The episode discusses the challenges of knowing when to stop an investigation if no findings are present.
Starting an investigation—be it for troubleshooting, problem diagnosis, threat hunting, incident response, and so on—is fairly straightforward. There’s a question or thesis you’re pursuing, you have logs and data sources to check, and you have tools to deploy. But if you don’t find anything, does that mean there was nothing to find? Are you sure ... Read more »