhart and others, the SANS framework organizes AI guidance around SWGDE investigation phases:
- Identification
- Collection/Preservation
- Triage
- Examination/Analysis
- Validation
- Reporting
For each phase, it assigns a risk level: AI recommended, AI optional, or AI never.
