Convergent vs Divergent Thinking in DFIR
These two thinking modes are the mental engine behind every good investigation.
Divergent thinking
Cast a wide net. You do not know the answer yet, so you explore broadly.
In event log investigation this means:
- Listing all available logs
- Sampling recent events without heavy filters
- Searching by vague keywords like boot, shutdown, started, stopped
- Reading full messages to build intuition
It is slow, messy, and necessary. You use it when you do not yet know what you are looking for.
Convergent thinking
Narrow the field. You have built hypotheses and now test them with precise rules.
In event log investigation this means:
- Filtering by specific event IDs
- Filtering by time ranges
- Using XPath so the machine does the narrowing
- Blacklisting or whitelisting event sources
It is fast, strict, and dangerous if your assumptions are wrong.
The blacklist approach: convergent by exclusion
Sometimes you do not know the exact signal, but you know the noise. You converge by removing what the event is not.
Example: find the last boot event by removing everything that is clearly not a boot event.
Get-WinEvent -LogName System -MaxEvents 500 |
Where-Object {
$_.Id -notin 1014, 2502, 2503, 8015, 10016, 55, 6008, 41 -and
$_.ProviderName -notmatch 'DNS|Tcpip|WHEA|BugCheck|User32|Kernel-Power'
} |
Select-Object TimeCreated, Id, ProviderName, Message
Then inspect the survivors and refine the blacklist. Repeat until the event pattern is isolated.
Why both modes matter
| Mode | Question | Risk |
|---|---|---|
| Divergent | What could this be? | Drowning in data |
| Convergent | Is this exactly it? | Missing the real event |
A good investigator switches between them. Start divergent, switch to convergent once you have a hypothesis, then diverge again if the hypothesis fails.
Mapping to the 7-step strategy
- Steps 1–4 of the Investigative Event Log Discovery Strategy are divergent.
- Steps 5–7 are convergent.
- The blacklist approach is a hybrid: it uses convergent exclusion after a small divergent sample.
Key rule
Never let a blacklist become invisible. Document every excluded ID and source. A blacklisted item is still a hypothesis, and it must be defensible if the case is reviewed.