Don’t be the anchor: Rethinking the DFIR workflow loop
By Christopher Vance
Originally published in the July 2026 issue of Magnet Unlocked. Want to be the first to see new content? Sign up for our monthly newsletter, Magnet Unlocked.
The anchor I see most often in a digital forensics lab isn’t a person.
It’s a workflow template.
Something a predecessor built years ago, that we’ve been regenerating on every case since, that nobody on the receiving end has opened in a long time. We keep building it because the request keeps coming. The request keeps coming because we keep building it. That’s the loop, and it’s quietly the single biggest thing holding digital forensics back right now.
Not the tooling. Not the backlog. Not the budget. The loop.
My colleague, Brandon Epstein wrote recently about the courtroom cost of “we’ve always done it this way,” how it can get a method torn apart on the stand. I want to talk about a quieter cost, the one that shows up long before the courtroom does: the cases you never get to, because the old workflow ate the week.
I’ve been thinking about this a lot since the hustle of conference season has been in full swing. The conversations that stuck with me weren’t about any specific feature or workflow. They were about the shape of the workflow itself, and about how much of that shape is dictated by muscle memory rather than by what the case actually needs.
The three people in every case
If you zoom out, most of our cases move through three sets of hands:
- The examiner, who does the work
- The investigator, who uses the work
- The prosecutor, who decides whether the work goes anywhere
Each of those three has a different relationship with change, and once you see it, you can’t unsee it.
Prosecutors are the most concerned with the outcome. They want the cleanest path to the plea, the conviction, or the dismissal. If you show them a better route to that outcome, most of them will take it. They just don’t always realize how much say they have in what “the route” looks like. A lot of the reports we produce look the way they do because someone, somewhere, once assumed that was what the prosecutor wanted.
Investigators, on the other hand, are the ones I think we’ve been misreading. In my experience, a lot of investigators aren’t trying to master the evidence. They’re trying to get the evidence out of their hands and into someone else’s, and they’ll reach for whatever tool they already know how to open. That’s a workload problem. But it does mean the request coming across the examiner’s desk is often the anchor talking. And the anchor almost always says the same six words.
“Just give me what you gave me last time.”
As an examiner, that’s the scariest sentence in my inbox. Not because the person on the other end is wrong to ask, but because if I say yes without thinking, I’ve just re-committed to a workflow neither of us has examined in years.
The confession I lead with now
When I present on newer, more automated workflows, I’ve started opening with a number that makes people uncomfortable, including me. Based on my own years as an examiner, I’d estimate that roughly 60% of the work product I generated ended up in a trash can.
I can’t prove that number because we don’t have a mechanism to check. There’s no accountability loop that tells the examiner, “The thing you spent four hours building was never looked at.” We just keep building.
I bring this up not to be grim, but because I think it reframes the whole conversation about automation. When examiners hear “we’re going to automate more of your workflow,” a lot of them hear “we’re going to automate you.”
What automation actually threatens is the 60% that was already going in the trash. What it protects, and what it gives back, is time. Time for the cases that deserve a real deep dive. Time for training. Time to go home at a reasonable hour and still be sharp the next morning. That’s the trade.
You can’t investigate what you don’t understand
Here’s the part of the meditation I keep coming back to, and it’s the part I’d ask every examiner reading this to sit with for a minute.
Whether or not you personally believe in AI as a forensic tool, the people we investigate are already using it. They’re using it to generate content, to obscure content, to communicate, to plan, to launder identity. That is not a future problem; it’s a current problem, on current devices, in current cases.
We train on grooming, narcotics, and homicide. We build competency in the things we investigate precisely because we are not the ones doing them. AI belongs on that same list. If we refuse to learn the tools that our subjects are already fluent in, we aren’t preserving the integrity of the craft. We’re just falling behind it.
Here’s the way I’ve started framing this to myself. Defensibility is a backward-looking test. It asks whether what you did will hold up. Adversary parity is a forward-looking test. It asks whether what you’re doing can keep pace with what’s already being done to you. Both matter, and both are the job. But most of the labs I visit are still optimizing hard for the first test and quietly losing ground on the second. The unread template gets updated. The AI training doesn’t get booked.
That’s the shift I want us to make. Not “AI is coming for my job.” But “AI is already in my casework, and I owe it to the case to understand it.“
A faster horse, or a hovercraft
The metaphor I keep using, and I’ll use it here because it’s the cleanest way I know to say it, is this. When examiners ask me for the next generation of tooling, most of them are asking for a faster horse. They want the workflow they already have, but quicker. That’s a reasonable request but it’s also the wrong one.
We aren’t offering a faster horse; we’re offering a hovercraft. You still get to the destination and close the case, but you get there by a different route, and you skip a bunch of the hurdles that used to eat your afternoon. The workflow isn’t sped up, it’s re-shaped. That’s a harder thing to accept than a faster horse, because it asks you to change the map, not just the mount.
So, what now?
Here’s the “so what,” and I mean this as a peer, not a pitchman.
This week, don’t audit a method. Audit a loop. Walk your own workflow and find one place where you’re generating output because it’s expected, not because it’s used. A template. A report section. A file you export every time and haven’t heard a question about in a year. That’s your anchor.
Cut just one. See what your week looks like without it and see whether anybody on the receiving end actually notices. If they don’t, you just got that time back for the case that deserves it, or for the training you’ve been putting off. If they do notice, great, now you have a real reason to keep it, and a real conversation to have about the rest.
Because the bad actors on the other side of our casework aren’t waiting for us to feel ready. They’re already on the hovercraft. The question isn’t whether the workflow is going to change. The question is whether we’re going to be the ones steering it, or the ones being dragged behind it.
Don’t be the anchor.