That is not the entire universe of DFIR books. That’s only what I could find on Amazon, thrift sites, and rare book sites. And it doesn’t include the entire universe of what can be considered “DFIR.” I did count upcoming books for 2027, which sometimes those books end up as vaporware.
I pulled this corpus apart to see what the books themselves say about how DFIR grew up: what got published, who kept writing, how often books were revised, how the language changed, and where the field started branching into incident response, eDiscovery, malware, mobile, cloud, threat hunting, and now AI.
TL:DR
I believe that we have drifted from the investigation of human behavior and moved toward recovering artifacts from computer events. That bothers me. Why? I can only speculate. But part of it could be because running an automated tool and exporting an artifact report is infinitely easier than doing the grueling work of proving who was at the keyboard and comprehending a complex legal process. That requires writing about human behavior, psychology, philosophy, law, and an investigative mindset.
Snapshot of the dataset

*812 authors include authors being counted more than once if they have more than one book.
Growth and publication trends
The early years are sparse. In the 1980s and 1990s, most of what shows up is tied to law, evidence, crime, and the courtroom. After 2000, the publishing pace changes. DFIR starts looking like a real specialist market instead of an occasional shelf of books. The bigger historical clusters show up in 2008, 2014–2018, and 2021–2024. And I would not read too much into the 2026 spike because some of those titles were still scheduled when I went through the titles.

Who keeps showing up?
A few names show up over and over, but I do not want to confuse repetition with influence. These are corpus credits, not a leaderboard for who “carried” DFIR. Sujeet Shenoi, Gilbert Peterson, Kim-Kwang Raymond Choo, Harlan Carvey, Eoghan Casey, Chuck Easttom, the Nelson/Phillips/Steuart textbook team, Sanjay Goel, Rohit Tamma, and Oleg Skulkin are among the most frequently credited names in this list. I included conference proceedings that were packaged and sold as books. That inflates some names because an editor gets a corpus credit even though other people wrote the individual papers. Still, I counted them for the work done in putting conference papers together as books.
Authors/editors with more than 3 corpus credits

A credit here can be a new edition, an edited proceedings volume, or another appearance in the corpus. This tells us who appears often but it does not tell us who had the most impact, who was cited the most, or who changed practice the most or at all. It does show who has been publishing!
One note: I may have missed someone’s book, and that means I undercounted. My apologies and I welcome corrections.
Time between editions
When I match title families after stripping out edition labels, I get 50 edition-to-edition intervals that are good enough to use.
Distribution of time between identifiable editions

Most new editions were published within three to five years of the previous edition. Three years was the most common interval, occurring 15 times, followed by five years, occurring 11 times. Longer gaps were uncommon, with only four intervals exceeding seven years and one reaching 18 years. Across all 50 edition-to-edition intervals, the average gap was about 4.5 years.
Number of credited authors per book
Nearly three quarters of the books were written by one or two authors. And 183 of the 400 books were written by one person. Having done both myself, I can tell you writing a book alone is difficult and writing one with someone else isn't easy.
| Credited authors | Books / editions |
|---|---|
| 1 | 183 |
| 2 | 110 |
| 3 | 59 |
| 4 | 29 |
| 5 | 13 |
| 6 | 3 |
| 8 | 1 |
| 12 | 1 |
| 13 | 1 |
Patterns
What I saw in the corpus is not one discipline replacing another. It is the field splitting into branches that keep overlapping. The early books are heavy on evidence, crime, the accused, and investigation.
Around 2000–2005, “computer forensics” settles in as a recognizable label, and incident response starts appearing right next to it.
After 2006, eDiscovery becomes much easier to see as its own publishing lane.
From about 2007 forward, books get more specific about platforms and artifacts.
By the 2010s and 2020s, DFIR is an umbrella term covering mobile, memory, malware, cloud, threat hunting, incident response, and now AI.

Publication timeline against legal and technology events
I am not saying these outside events influenced the publishing numbers. That would be too easy to say and too difficult to prove. I am using them as reference points. New evidence sources, new legal duties, and new operating platforms tend to be followed by books explaining how practitioners are supposed to deal with them. The timing is worth looking at even when causation cannot be proved from this corpus alone.

One thing on “electronic discovery” is that if you’ve never worked in ediscovery, you’d probably think it has not much to do with DFIR. Civil eDiscovery forced lawyers, courts, vendors, and experts to argue with preservation, collection, metadata, production, authenticity, and electronic evidence long before some of those subjects became routine elsewhere. DFIR practitioners shouldn't dismiss eDiscovery literature just because it came out of civil litigation.
Personally significant books
This is not a citation ranking and it is not a claim that these are the best books ever written. These are titles that stand out inside this corpus because they helped shape my work, my perspective, and my objectives. I kept the list short, but there are more that made a difference in how I think and how I do DFIR.

| Year | Title | Author(s) | Why it mattered to me |
|---|---|---|---|
| 1995 | High-Technology Crime: Investigating Cases Involving Computers | Kenneth S. Rosenblatt | Early explicit investigative framing. This book could be back in print today and be mostly accurate still. |
| 2000 | Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet | Eoghan Casey | If Eoghan Casey writes it, I read it. |
| 2001 | Incident Response: Investigating Computer Crime | Chris Prosise · Kevin Mandia | Clear early bridge between criminal investigation and IR. |
| 2001 | Computer Forensics: Incident Response Essentials | Warren G. Kruse II · Jay G. Heiser | The first DFIR book I ever read. Imagine if I read a terrible DFIR book first…I’d probably be doing something different today. |
| 2004 | Computer Forensics and Investigations | Bill Nelson · Amelia Phillips · Frank Enfinger · Christopher Steuart | I was fortunate to live and work in the same area as these authors, and they helped shape me when I started as a young detective in forensics. |
| 2005 | File System Forensic Analysis | Brian Carrier | I remember the day I bought this book. It has since worn out, but I still have it. |
| 2007 | Windows Forensic Analysis DVD Toolkit | Harlan Carvey | Again, if Harlan writes it, I’m reading it. |
| 2013 | Placing the Suspect Behind the Keyboard: Using Digital Forensics and Investigative Techniques to Identify Cybercrime Suspects | Brett Shavers | Yes, I wrote it…weird to say it shaped my work. But it did, for many reasons. I’ve told the story before, I’ll tell it again sometime. A reminder (to me) that digital forensics is attribution using all types of evidence, not just electronic data. |
| 2014 | The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory | Michael Hale Ligh · Andrew Case · Jamie Levy · Aaron Walters | I could barely get through this book because I wanted to practice the things I was reading right away. A seminal book! |
What the corpus says about DFIR: past, present, future
Past
The early books are centered on people, crime, evidence, and court. The machine is usually the thing being examined either as evidence or as having facilitated a crime, but the real question is whether the evidence coming from that machine can be collected properly, explained clearly, challenged in court, and tied back to conduct by a person. Basically, a crime happened, a computer device was involved, and these books helped get electronic evidence admissible in legal cases.
Present
Today the field is broader and much more technical. “Digital” and “cyber” gradually push “computer” out of the center. Books break into platform and artifact specialties. Incident response, threat hunting, malware, cloud, mobile, network, and memory analysis all overlap with forensic methods.
Future
What comes next may not be another simple DF-versus-IR split. I think the sharper divide will be between evidence-driven human attribution, high-speed response and threat operations, and AI-assisted or AI-targeted forensic work. The titles already hint at that. Crime and investigation never disappear, while cyber, platform, and AI language keeps expanding around them. And that leaves an old problem sitting right in the middle: tools can tell us a lot about what happened on a system, but they do not automatically tell us who did it, why they did it, whether our explanation is the best one, or whether that explanation will survive scrutiny.
Dataset inclusion, exclusion, and limitations
Inclusion logic
I kept books in the corpus when their main subject was digital or computer evidence, computer crime investigation, digital forensics, forensic computing, incident response with real forensic content, malware analysis with investigative value, eDiscovery or electronic evidence, platform-specific forensic work, threat investigation, OSINT where it appeared in the supplied list, and newer AI/forensic topics. I also kept separate editions as separate records because revision cadence and repeat authorship are part of what I wanted to measure.
Exclusion logic
I did not try to make this a list of every cybersecurity book ever published. General security, hacking, networking, programming, cybersecurity, and AI titles should stay out unless the title and stated scope connect directly to examination, investigation, evidence, response, or closely related DFIR work. I also left out journal articles, standards, vendor manuals, training courses, and conference papers unless the supplied dataset treated something as a book-length proceedings volume.
Limitations
-
This started as a curated title list, not a complete bibliographic database.
-
Publication years can move around depending on edition, country, hardcover versus paperback release, and retailer metadata.
-
The total-page number is an estimate, not verified pagination, based on 350 page average per book.
-
I didn’t have confidence to determine whether an author is a practitioner, academic, or both (hybrid) based on bios in books. It would be interesting to see how the percentages stack up for each category.
-
Proceedings volumes can make some authors or editors look more frequent and can push annual counts up compared with ordinary monographs. I was torn about whether to add these as ‘books’ but since they were being marketed and sold as books, and there is value in the information, I included them.
-
Categories were assigned manually and one book can belong to more than one category.
-
2026 is an incomplete listing and 2027 consists of upcoming titles.
GenAI written books
I did not include, to the best of my knowledge, books that were apparently written mostly by GenAI. Here are my thoughts on GenAI written books: It is DFIR-book slop. Without naming them, many were Kindle books with authors who I could not find online. Some of the ‘authors’ had a dozen or more books about everything, like travel and cooking along with a DFIR-titled book. I purchased two unfamiliar DFIR books because the titles and summary were enticing, and one was so glaringly AI-written that I felt scammed.
Excluded books were an editorial decision. A GenAI book has no firsthand judgment, no experience, and no personality. Worse still, it can be flat-out wrong, creating a blast radius of bad information when that material gets repeated, cited, scraped, summarized, or fed into other systems.
The book list
I put all the books on dfir.training (https://www.dfir.training/dfir-books). The count will change as I update with more books as they get published or promised to be published. I will do my best to not put any book that I feel is GenAI written. To be fair, I am fine with AI editing help (MS Word has it, Grammarly, and all the other AI forced upon us does impact our writing). I attempted to link to a buying source (Amazon or other) if it exists, and if Amazon, I’ll get a nickel if you buy a book. Just so you know. Some books aren’t available online anymore, but I listed them for historical purposes.
Have we gotten better at writing about finding evidence while getting worse at writing about investigating people?
Comments welcome on LinkedIn: https://www.linkedin.com/posts/brettshavers_dfir-digitalforensics-incidentresponse-share-7496272517565722624-uAqP/
-
U.S. Courts: E-discovery and 2006 FRCP amendments (https://www.uscourts.gov/file/document/e-discovery-discovery)
-
Microsoft: Facts About Microsoft (Windows 95, XP, Windows 10 dates) (https://news.microsoft.com/facts-about-microsoft/)
-
Microsoft: Windows 10 lifecycle (https://learn.microsoft.com/en-us/lifecycle/products/windows-10-home-and-pro)
-
Microsoft: Windows 11 availability, Oct. 5, 2021 (https://news.microsoft.com/en-in/windows-11-is-now-available-in-india/)
-
Apple : iPhone introduction, Jan. 9, 2007 (https://www.apple.com/newsroom/2007/01/09Apple-Reinvents-the-Phone-with-iPhone/)
-
Apple: App Store turns 10 (launch July 10, 2008) (https://www.apple.com/newsroom/2018/07/app-store-turns-10/)
-
Android Developers: Android 1.0 launched Sept. 2008 (https://android-developers.googleblog.com/2010/05/android-22-and-developers-goodies.html)
-
NSF: Birth of the Commercial Internet (https://www.nsf.gov/impacts/internet)
-
DOJ CCIPS: Electronic-evidence manuals and DF methodology (https://www.justice.gov/criminal-ccips/ccips-documents-and-reports)
-
NIST: SP 800-101 Rev.1, Guidelines on Mobile Device Forensics (https://csrc.nist.gov/pubs/sp/800/101/r1/final)
-
OpenAI: Introducing ChatGPT, Nov. 30, 2022 (https://openai.com/index/chatgpt/)
-
Reuters : ChatGPT launches boom in AI-written e-books on Amazon (https://www.reuters.com/technology/chatgpt-launches-boom-ai-written-e-books-amazon-2023-02-21/)
-
Authors Guild : Amazon AI-generated-content disclosure policy (https://authorsguild.org/news/amazons-new-disclosure-policy-for-ai-generated-book-content-is-a-welcome-first-step/)
-
Authors Guild : AI is driving a surge of sham books on Amazon (https://authorsguild.org/news/ai-driving-new-surge-of-sham-books-on-amazon/)
-
Authors Guild : KDP generative-AI policy and daily publishing caps (https://authorsguild.org/news/amazon-adds-to-kdp-generative-ai-policy-caps-daily-self-publishing-uploads/)
-
Taylor & Francis: Against Cybercrime (Kevin F. Steinmetz, 2023) (https://www.taylorfrancis.com/books/mono/10.4324/9781003277996/cybercrime-kevin-steinmetz)




