Talk With an Expert

Think Like an Examiner

Think Like an Examiner (PDF, 2.57MB)Last updated: 24 Jul, 2025
Presented by:
Tony Knutson
Tony Knutson

Cybersecurity professionals are often faced with complex, high-stakes investigations where quick decision-making and investigative accuracy are critical. However, many practitioners struggle to balance the rapid response required in Incident Response (IR) with the deep analytical mindset needed for Digital Forensics (DF). Without a structured investigative approach, security teams risk missing key evidence, drawing premature conclusions, or failing to remediate threats effectively. This presentation, “Think Like an Examiner: Strengthening Your Forensic & Response Mindset,” explores how cybersecurity professionals can develop a structured, examiner-focused approach that enhances both forensic accuracy and incident response agility. By shifting from a reactive mindset to an investigative mindset, examiners can improve their ability to analyze threats, preserve critical evidence, and make confident decisions in high-pressure environments.

SANS DFIR Summit 2025