Preface
- Why This Book Was Written
The Central Thesis of This Book
The Learning Philosophy of This Book
The Ten Architectural Principles
Why Digital Forensics and Incident Response?
Learning with AI
Architecture Before Implementation
Dataset Independence
Verification Is Part of the Architecture
A Final Word
The Ten Architectural Principles of Trustworthy GenAI Systems for Digital Forensics and Incident Response
- Principle 1 — Architecture Precedes Prompting
- Principle 2 — Constrain the Reasoning Boundary
- Principle 3 — Separate Observation from Interpretation
- Principle 4 — Preserve Ambiguity
- Principle 5 — Retrieve Before You Reason
- Principle 6 — Separate Evidence from Knowledge
- Principle 7 — Preserve Provenance
- Principle 8 — Memory Stores State, Not Conclusions
- Principle 9 — Prefer Deterministic Computation
- Principle 10 — Capability Requires Governance
The Reader’s Journey
- Looking Ahead
Chapter 1
Architecting Trustworthy GenAI Applications for Cybersecurity
Learning Objectives
1.1 Why Trustworthiness Matters
- Architect’s Note
1.2 The Journey Through This Book
- Part I – Prompt Engineering
- Part II – Retrieval-Augmented Generation
- Part III – Agentic AI
- Architect’s Note
1.3 Why We Design Before We Build
- Architect’s Note
1.4 The Role of the Human Architect
- Architect’s Note
1.5 A Running DFIR Case Study
- Architect’s Note
1.6 Developing the First Implementation Specification
- Architect’s Note
1.7 The First Implementation Specification
- Implementation Specification
- Architect’s Note
1.8 Working with the AI Coding Assistant
- Architect’s Note
1.9 Reviewing Generated Software
- Architect’s Note
1.10 Preparing for Prompt Engineering
- Architect’s Note
1.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Architect’s Note
1.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
- Architect’s Note
1.13 Chapter Summary
Architectural Reflection
End of Chapter 1
Chapter 2
Prompt Engineering I: Building Your First Trustworthy GenAI Application
- Learning Objectives
2.1 From Large Language Models to GenAI Applications
- Architect’s Note
2.2 DFIR Scenario
2.3 The First Trustworthy GenAI Architecture
- Architect’s Note
2.4 Designing the Data Contract
2.5 Why Prompt Engineering Is About Reasoning Boundaries
- Architect’s Note
2.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
2.7 Designing the Prompt
2.8 Context Windows and Log Chunking
- Architect’s Note
2.9 Working with an AI Coding Assistant
2.10 Reviewing the Generated Implementation
- Architect’s Note
2.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Architect’s Note
2.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
2.13 Applying the Architecture Beyond Linux
- Architect’s Note
2.14 Limitations of Prompt Engineering
2.15 Chapter Summary
Architectural Reflection and Extension
End of Chapter 2
Chapter 3
Prompt Engineering II: Detecting Credential Misuse Through Evidence-Based Reasoning
- Learning Objectives
3.1 Beyond Explaining Individual Events
- Architect’s Note
3.2 DFIR Scenario
3.3 Architectural Principle 3 – Separate Observation from Interpretation
- Observable Authentication Behaviour
- Analytical Observations
- Architect’s Note
3.4 Extending the Architecture
- Architect’s Note
3.5 Designing the Data Contract
3.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
3.7 Designing a Trustworthy Analytical Prompt
3.8 Behaviour Aggregation Before Reasoning
- Architect’s Note
3.9 Working with the AI Coding Assistant
3.10 Reviewing the Generated Architecture
- Architect’s Note
3.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Evidential Verification
- Architect’s Note
3.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
3.13 Applying the Architecture Beyond Authentication Logs
- Architect’s Note
3.14 Limitations of the Current Architecture
3.15 Chapter Summary
Architectural Reflection and Extension
End of Chapter 3
Chapter 4
Prompt Engineering III: Managing Investigative Uncertainty Through Multi-Stage Reasoning
Learning Objectives
4.1 Investigations Rarely Produce Complete Answers
- Architect’s Note
4.2 DFIR Scenario
4.3 Architectural Principle 4 – Preserve Ambiguity
- Architect’s Note
4.4 Extending the Architecture
- Architect’s Note
4.5 Designing the Data Contract
4.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
4.7 Designing the Prompt
4.8 Deterministic Identification of Evidence Gaps
- Architect’s Note
4.9 Working with the AI Coding Assistant
4.10 Reviewing the Generated Architecture
- Architect’s Note
4.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Uncertainty Verification
- Architect’s Note
4.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
4.13 Applying the Architecture Beyond Authentication Investigations
- Architect’s Note
4.14 The Architectural Limits of Prompt Engineering
4.15 Chapter Summary
Architectural Reflection and Extension
End of Chapter 4
Chapter 5
Retrieval-Augmented Generation I: Grounding Investigations with External Knowledge
Learning Objectives
5.1 When Prompt Engineering Reaches Its Limit
- Architect’s Note
5.2 DFIR Scenario
5.3 Architectural Principle 5 – Retrieve Before You Reason
- Architect’s Note
5.4 Extending the Architecture
- Architect’s Note
5.5 Designing the Data Contract
- Investigative Evidence
- Retrieved Reference Knowledge
5.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
5.7 Why Retrieval Requires a Knowledge Base
5.8 Understanding Embeddings and Vector Databases
- Architect’s Note
5.9 Retrieval Before Prompt Construction
5.10 Working with the AI Coding Assistant
5.11 Reviewing the Generated Architecture
- Architect’s Note
5.12 Verifying the Application
- Functional Verification
- Architectural Verification
- Retrieval Verification
- Architect’s Note
5.13 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
5.14 Applying the Architecture Beyond Linux Commands
- Architect’s Note
5.15 Common Retrieval Failure Modes
- Architect’s Note
5.16 The Architectural Limits of Retrieval-Augmented Generation
5.17 Chapter Summary
Architectural Reflection and Extension
End of Chapter 5
Chapter 6
Retrieval-Augmented Generation II: Integrating Evidence and Knowledge in DFIR Investigations
Learning Objectives
6.1 Retrieval Does Not Replace Investigation
- Architect’s Note
6.2 DFIR Scenario
6.3 Architectural Principle 6 — Separate Evidence from Knowledge
- Architect’s Note
6.4 Extending the Architecture
- Architect’s Note
6.5 Designing the Data Contract
- Investigative Evidence
- Retrieved Knowledge
- Knowledge Provenance
6.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
6.7 Designing the Prompt
6.8 Integrating Multiple Knowledge Sources
- Architect’s Note
6.9 Working with the AI Coding Assistant
6.10 Reviewing the Generated Architecture
- Architect’s Note
6.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Evidential Integrity Verification
- Architect’s Note
6.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
6.13 Applying the Architecture Beyond Endpoint Investigations
- Architect’s Note
6.14 Common Knowledge Integration Failure Modes
- Architect’s Note
6.15 The Architectural Limits of Multi-Source RAG
6.16 Chapter Summary
Architectural Reflection and Extension
End of Chapter 6
Chapter 7
Retrieval-Augmented Generation III: Building Traceable Investigation Reports
Learning Objectives
7.1 Trust Depends on Traceability
- Architect’s Note
7.2 DFIR Scenario
7.3 Architectural Principle 7 — Preserve Provenance
- Architect’s Note
7.4 Extending the Architecture
- Architect’s Note
7.5 Designing the Data Contract
- Investigative Evidence
- Retrieved Knowledge
- Provenance Metadata
- Generated Report Objects
7.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
7.7 Designing a Provenance-Aware Prompt
7.8 Building the Provenance Builder
- Architect’s Note
7.9 Working with the AI Coding Assistant
7.10 Reviewing the Generated Architecture
- Architect’s Note
7.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Provenance Verification
- Architect’s Note
7.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
7.13 Applying the Architecture Beyond DFIR
- Architect’s Note
7.14 Common Provenance Failure Modes
- Architect’s Note
7.15 The Architectural Limits of Retrieval-Augmented Generation
7.16 Chapter Summary
Architectural Reflection and Extension
End of Chapter 7
Chapter 8
Agentic AI I: Building Stateful DFIR Investigations
Learning Objectives
8.1 Investigations Are Conversations With Evidence
- Architect’s Note
8.2 DFIR Scenario
8.3 Architectural Principle 8 — Preserve Investigation State
- Architect’s Note
8.4 Extending the Architecture
- Architect’s Note
8.5 Designing the Investigation State Model
- Investigation Overview
- Evidence Summary
- Investigative Progress
- Knowledge History
- Analyst Decisions
8.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
8.7 Designing the Prompt
8.8 Designing the State Manager
- Architect’s Note
8.9 Working with the AI Coding Assistant
8.10 Reviewing the Generated Architecture
- Architect’s Note
8.11 Verifying the Application
- Functional Verification
- Architectural Verification
- State Verification
- Architect’s Note
8.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
8.13 Applying the Architecture Beyond DFIR
- Architect’s Note
8.14 Common Investigation State Failure Modes
- Architect’s Note
8.15 The Architectural Limits of Investigation State
8.16 Chapter Summary
Architectural Reflection and Extension
End of Chapter 8
Chapter 9
Agentic AI II: Integrating Deterministic Skills into Trustworthy DFIR Applications
Learning Objectives
9.1 Not Every Problem Requires an LLM
- Architect’s Note
9.2 DFIR Scenario
9.3 Architectural Principle 9 — Delegate Deterministic Work to Deterministic Components
- Architect’s Note
9.4 Extending the Architecture
- Architect’s Note
9.5 Designing the Skill Model
- Evidence Processing Skills
- Cryptographic Skills
- Windows Skills
- Linux Skills
- Threat Intelligence Skills
9.6 Developing the Implementation Specification
- Implementation Specification
- Architect’s Note
9.7 Designing the Prompt
9.8 Designing the Skill Orchestrator
- Architect’s Note
9.9 Working with the AI Coding Assistant
9.10 Reviewing the Generated Architecture
- Architect’s Note
9.11 Verifying the Application
- Functional Verification
- Architectural Verification
- Skill Verification
- Architect’s Note
9.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
9.13 Applying the Architecture Beyond DFIR
- Architect’s Note
9.14 Common Skill Orchestration Failure Modes
- Architect’s Note
9.15 The Architectural Limits of Skill-Enabled Agents
9.16 Chapter Summary
Architectural Reflection and Extension
End of Chapter 9
Chapter 10
Agentic AI III: Governing Trustworthy DFIR Agents
Learning Objectives
10.1 Capability Does Not Imply Authority
- Architect’s Note
10.2 DFIR Scenario
10.3 Architectural Principle 10 — Govern the Agent, Not Just the Model
- Architect’s Note
10.4 Completing the Architecture
- Architect’s Note
10.5 Designing the Governance Model
- Informational Actions
- Investigative Actions
- Operational Actions
- Restricted Actions
10.6 Developing the Master Implementation Specification
Master Implementation Specification
- Objective
- System Architecture
- Data Contract
- Functional Requirements
- Reasoning Constraints
- Suggested Technology Stack
- Verification Requirements
- Architect’s Note
10.7 Designing the Governance Engine
- Example Policy Rules
- Architect’s Note
10.8 Designing the Policy Enforcement Layer
- Architect’s Note
10.9 Working with the AI Coding Assistant
10.10 Reviewing the Complete Architecture
- Architect’s Note
10.11 Verifying the Complete Application
- Functional Verification
- Architectural Verification
- Governance Verification
- Architect’s Note
10.12 AI Coding Assistant Review Checklist
- AI Coding Assistant Review Checklist
10.13 Common Governance Failure Modes
- Architect’s Note
10.14 The Ten Trustworthiness Principles
- Architect’s Note
10.15 Beyond Digital Forensics
10.16 Final Reflection
Final Architectural Reflection
End of Chapter 10
Appendix A
The Ten Trustworthiness Principles
Appendix B
Master Implementation Specification Template
Appendix C
AI Coding Assistant Prompt Templates
- Template 1 — Build a New Application
- Template 2 — Extend an Existing Architecture
- Template 3 — Review Generated Software
- Template 4 — Refactor the Architecture
- Template 5 — Generate Tests
Appendix D
Master Architectural Review Checklist
- Architecture
- Language Model
- Retrieval
- Provenance
- Investigation State
- Deterministic Skills
- Governance
- Overall Trustworthiness
Appendix E
Applying the Methodology Beyond DFIR
Final Note