Becoming a DART Engineer — Foundations
A living field manual, growing one reel at a time. Every day of the "Becoming a DART Engineer" series adds a new section below — by the end of the series this becomes a complete introduction to the role.
Day 01 — What Is a DART Engineer?
A DART/DFIR engineer is the person who gets called in after something bad has already happened on a network. Concretely, the job is:
- Collecting forensic evidence from endpoints and servers (live and offline)
- Rebuilding an incident timeline from disk, memory, and log artifacts
- Identifying Indicators of Compromise (IOCs)
- Scoping the blast radius — which systems, accounts, and data were touched
- Containing and eradicating the threat
- Supporting recovery
- Writing the root-cause report for leadership or regulators
This is modeled on real teams: Microsoft's DART (Detection and Response Team — roughly 4,500 engagements in 2024) and Google's Mandiant Incident Response practice (2-hour SLA for retainer clients).
How This Differs From Adjacent Roles
| Role | Focus |
|---|---|
| SOC Analyst (Tier 1/2) | First line of defense — triage the alert queue in near-real-time. High volume, shallow depth. |
| Threat Hunter | Proactive, hypothesis-driven — assumes an attacker is already inside undetected and goes looking without waiting for an alert. |
| Forensics Examiner | Narrower and deeper — evidence collection, preservation, chain of custody, sometimes for legal proceedings. |
| DFIR / DART Engineer | Synthesizes all of the above — forensic technique plus threat-hunting mindset, under incident-response time pressure. |
SANS' own DFIR taxonomy names these as overlapping specializations within one discipline, not a strict hierarchy — smaller companies often have one person doing all of it; larger orgs (and consultancies like Mandiant) split them into dedicated teams.
The Incident Response Lifecycle (NIST SP 800-61)
The classic four-phase model every SOC/DART job posting and cert (like GCIH) still references:
- Preparation — runbooks, escalation paths, SIEM/EDR access set up before anything fires
- Detection & Analysis — the alert-triage phase: is this actually an incident?
- Containment, Eradication & Recovery — stop the bleeding, remove the root cause, restore normal operation
- Post-Incident Activity — the lessons-learned review that feeds back into Preparation
(Note: NIST formally withdrew Rev. 2 in April 2025 in favor of Rev. 3, but the four-phase model above is still what's universally taught — you'll see it everywhere in this field.)
---
Sources: Microsoft DART blog & Tech Community, Google Cloud/Mandiant, SANS Institute, NIST SP 800-61 Rev. 2/3.