I just went through 400 DFIR books spanning 46 years to get some stats on where we came from, where we are, and maybe some ideas on where we are going. This wasn’t easy. Some books that I have are no longer in print. Some books that I used to have, I can’t find online anymore (and don’t really remember much about them...which doesn’t help looking for them).
That is not the entire universe of DFIR books. That’s only what I could find on Amazon, thrift sites, and rare book sites. And it doesn’t include the entire universe of what can be considered “DFIR.” I did count upcoming books for 2027, which sometimes those books end up as vaporware.
I pulled this corpus apart to see what the books themselves say about how DFIR grew up: what got published, who kept writing, how often books were revised, how the language changed, and where the field started branching into incident response, eDiscovery, malware, mobile, cloud, threat hunting, and now AI.
TL:DR
I believe that we have drifted from the investigation of human behavior and moved toward recovering artifacts from computer events. That bothers me. Why? I can only speculate. But part of it could be because running an automated tool and exporting an artifact report is infinitely easier than doing the grueling work of proving who was at the keyboard and comprehending a complex legal process. That requires writing about human behavior, psychology, philosophy, law, and an investigative mindset.
Snapshot of the dataset
*812 authors include authors being counted more than once if they have more than one book.




