Leanpub Header

Skip to main content

Building GenAI Systems for DFIR

Designing Trustwothy GenAI Applications for Digital Forensics & Incident Responders

This book presents an architecture-first approach to designing trustworthy GenAI applications. Using Digital Forensics and Incident Response (DFIR) as a continuous case study, you will progressively build an AI-assisted investigation system. If you want to move beyond building AI applications that simply work, and start architecting AI systems that professionals can trust, this book is for you.

Minimum price

$9.00

$19.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
About

About

About the Book

Generative AI has transformed the way cybersecurity applications are built. With today's AI Coding Assistants, developers can generate working software in minutes, build Retrieval-Augmented Generation (RAG) systems with minimal effort, and orchestrate sophisticated agentic workflows using modern AI frameworks. Yet an important question remains:

How do we know that these applications can be trusted?

This book argues that trustworthiness is not achieved through better prompts, larger language models, or more sophisticated frameworks alone. Instead, trustworthy GenAI applications are built through good architecture.

Using Digital Forensics and Incident Response (DFIR) as a continuous case study, this book introduces a practical methodology for designing trustworthy Generative AI applications. Rather than focusing on individual technologies, each chapter addresses a specific architectural challenge—from Prompt Engineering and Retrieval-Augmented Generation (RAG) to Agentic AI—and introduces one design principle that improves the trustworthiness of the overall system.

Throughout the book, you will progressively build a GenAI-assisted DFIR application that evolves from a simple prompt-based prototype into a governed, enterprise-ready agentic system. Along the way, you will learn how to:

  • design applications before writing code;
  • collaborate effectively with AI Coding Assistants;
  • constrain LLM reasoning appropriately;
  • integrate Retrieval-Augmented Generation responsibly;
  • preserve evidence, provenance, and investigation state;
  • delegate deterministic work to specialised software components;
  • govern autonomous behaviour using explicit architectural policies.

Unlike many books that concentrate on programming frameworks or implementation libraries, this book emphasises architectural thinking. Every chapter begins with an Implementation Specification that communicates design intent to an AI Coding Assistant, demonstrating how human architects remain responsible for system design while AI accelerates implementation.

By the end of the book, you will have learned a complete methodology built around the Ten Principles of Trustworthy GenAI Application Design. Although demonstrated using DFIR, these principles apply broadly to any domain where AI-generated outputs influence important decisions, including healthcare, finance, engineering, legal practice, and regulatory compliance.

Whether you are a cybersecurity practitioner, software architect, AI engineer, researcher, or educator, this book aims to help you move beyond building AI applications that merely work—to architecting AI systems that professionals can trust.

Author

About the Author

Jonathan Pan

Dr Jonathan Pan is an Associate Professor (adjunct) at Nanyang Technological University, Singapore, where he teaches Cyber Security (technology, governance, incident response and digital forensics) and Generative AI Applications (applied) to post graduate students. He also has an Adjunct Associate Professor role with The University of Queensland, Australia. He currently leads a multi-disciplinary team of researchers exploring emerging frontier technologies such as artificial intelligence, quantum and space technologies for public safety applications. His past roles expands deep within cybersecurity domain including CISO leadership roles.

Jonathan’s teaching and writing focus on helping cyber security and AI learners and practitioners design responsible, evidence-grounded Generative AI systems.

Contents

Table of Contents

Preface

  1. Why This Book Was Written

The Central Thesis of This Book

The Learning Philosophy of This Book

The Ten Architectural Principles

Why Digital Forensics and Incident Response?

Learning with AI

Architecture Before Implementation

Dataset Independence

Verification Is Part of the Architecture

A Final Word

The Ten Architectural Principles of Trustworthy GenAI Systems for Digital Forensics and Incident Response

  1. Principle 1 — Architecture Precedes Prompting
  2. Principle 2 — Constrain the Reasoning Boundary
  3. Principle 3 — Separate Observation from Interpretation
  4. Principle 4 — Preserve Ambiguity
  5. Principle 5 — Retrieve Before You Reason
  6. Principle 6 — Separate Evidence from Knowledge
  7. Principle 7 — Preserve Provenance
  8. Principle 8 — Memory Stores State, Not Conclusions
  9. Principle 9 — Prefer Deterministic Computation
  10. Principle 10 — Capability Requires Governance

The Reader’s Journey

  1. Looking Ahead

Chapter 1

Architecting Trustworthy GenAI Applications for Cybersecurity

Learning Objectives

1.1 Why Trustworthiness Matters

  1. Architect’s Note

1.2 The Journey Through This Book

  1. Part I – Prompt Engineering
  2. Part II – Retrieval-Augmented Generation
  3. Part III – Agentic AI
  4. Architect’s Note

1.3 Why We Design Before We Build

  1. Architect’s Note

1.4 The Role of the Human Architect

  1. Architect’s Note

1.5 A Running DFIR Case Study

  1. Architect’s Note

1.6 Developing the First Implementation Specification

  1. Architect’s Note

1.7 The First Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

1.8 Working with the AI Coding Assistant

  1. Architect’s Note

1.9 Reviewing Generated Software

  1. Architect’s Note

1.10 Preparing for Prompt Engineering

  1. Architect’s Note

1.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Architect’s Note

1.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist
  2. Architect’s Note

1.13 Chapter Summary

Architectural Reflection

End of Chapter 1

Chapter 2

Prompt Engineering I: Building Your First Trustworthy GenAI Application

  1. Learning Objectives

2.1 From Large Language Models to GenAI Applications

  1. Architect’s Note

2.2 DFIR Scenario

2.3 The First Trustworthy GenAI Architecture

  1. Architect’s Note

2.4 Designing the Data Contract

2.5 Why Prompt Engineering Is About Reasoning Boundaries

  1. Architect’s Note

2.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

2.7 Designing the Prompt

2.8 Context Windows and Log Chunking

  1. Architect’s Note

2.9 Working with an AI Coding Assistant

2.10 Reviewing the Generated Implementation

  1. Architect’s Note

2.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Architect’s Note

2.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

2.13 Applying the Architecture Beyond Linux

  1. Architect’s Note

2.14 Limitations of Prompt Engineering

2.15 Chapter Summary

Architectural Reflection and Extension

End of Chapter 2

Chapter 3

Prompt Engineering II: Detecting Credential Misuse Through Evidence-Based Reasoning

  1. Learning Objectives

3.1 Beyond Explaining Individual Events

  1. Architect’s Note

3.2 DFIR Scenario

3.3 Architectural Principle 3 – Separate Observation from Interpretation

  1. Observable Authentication Behaviour
  2. Analytical Observations
  3. Architect’s Note

3.4 Extending the Architecture

  1. Architect’s Note

3.5 Designing the Data Contract

3.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

3.7 Designing a Trustworthy Analytical Prompt

3.8 Behaviour Aggregation Before Reasoning

  1. Architect’s Note

3.9 Working with the AI Coding Assistant

3.10 Reviewing the Generated Architecture

  1. Architect’s Note

3.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Evidential Verification
  4. Architect’s Note

3.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

3.13 Applying the Architecture Beyond Authentication Logs

  1. Architect’s Note

3.14 Limitations of the Current Architecture

3.15 Chapter Summary

Architectural Reflection and Extension

End of Chapter 3

Chapter 4

Prompt Engineering III: Managing Investigative Uncertainty Through Multi-Stage Reasoning

Learning Objectives

4.1 Investigations Rarely Produce Complete Answers

  1. Architect’s Note

4.2 DFIR Scenario

4.3 Architectural Principle 4 – Preserve Ambiguity

  1. Architect’s Note

4.4 Extending the Architecture

  1. Architect’s Note

4.5 Designing the Data Contract

4.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

4.7 Designing the Prompt

4.8 Deterministic Identification of Evidence Gaps

  1. Architect’s Note

4.9 Working with the AI Coding Assistant

4.10 Reviewing the Generated Architecture

  1. Architect’s Note

4.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Uncertainty Verification
  4. Architect’s Note

4.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

4.13 Applying the Architecture Beyond Authentication Investigations

  1. Architect’s Note

4.14 The Architectural Limits of Prompt Engineering

4.15 Chapter Summary

Architectural Reflection and Extension

End of Chapter 4

Chapter 5

Retrieval-Augmented Generation I: Grounding Investigations with External Knowledge

Learning Objectives

5.1 When Prompt Engineering Reaches Its Limit

  1. Architect’s Note

5.2 DFIR Scenario

5.3 Architectural Principle 5 – Retrieve Before You Reason

  1. Architect’s Note

5.4 Extending the Architecture

  1. Architect’s Note

5.5 Designing the Data Contract

  1. Investigative Evidence
  2. Retrieved Reference Knowledge

5.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

5.7 Why Retrieval Requires a Knowledge Base

5.8 Understanding Embeddings and Vector Databases

  1. Architect’s Note

5.9 Retrieval Before Prompt Construction

5.10 Working with the AI Coding Assistant

5.11 Reviewing the Generated Architecture

  1. Architect’s Note

5.12 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Retrieval Verification
  4. Architect’s Note

5.13 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

5.14 Applying the Architecture Beyond Linux Commands

  1. Architect’s Note

5.15 Common Retrieval Failure Modes

  1. Architect’s Note

5.16 The Architectural Limits of Retrieval-Augmented Generation

5.17 Chapter Summary

Architectural Reflection and Extension

End of Chapter 5

Chapter 6

Retrieval-Augmented Generation II: Integrating Evidence and Knowledge in DFIR Investigations

Learning Objectives

6.1 Retrieval Does Not Replace Investigation

  1. Architect’s Note

6.2 DFIR Scenario

6.3 Architectural Principle 6 — Separate Evidence from Knowledge

  1. Architect’s Note

6.4 Extending the Architecture

  1. Architect’s Note

6.5 Designing the Data Contract

  1. Investigative Evidence
  2. Retrieved Knowledge
  3. Knowledge Provenance

6.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

6.7 Designing the Prompt

6.8 Integrating Multiple Knowledge Sources

  1. Architect’s Note

6.9 Working with the AI Coding Assistant

6.10 Reviewing the Generated Architecture

  1. Architect’s Note

6.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Evidential Integrity Verification
  4. Architect’s Note

6.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

6.13 Applying the Architecture Beyond Endpoint Investigations

  1. Architect’s Note

6.14 Common Knowledge Integration Failure Modes

  1. Architect’s Note

6.15 The Architectural Limits of Multi-Source RAG

6.16 Chapter Summary

Architectural Reflection and Extension

End of Chapter 6

Chapter 7

Retrieval-Augmented Generation III: Building Traceable Investigation Reports

Learning Objectives

7.1 Trust Depends on Traceability

  1. Architect’s Note

7.2 DFIR Scenario

7.3 Architectural Principle 7 — Preserve Provenance

  1. Architect’s Note

7.4 Extending the Architecture

  1. Architect’s Note

7.5 Designing the Data Contract

  1. Investigative Evidence
  2. Retrieved Knowledge
  3. Provenance Metadata
  4. Generated Report Objects

7.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

7.7 Designing a Provenance-Aware Prompt

7.8 Building the Provenance Builder

  1. Architect’s Note

7.9 Working with the AI Coding Assistant

7.10 Reviewing the Generated Architecture

  1. Architect’s Note

7.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Provenance Verification
  4. Architect’s Note

7.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

7.13 Applying the Architecture Beyond DFIR

  1. Architect’s Note

7.14 Common Provenance Failure Modes

  1. Architect’s Note

7.15 The Architectural Limits of Retrieval-Augmented Generation

7.16 Chapter Summary

Architectural Reflection and Extension

End of Chapter 7

Chapter 8

Agentic AI I: Building Stateful DFIR Investigations

Learning Objectives

8.1 Investigations Are Conversations With Evidence

  1. Architect’s Note

8.2 DFIR Scenario

8.3 Architectural Principle 8 — Preserve Investigation State

  1. Architect’s Note

8.4 Extending the Architecture

  1. Architect’s Note

8.5 Designing the Investigation State Model

  1. Investigation Overview
  2. Evidence Summary
  3. Investigative Progress
  4. Knowledge History
  5. Analyst Decisions

8.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

8.7 Designing the Prompt

8.8 Designing the State Manager

  1. Architect’s Note

8.9 Working with the AI Coding Assistant

8.10 Reviewing the Generated Architecture

  1. Architect’s Note

8.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. State Verification
  4. Architect’s Note

8.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

8.13 Applying the Architecture Beyond DFIR

  1. Architect’s Note

8.14 Common Investigation State Failure Modes

  1. Architect’s Note

8.15 The Architectural Limits of Investigation State

8.16 Chapter Summary

Architectural Reflection and Extension

End of Chapter 8

Chapter 9

Agentic AI II: Integrating Deterministic Skills into Trustworthy DFIR Applications

Learning Objectives

9.1 Not Every Problem Requires an LLM

  1. Architect’s Note

9.2 DFIR Scenario

9.3 Architectural Principle 9 — Delegate Deterministic Work to Deterministic Components

  1. Architect’s Note

9.4 Extending the Architecture

  1. Architect’s Note

9.5 Designing the Skill Model

  1. Evidence Processing Skills
  2. Cryptographic Skills
  3. Windows Skills
  4. Linux Skills
  5. Threat Intelligence Skills

9.6 Developing the Implementation Specification

  1. Implementation Specification
  2. Architect’s Note

9.7 Designing the Prompt

9.8 Designing the Skill Orchestrator

  1. Architect’s Note

9.9 Working with the AI Coding Assistant

9.10 Reviewing the Generated Architecture

  1. Architect’s Note

9.11 Verifying the Application

  1. Functional Verification
  2. Architectural Verification
  3. Skill Verification
  4. Architect’s Note

9.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

9.13 Applying the Architecture Beyond DFIR

  1. Architect’s Note

9.14 Common Skill Orchestration Failure Modes

  1. Architect’s Note

9.15 The Architectural Limits of Skill-Enabled Agents

9.16 Chapter Summary

Architectural Reflection and Extension

End of Chapter 9

Chapter 10

Agentic AI III: Governing Trustworthy DFIR Agents

Learning Objectives

10.1 Capability Does Not Imply Authority

  1. Architect’s Note

10.2 DFIR Scenario

10.3 Architectural Principle 10 — Govern the Agent, Not Just the Model

  1. Architect’s Note

10.4 Completing the Architecture

  1. Architect’s Note

10.5 Designing the Governance Model

  1. Informational Actions
  2. Investigative Actions
  3. Operational Actions
  4. Restricted Actions

10.6 Developing the Master Implementation Specification

Master Implementation Specification

  1. Objective
  2. System Architecture
  3. Data Contract
  4. Functional Requirements
  5. Reasoning Constraints
  6. Suggested Technology Stack
  7. Verification Requirements
  8. Architect’s Note

10.7 Designing the Governance Engine

  1. Example Policy Rules
  2. Architect’s Note

10.8 Designing the Policy Enforcement Layer

  1. Architect’s Note

10.9 Working with the AI Coding Assistant

10.10 Reviewing the Complete Architecture

  1. Architect’s Note

10.11 Verifying the Complete Application

  1. Functional Verification
  2. Architectural Verification
  3. Governance Verification
  4. Architect’s Note

10.12 AI Coding Assistant Review Checklist

  1. AI Coding Assistant Review Checklist

10.13 Common Governance Failure Modes

  1. Architect’s Note

10.14 The Ten Trustworthiness Principles

  1. Architect’s Note

10.15 Beyond Digital Forensics

10.16 Final Reflection

Final Architectural Reflection

End of Chapter 10

Appendix A

The Ten Trustworthiness Principles

Appendix B

Master Implementation Specification Template

Appendix C

AI Coding Assistant Prompt Templates

  1. Template 1 — Build a New Application
  2. Template 2 — Extend an Existing Architecture
  3. Template 3 — Review Generated Software
  4. Template 4 — Refactor the Architecture
  5. Template 5 — Generate Tests

Appendix D

Master Architectural Review Checklist

  1. Architecture
  2. Language Model
  3. Retrieval
  4. Provenance
  5. Investigation State
  6. Deterministic Skills
  7. Governance
  8. Overall Trustworthiness

Appendix E

Applying the Methodology Beyond DFIR

Final Note

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub