That is not the entire universe of DFIR books. That’s only what I could find on Amazon, thrift sites, and rare book sites. And it doesn’t include the entire universe of what can be considered “DFIR.” I did count upcoming books for 2027, which sometimes those books end up as vaporware.

I pulled this corpus apart to see what the books themselves say about how DFIR grew up: what got published, who kept writing, how often books were revised, how the language changed, and where the field started branching into incident response, eDiscovery, malware, mobile, cloud, threat hunting, and now AI.

TL:DR

I believe that we have drifted from the investigation of human behavior and moved toward recovering artifacts from computer events. That bothers me. Why? I can only speculate. But part of it could be because running an automated tool and exporting an artifact report is infinitely easier than doing the grueling work of proving who was at the keyboard and comprehending a complex legal process. That requires writing about human behavior, psychology, philosophy, law, and an investigative mindset.

Snapshot of the dataset

*812 authors include authors being counted more than once if they have more than one book.