Convergent vs Divergent Thinking in DFIR

These two thinking modes are the mental engine behind every good investigation.

Divergent thinking

Cast a wide net. You do not know the answer yet, so you explore broadly.

In event log investigation this means:
- Listing all available logs
- Sampling recent events without heavy filters
- Searching by vague keywords like boot, shutdown, started, stopped
- Reading full messages to build intuition

It is slow, messy, and necessary. You use it when you do not yet know what you are looking for.

Convergent thinking

Narrow the field. You have built hypotheses and now test them with precise rules.

In event log investigation this means:
- Filtering by specific event IDs
- Filtering by time ranges
- Using XPath so the machine does the narrowing
- Blacklisting or whitelisting event sources

It is fast, strict, and dangerous if your assumptions are wrong.

The blacklist approach: convergent by exclusion

Sometimes you do not know the exact signal, but you know the noise. You converge by removing what the event is not.

Example: find the last boot event by removing everything that is clearly not a boot event.

Get-WinEvent -LogName System -MaxEvents 500 |
Where-Object {
    $_.Id -notin 1014, 2502, 2503, 8015, 10016, 55, 6008, 41 -and
    $_.ProviderName -notmatch 'DNS|Tcpip|WHEA|BugCheck|User32|Kernel-Power'
} |
Select-Object TimeCreated, Id, ProviderName, Message

Then inspect the survivors and refine the blacklist. Repeat until the event pattern is isolated.

Why both modes matter

Mode Question Risk
Divergent What could this be? Drowning in data
Convergent Is this exactly it? Missing the real event

A good investigator switches between them. Start divergent, switch to convergent once you have a hypothesis, then diverge again if the hypothesis fails.

Mapping to the 7-step strategy

Key rule

Never let a blacklist become invisible. Document every excluded ID and source. A blacklisted item is still a hypothesis, and it must be defensible if the case is reviewed.