‹ The Security Monk
🧬

Becoming a DART Engineer — Foundations

A living field manual, growing one reel at a time. Every day of the "Becoming a DART Engineer" series adds a new section below — by the end of the series this becomes a complete introduction to the role.

Day 01 — What Is a DART Engineer?

A DART/DFIR engineer is the person who gets called in after something bad has already happened on a network. Concretely, the job is:

  • Collecting forensic evidence from endpoints and servers (live and offline)
  • Rebuilding an incident timeline from disk, memory, and log artifacts
  • Identifying Indicators of Compromise (IOCs)
  • Scoping the blast radius — which systems, accounts, and data were touched
  • Containing and eradicating the threat
  • Supporting recovery
  • Writing the root-cause report for leadership or regulators

This is modeled on real teams: Microsoft's DART (Detection and Response Team — roughly 4,500 engagements in 2024) and Google's Mandiant Incident Response practice (2-hour SLA for retainer clients).

How This Differs From Adjacent Roles

RoleFocus
SOC Analyst (Tier 1/2)First line of defense — triage the alert queue in near-real-time. High volume, shallow depth.
Threat HunterProactive, hypothesis-driven — assumes an attacker is already inside undetected and goes looking without waiting for an alert.
Forensics ExaminerNarrower and deeper — evidence collection, preservation, chain of custody, sometimes for legal proceedings.
DFIR / DART EngineerSynthesizes all of the above — forensic technique plus threat-hunting mindset, under incident-response time pressure.

SANS' own DFIR taxonomy names these as overlapping specializations within one discipline, not a strict hierarchy — smaller companies often have one person doing all of it; larger orgs (and consultancies like Mandiant) split them into dedicated teams.

The Incident Response Lifecycle (NIST SP 800-61)

The classic four-phase model every SOC/DART job posting and cert (like GCIH) still references:

  1. Preparation — runbooks, escalation paths, SIEM/EDR access set up before anything fires
  2. Detection & Analysis — the alert-triage phase: is this actually an incident?
  3. Containment, Eradication & Recovery — stop the bleeding, remove the root cause, restore normal operation
  4. Post-Incident Activity — the lessons-learned review that feeds back into Preparation

(Note: NIST formally withdrew Rev. 2 in April 2025 in favor of Rev. 3, but the four-phase model above is still what's universally taught — you'll see it everywhere in this field.)

---

Sources: Microsoft DART blog & Tech Community, Google Cloud/Mandiant, SANS Institute, NIST SP 800-61 Rev. 2/3.