ABCDEFGHIJKLMNOPQRSTUVWXYZAAABAC
1
TimestampEducation Background
How many years have you been in DFIR field
Do you hold any Certification
Do you feel your Certification brings value to your Job/Career
What Certification do you currently have
Are you currently happy with your current job
Do you consider yourself overworked or burnt out
What is your current salary
What is your main job roleRole LevelDo you feel underpaid
How many times did you swap jobs/companies
Do you work out of a Major City (NY, PHL, CHI)
Are you Law Enforcement/Private Sector/Government
How do you feel about the current and future DFIR job environment.
Are you currently looking for a new job?
Do you feel Certifications are important for new graduates to obtain for applying to jobs?
Do you feel the quality of candidates from university have gone up or down in recent years?
Do you feel the DFIR field is becoming saturated with new graduates?
For students who are unable to find a job what advice do you have for them.
Any projects ideas a student can work on to help the DFIR community?
How can students make their resume's stand out
2
5/1/2024 14:57:57High School0-1YesYesBtl1YesNo$30,001 - $60,000SOCEntry LevelNo1YesGovernmentGoodPossiblyYesHas been going downNo
3
5/1/2024 15:03:07Master5-10YesNoEnceYesNo$125,001 - $150,000Digital Forensics analystLeadNo3YesPrivate SectorGoodPossiblyNoHas been going upNo
Take a role in an adjacent field and work your way over.
No
Specifics on tools and training
4
5/1/2024 15:17:24Bachelor's2-5YesMaybe
Cfce, casa, cco, misc belkasoft
YesYes$60,001 - $100,000Digital Forensics analystAssociateYes0NoLaw EnforcementSkepticalYesYesHas been going downNo
Coding. Learn to code. Work on open source projects. Show the interviewers you understand computational workflows and thinking
Look towards the libraries and archives sector for digital preservation projects. Low barrier of entry. Very similar technologies under the hood when you dig in. No need to pursuade someone to clear you for the grubby stuff. No exposure to the grubby stuff
Don't list certs. List achievements. Show me you understand df workshops.
5
5/1/2024 15:51:12High School5-10YesYes
GCFA, GCIH, GNFA, GX-FA, GX-IH
NoNo$60,001 - $100,000Digital Forensics analystMid-SeniorYes0NoGovernmentGoodYesYesHas been going downNo
6
5/1/2024 15:54:53Master5-10YesYesCFCEYesGetting there$60,001 - $100,000Digital Forensics analystLeadYes0NoLaw EnforcementGoodNoNoHas been going downYes
Continue to build resume, internships
Internships
7
5/1/2024 16:03:42High School0-1YesYesSans FOR508YesYes<$30,000Digital Forensics analystEntry LevelYes0NoPrivate SectorGoodPossiblyNoHas been going downNo
Learn By doing. Partecipate in CTF challenges.
More tools. We are in dire need of more open source stuff, especially for mobile forensics
8
5/1/2024 16:19:24Master10+YesYesGIACx22, CFE, DFCP, etc. YesGetting there$200,001+Team Lead/ ManagmentDirectorYes4NoPrivate SectorSkepticalPossiblyYesHas been going upNo
Networking and finding a mentor in the industry can pay off hugely in finding a place to land. When you apply to any position, you are pitted against the pool. If you can get the internal referral, you move to the front of the line.
Cloud and Log parsing are becoming more and more critical for the cases being worked.
External Projects and Tools help indicate the student can think through a problem by creating the solution themselves.
9
5/1/2024 16:34:18Master10+YesYesCce, GASF, ence, mcfeYesNo$150,001- $200,000Mid-SeniorNo1NoLaw EnforcementGoodNoYesHas been going upNo
Go the law enforcement route
10
5/1/2024 16:46:00Bachelor's2-5YesMaybe
Security+, AZ-900, AWS CCP
YesGetting there$100,001 - $125,000SOCAssociateNo1NoPrivate SectorSkepticalPossiblyYesHas been going downYes
Cybersecurity is NOT entry level. You might get lucky (or maybe make your own luck) and start off in cyber but that is very unlikely. Start in another facet of IT and learn how security can be applied to it. With the market for entry level jobs as saturated as it is, it unlikely that you will be the top candidate through no fault of your own, taking another road and coming back to cyber will benefit you in the long run and stop you from getting discouraged.
Learn everything you can about the Windows operating system.
11
5/1/2024 17:49:35Master2-5YesMaybeCISSPYesNo$150,001- $200,000Incident ResponseLeadNo2NoPrivate SectorSkepticalNoYesHas been going upNo
You don't need to specialise until you're in your 30s.
Host your own websites, interpret logs, make timelines, explore malware safely
Keep it concise and relevant - don't oversell it. Keep it factual. Every word matters, don't fill it with crap.
12
5/1/2024 18:03:21Bachelor's2-5NoNoNoYes$125,001 - $150,000SOCMid-SeniorNo0YesPrivate SectorGoodPossiblyYesHas been going downNo
13
5/1/2024 18:10:00Bachelor's2-5YesMaybeSANS GCFEYesNo$60,001 - $100,000Digital Forensics analystAssociateNo0YesLaw EnforcementGoodNoYesHas been going upNo
Try to get more certifications and free external/online training before applying.
14
5/1/2024 18:17:42Associate10+YesYes8 different ones YesNo$100,001 - $125,000Digital Forensics analystLeadYes0NoLaw EnforcementGoodYesYesHas been going downYes
Get a low level job or law enforcement first
No
15
5/1/2024 20:17:54Master5-10YesMaybeEnce, Inspector, MagnetYesNo$200,001+Digital Forensics analystMid-SeniorNo3YesPrivate SectorSkepticalNoYes
Infosec is a broad field. Learn a little bit about everything.
16
5/1/2024 20:19:23Master10+YesYesCFCE, GCFA, GCIHYesGetting there$200,001+Team Lead/ ManagmentExecutiveNo3NoPrivate SectorGoodNoYesHas been going downNo
17
5/1/2024 20:28:32Bachelor's0-1YesYesCFCEYesNo$60,001 - $100,000Digital Forensics analystEntry LevelNo0YesPrivate SectorGoodNoYesHas been going upNoGet the CFCE
18
5/1/2024 20:39:01Bachelor's2-5YesMaybeMCFEYesNo$60,001 - $100,000Digital Forensics analystAssociateYes0YesPrivate SectorGoodNoNoHas been going upYes
Work on networking and people skills. Let hiring managers know you are ready to learn and adapt to their needs. Do worry about not knowing the big forensics tools. Communication skills are really lacking in our space and it's one thing that can make you stand out from another candidate.
Take as many free courses as you can from the big vendors. Companies like Magnet and Cellebrite are always offering excellent training. If you can't get your hands on the tools, having a basic understanding of the functionality will be better than most. Work on report writing and take a technical writing course while you are in school. Being able to communicate your findings to the client is oftentimes overlooked. Understand your audience.
Highlight your major skills and the goals you are looking to achieve in the position you are looking for. Understand the audience and know that you might need a different resume template depending on the job posting. I remember some places had a required format. Try to target the department manager or partner and get it into their inbox if possible. Sometimes it is all about the people you know.
19
5/1/2024 20:45:27Master2-5YesYesGCFAYesNo$60,001 - $100,000Incident ResponseAssociateYes0YesPrivate SectorGoodPossiblyNoHas been going upNo
Even if you don't have work experience, I think being able to talk enthusiastically about the projects you've done at school and how you approached those problems is something that interviewers like to see. Also, be humble and express that you're someone who enjoys to learn.
I feel that just being able to understand and explain artifacts of execution like userassist, amcache, shimcache, prefetch, and whatnot probably will help new grads stand out from other people.
20
5/1/2024 20:46:28Bachelor's5-10YesYesYesNo$150,001- $200,000Team Lead/ ManagmentDirectorNo1YesPrivate SectorGoodNoNoHas been going upNo
21
5/1/2024 20:56:42Bachelor's2-5NoMaybeYesNo$100,001 - $125,000DFIRAssociateNo0NoPrivate SectorGoodNoNoHas been going upNoInternships !!!
22
5/1/2024 20:57:05High School5-10YesYesSansYesNo$150,001- $200,000Team Lead/ ManagmentLeadNo0YesPrivate SectorGoodPossiblyNoHas been going upYesTry harder Velociraptor scripts
Go beyond the degree, give me real world projects you’ve engaged in at home
23
5/1/2024 21:04:03Bachelor's2-5YesYesCfce, mcfe, cppa YesGetting there$60,001 - $100,000Digital Forensics analystAssociateYes0NoLaw EnforcementSkepticalYesHas been going downYesGo to an le agency
Something like the LEAPPS
24
5/1/2024 22:00:29
25
5/1/2024 22:06:31Bachelor's2-5YesYesGCFE, GCFA, GCLDYesGetting there$125,001 - $150,000SOCMid-SeniorNo2YesPrivate SectorGoodPossiblyNoHas been going downNo
Most people do not go straight into DFIR, you gain a lot of knowledge working in a SOC or similar roles. Even starting in IT is good. Getting to understand real environments and real world situations goes a lot further then anything a course can teach you. School will not teach you that you sometimes just walk into a situation and find out the IT department saw nothing wrong with giving every single person admin on their device.
Automation of log parsing and visual aid creation for senior level/court will make you a lot of friends.
A link to your own personal website with example reports of mock device examination. Report writing is a lot more important then you realize. If you list a tool or a skill you better be prepared to explain not only how you use it but why.
26
5/1/2024 22:10:55Bachelor's2-5YesYesGCFAYesGetting there$100,001 - $125,000Digital Forensics analystAssociateNo1NoGovernmentGoodPossiblyYesHas been going downNo
27
5/1/2024 22:11:20Bachelor's2-5YesMaybe13cubed, several SANSYesNo$125,001 - $150,000Digital Forensics analystMid-SeniorNo1NoPrivate SectorGoodNoYesHas been going downNo
Contribute, even in small ways, to the community. Show interest an interest in learning
28
5/1/2024 22:43:06Bachelor's10+YesYesGCFE, GASFYesNo$150,001- $200,000Digital Forensics analystMid-SeniorNo1YesGovernmentGoodNoYesHas been going upNo
29
5/1/2024 22:58:14Bachelor's5-10YesYes
CFCE ICMDE CCO/CCPA MCFE
YesNo$60,001 - $100,000Digital Forensics analystMid-SeniorYes2YesLaw EnforcementGoodNoYesHas been going downNoNa
30
5/2/2024 0:52:08High School10+YesYesIACIS CFCEYesNo$150,001- $200,000Team Lead/ ManagmentMid-SeniorNo1NoPrivate SectorGoodNoNoHas been going downYes
31
5/2/2024 1:11:27Bachelor's5-10YesYesAXIOM, Cellebrite, FEXYesGetting there$125,001 - $150,000Digital Forensics analystMid-SeniorNoLaw EnforcementGoodYesYesHas been going upNo
32
5/2/2024 1:28:05Bachelor's10+NoMaybeYesYes$60,001 - $100,000Digital Forensics analystDirectorNo1NoPrivate SectorSkepticalPossiblyNoHas been going downYes
Placement years to get your foot in the door, uk based (I'd going for a police force) special may also help get you a start
Ctf schemes
33
5/2/2024 1:41:49Bachelor's5-10YesYes
I filled out this form but the data was lost.
YesNo$30,001 - $60,000Digital Forensics analystAssociateYes2YesLaw EnforcementGoodNoNoHas been going downYes
Get practical experience at home.
Software development
Technical knowledge, an investigative mind, honesty.
34
5/2/2024 2:27:14Bachelor's2-5NoYesGetting there$60,001 - $100,000Incident ResponseMid-SeniorNo0YesPrivate SectorGoodPossiblyNoHas been going upNo
35
5/2/2024 2:58:55Bachelor's2-5YesNo
Product management, some tool specific certs.
YesYes$60,001 - $100,000Product manager AssociateYes0NoPrivate SectorSkepticalPossiblyNoHas been going downNo
Be truthful in interviews, if you don’t know the answer be honest. Try to get some free work experience done, that’s how I’m still working for a forensic software vendor.
Faster hashing technologies
Your competencies should be clear and up front.
36
5/2/2024 6:06:14Bachelor's2-5YesYes
Sans + multiple Cellebrite certs
YesNo$60,001 - $100,000Digital Forensics analystAssociateYes0NoLaw EnforcementSkepticalNoYesHas been going downNo
Certifications, blogs, writing papers on forensic artifacts, hands on self learning (phones, computers, etc)
Verifying and testing data on phones. Location data, messages apps, testing on new apps people might be using, etc
Show that you’re passionate about the field. Write some blog posts. Show you’ve done forensic testing on devices. Show something interesting you found in a phone extraction.
37
5/2/2024 8:50:59High School10+YesYesGCFA , GNFAYesNo$200,001+Team Lead/ ManagmentDirectorNo5+NoPrivate SectorGoodNoYesHas been going downNo
Don’t give up, consider working hard a SOC role.
Better parsers for cloud computing artifacts and AI/ML ideas.
Don’t just list tools, list stuff you have worked on (ie: malware intrusion on a server)
38
5/2/2024 9:53:58Master10+YesYesYesNo$200,001+Digital Forensics analystMid-SeniorNo4NoPrivate SectorSkepticalNoYesHas been going upYes
39
5/2/2024 10:29:52Bachelor's5-10YesYesCFCE, GREM, GCFRYesNo$150,001- $200,000Incident ResponseMid-SeniorNo2YesPrivate SectorGoodPossiblyNoHas been going upNo
Apply even if you don’t meet min. Requirements
Follow ATS standards
40
5/2/2024 13:22:17Bachelor's10+YesYesEnce, CCE, ACEYesNo$100,001 - $125,000Digital Forensics analystDirectorNo3YesPrivate SectorGoodNoYesHas been going upYes
Market yourself on LinkedIn, set your self apart from others with blogs/research
find / test new artifacts with computers, phones, etc.
experience, research, and blog projects
41
5/2/2024 15:18:54Master5-10YesMaybeCISSP, CCNP:RSYesNo$125,001 - $150,000Incident ResponseMid-SeniorNo4NoPrivate SectorGoodNoYesHas been going upNo
42
5/2/2024 16:18:07High School5-10YesYesGCFA, GCIHYesNo$125,001 - $150,000Threat hunterMid-SeniorNo3NoPrivate SectorGoodNoYesHas been going downYes
43
5/4/2024 7:26:51Master0-1NoMaybeNoGetting there<$30,000Quality analyst Mid-SeniorYes2NoPrivate SectorGoodYesYesHas been going upYes
44
5/6/2024 20:13:33Master10+NoNononeNoGetting there$200,001+DirectorYes5+NoPrivate SectorGoodYesYes
45
5/9/2024 10:17:58Bachelor's10+YesYesGCFA, GCFENoYes$150,001- $200,000Team Lead/ ManagmentLeadYes4NoPrivate SectorSkepticalPossiblyNoHas been going upYes
Make yourself stand out by doing research, publishing a blog, standing up a home lab. If you can show me you understand all the concepts and can demonstrate that, you are better off that 90% of the new candidates I see.
anything cloud or container forensics
Look at the job posting and make sure the keywords they are looking for are in your resume. If I am hiring a forensics person, and you do not mention forensics in your resume, it will not get past the initial checks and searches.

Don't use ChatGPT to write your resume. ChatGPT written text is easy to spot and often comes off as snooty. Its OK to use ChatGPT but reword what it creates.
46
5/13/2024 14:58:31Bachelor's0-1YesYesNuixYesNo$60,001 - $100,000Digital Forensics analystAssociateNo2NoLaw EnforcementGoodNoNo
47
5/13/2024 16:05:19Bachelor's5-10YesNoWhere to start...YesNo$60,001 - $100,000Digital Forensics analystMid-SeniorYes3NoLaw EnforcementSkepticalPossiblyNoHas been going downYes
Work in a technical field to get experience. It will probably be transferrable
48
5/13/2024 17:44:10Bachelor's10+YesMaybeCFEYesNo$200,001+Digital Forensics analystExecutiveNo0NoPrivate SectorGoodNoYesHas been going upNoGo into LE to start
49
5/14/2024 3:06:50High School10+YesYesACE, GNFA, GCFEYesNo$200,001+Team Lead/ ManagmentDirectorNo5+NoPrivate SectorGoodNoYesHas been going upNoKeep your head up!More automationTry and intern at places!
50
5/15/2024 11:58:42High School0-1YesYesSec+YesNo$60,001 - $100,000SOCEntry LevelYes1NoGovernmentSkepticalPossiblyYesHas been going upNo
51
5/15/2024 20:47:58Associate5-10NoMaybeNoYes$60,001 - $100,000Digital Forensics analystMid-SeniorYes0YesLaw EnforcementSkepticalYesYesHas been going downNo
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100