Showing posts with label civil litigation. Show all posts
Showing posts with label civil litigation. Show all posts

Monday, February 14, 2022

When the Absence of Evidence is Good Evidence

February 14, 2022


When the Absence of Evidence is Good Evidence


Fielding dozens of inquiries every month for nearly 9 years as a digital forensic service provider, we start to get a good sense about what many cases involve, even before the details of an incident are revealed.  Whether the case involves mobile device evidence, computer evidence, cellular records analysis or electronic-based investigation, the general approach to the case, depending on the scope, is about the same.  What many attorneys and their clients are seeking is the proverbial “smoking gun” or “nail in the coffin” of their case.  As we often tell them, that does happen, from time to time.  But it is not the norm.  


More often than not, we are provided data that is lacking or missing something important.  The question then becomes why is the data missing, when did it go missing and who (if anyone) caused it to become missing?  In this game of piecing the digital puzzle together, often what is absent can also be key to the case.  But there are some definite considerations that go along with this notion as well.




The Value of Missing Data


There are circumstances where missing data can tell a decent part of the story.  For instance, on some mobile devices, items in certain areas are stored sequentially and numbers (or indices) in the sequence are not repeated.  Accordingly, if we find that there are missing numbers in the sequence, we can conclude that something was removed from the table that stores this information.  Can we always recover the data itself?  No.  But we can often determine that it was removed and at the very least approximate when it was removed, using process of elimination.


We can further determine the prior existence of this data by:


1) Searching for the likely file names or monikers of the missing data to see if there are any other records of those files being accessed or used on the system or device.

2) Looking at the timeline of activity on the device or system to determine what took place during the time frame that the data is suspected to have been removed.  Many other areas of the device may have been used around these times to help show the overall activity around these times.

3) Looking at patterns of removal of data, either in this or other categories, to see if perhaps a mass-deletion of data may have taken place.  There are always alternative explanations which need to be explored before coming to concrete conclusions.


We can also try to determine if some or all of the missing data might have been stored elsewhere.  Alternative and backup data storage such as computer syncing and cloud-based storage are valuable, common areas that could potentially store either more data and/or the deleted data to help answer these important questions.


The Expert’s Conclusions re: Missing Data


The ultimate goal in missing data analysis is to be able to come to some conclusion within a reasonable degree of certainty.  This is not always easy and it’s almost never 100%.  However, as analysts and Experts who testify in legal matters, digital forensic practitioners can be *mostly* sure about what happened through thorough analysis and testing, depending on the scope of the case and the needs of the Client.  


The important point about our conclusions with regard to when items were deleted, who deleted them and when lies in the thoroughness of our work.  Leaving no stone unturned is a good approach, but it’s also time-consuming and expensive.  Many clients will not want to support this cost expenditure, mostly because they don’t see the need for it.  Ultimately, it is the analyst’s reputation and work that is to be scrutinized in court and by other experts, therefore, the analyst should be steadfast in their calls for whatever measures are appropriate to support their conclusions in court.  Whatever the conclusion(s) is/are, they must be articulated, defensible, repeatable and supported by the data.  Otherwise, they will not pass evidentiary muster and ultimately the client will not be served by the expenditure.


This is another area where peer review can play a vital role.  No digital forensic analyst knows everything about every data storage medium, file system, application, mobile device, etc.  However, with a thoughtful and thorough peer review of the procedures, findings and conclusions, we take another valuable step to validating those conclusions for the finder of fact.   




A Brief Case Study


We once worked a divorce case involving an iPod with internet connectivity.  The husband, our client, found videos on a computer of his wife engaged in sexual relations with another man.  When the Court ordered her devices turned over, including the iPod on which she was suspected to have chatted for months with her paramour, there were no messages found.  However, there were suggestive pictures and videos located on the iPod, which supported the suspicion of chatting behavior.


Additionally, the Court ordered her laptop hard drive to be analyzed.  On the laptop hard drive, there were a number of iPod backup files, nearly all of which contained the application-based chats with the paramour, including their sexually explicit conversations and his admission to killing another person in another state.


Wrapping It Up


We like to take the approach that the data is virtually always somewhere.  But even if it’s not anywhere, we can often find markers, indicators, patterns and evidence that it existed in some form prior to our obtaining the data enough to be able to come to some conclusion about it.  The key lies in the ability, competency & knowledge of the digital forensic analyst to be able to determine what may have happened, when and who is responsible.  Just because it’s not there doesn’t mean your case is dead or that your analyst can’t do anything to help.  Tenacity is a virtue in digital forensics.  Make sure to scrutinize the characteristics of your analyst before asking them to work your case.  Not all analysts (or lawyers or clients or… ) are created equally.


Author: 

Patrick J. Siewert

Founder & Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/  

Wednesday, June 9, 2021

Three FAQs About Digital Forensics as a Service

 June 8, 2021


Three FAQs About Digital Forensics as a Service


There are many tentacles to the practice of digital forensics.  As explored in a previous article, there can be two main tracks to the practice of digital forensics:  Incident Response & Litigation Support.  Along the same vein, there are practitioners both in the public sector (law enforcement, government contractors, etc.) and the private sector.  While the practice is essentially the same across both sectors, the types of cases called upon to work and the complaints or inquiries received can be vastly different.  


When I was a law enforcement examiner, my time was spent mainly investigating criminal incidents involving child sex abuse material (CSAM) and other crimes, such as fraud, cyber-stalking, etc.  After transitioning to the private sector, I found the case inquiries and cases worked to be quite different.  Sure, there’s a minority percentage of cases in the criminal realm, but many of our cases span family law, corporate law, intellectual property theft and other civil disputes.  One of the most notable areas that the shift has occurred has been in the types of inquires receive.  The three questions explored and answered here are designed to provide those would-be clients with answers that they can readily access without the need to contact a forensic service provider and to help provide guidance for some in our industry as a whole.  These questions are taken directly from inquiries we receive weekly.


FAQ #1:  I think someone (estranged spouse, other person) is “hacking” me.  Can you find out who it is?


This is probably the most frequent question we receive and it eats up a ton of time.  Indeed, there are many reasons why someone might feel they’ve been “hacked”, but at a 30,000-foot level, it’s not likely.  Why isn’t it likely?  Well, the first question anyone needs to ask themselves is WHY would someone hack your devices on purpose?  Jeff Bezos’ iPhone was hacked.  He’s also the CEO of a multi-billion dollar corporation and he was targeted with a very specific electronic exploit by a quasi-trusted source in a coordinated event and the means to hack his device were engineered specifically for that purpose.  Let’s be clear:  No one is likely doing that to YOU.  The time, effort, resources and level of technical sophistication needed to hack an individual’s devices at that level are so advanced and multi-faceted that no one with a standard or mid-range knowledge of computers or cell phones would be able to do that to you.


And just because they “work in I.T.” doesn’t mean they have any advanced coding knowledge to be able to hack your devices.



Most of these allegations surround mobile devices, but to be more specific, an iPhone is quite difficult to “hack”, at least to the level where one would be reading your text messages or tracking your location or listening to your calls.  Everything on the phone needs to run in an application and there are no applications on the Apple App Store which allow this type of activity.  This is why iPhones are generally considered more secure than Android devices – because you *have* to run everything as an app and the only place to get an app is the App Store and Apple has tight controls over what they allow on the App Store. 


What is likely the case in roughly 99.9% of instances is that access was granted by the iCloud account holder (i.e., iPhone owner) to the alleged hacker at some point prior to the “hacking” and they are using utilities like Find my iPhone and iMessage syncing to track these locations and activities.  Also not unlikely is that a formerly-trusted source knows your standard passwords and accessed your account using one of those, and may even have 2-factor authentication access from an older device.  Change your iCloud login and password and make the password strong and unique.  Also, disconnect older devices from your iCloud.  Finally, don’t use public wi-fi.


Android devices, while theoretically easier to “hack” than iPhones, still require some access for 99.9% of users to be able to track location, read messages, etc.  Apple, Samsung, LG, etc. don’t make money and keep customers by making their devices easy to exploit to any sort of hacking activity.  If that were the case, we’d all be walking around with hacked smart phones.  The security on these devices, particularly the newer models, is strong enough to ensure that the vast majority of people to whom access is not granted to the data, cannot access the data… And with each new generation of device, the security gets stronger.  


The reality is that we are all bleeding our location, purchase history, check-in activity, life events and much more on our mobile devices every day without even realizing it.  Google has more data on you than the NSA and they exploit it to make money.  Does hacking of an iPhone or Android phone happen? Yes.  But it is very, very unlikely for 99.9% of users.


As a final note, I tell all potential clients that call with this complaint, hacking in many forms is a crime.  If you have evidence you’ve been hacked, report that to the authorities and initiate a criminal investigation.  They work for you and you pay them with your tax dollars.  They also have the power to issue things like subpoenas and search warrants, which any private practitioner does not.  In short, they can help you much more than we can.



FAQ #2:  Someone is sending me harassing text messages anonymously.  Can you identify who it is?


The short answer to this is, probably not.  If the only evidence we are afforded are the text messages from the phone of the person receiving them, there isn’t much evidence for us to investigate from the device itself.  The existence of the text messages is not in dispute, the origin is what is sought.  Most of these numbers are issued through a third-party and purposely anonymous at a practical level, so our ability to track down the number to a specific person is very limited.  


In order to track the number to a person, litigation needs to be in place or a criminal investigation needs to be undertaken.  This will provide the power of subpoena or search warrant to help track down and follow the bread-crumb trail to who may be responsible.  Even still, this can require multiple levels of subpoena, which can take time and often be a dead-end in the investigation.


Harassing text messages and/or calls are annoying.  They may even be illegal, depending on where you live.  But it’s much easier and less expensive to change your phone number and let trusted friends & family know you’ve changed your number than it is to try to dig down into the rabbit-hole that is a chain of subpoenas to try and track down who is responsible.  As a wise man once said to me, “the juice isn’t worth the squeeze”.





FAQ #3:  I suspect my spouse or significant other is cheating. Can you analyze their phone to let me know if this is true or not?


We get this question a lot.  And it’s usually followed up with a statement by the would-be client that “the account is in my name”.  The problem is, the data isn’t in your name, and the data is what you’re asking us to analyze.  The issue of marital ownership of property can get a bit murky, particularly when one feels their trust is being violated.  


I know a lot about the law, but I am not a lawyer.  Generally, we refer people who ask for this service to consult an attorney and the natural rebuttal is “I want proof that something is going on before I get an attorney”.  At that point, we gracefully exit.  Why?  Because past instances have taught us that getting involved in domestic issues where there is no litigation is messy and fraught with complications.  In short, we’re not going to be the reason you get a divorce.


Aside from that, there are technical issues which can arise in this.  The first is access to the data.  For all modern cell phones, we need the pass code in order to obtain the data.  Period.  There are no notable exceptions to this for private sector practitioners.  Oh, you have the pass code?  Great.  We still won’t do it.  Modern mobile forensic tools also extract authentication keys for social media and other cloud accounts, which is a very powerful tool, particularly if used in the wrong hands.  By accessing the data on the phone and/or the data on the cloud without proper authorization, we are breaking the law.  There is no client or any amount of money who would convince us that our professional integrity and reputation is worth one case.  Finally, if we engaged in this practice and the case did go to litigation, we’d have to testify about how we accessed the data and by what authority.  That would be a tough question to answer.


Are there digital forensic practitioners who will do this?  Absolutely.  Please contact them and let me know how their testimony goes.


Wrapping It Up


The FAQs discussed here are just a sampling of some of those we receive quite regularly.  And while the answers may have a bit of pointed clarification in them, they also touch on a wider theme of ethical practices in private sector digital forensics.  When you are researching a digital forensic service provider, please ask yourself 1) is what you’re asking them to do within the bounds of the law and/or ethical practices and 2) if they agreed to do it for you, what does that say about their ethical standards?   The training, tools and ability to do what we do are all extraordinarily powerful and if used by the wrong type of practitioner, could lead to drastic consequences.  Violations of what could be termed “standards of practice” will affect the industry as a whole.  Let’s all work together to ensure that doesn’t happen.


Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/  

Tuesday, December 15, 2020

Keys to Success in Digital Forensics Series: Knowing the Justice System

Keys to Success in Digital Forensics Series: 

Knowing the Justice System


A recent discussion on an international podcast spawned several offspring topics about what bona-fide occupational qualifications (previously known as BFOQs) are key to success in the field of digital forensics.  This question has several answers, some of which are not readily apparent to many who may be pursing coursework and a career in digital forensics, but they are often intangible assets that differentiate between a good examiner and a great examiner.  One of these has very little to do with the nuts-and-bolts of digital forensics: Knowledge of the Justice System.  We’ll explore the system and elements to this key to success here, concentrating on those elements particularly in the United States.

Key Element #1:  The Difference in Types of Justice Systems

In the United States, there are several different types or levels of court system.  They are also divided into levels inside their own particular system.  For instance, there are Federal, State and Uniform Courts of Military Justice (UCMJs), which handles solely military justice matters (i.e., Army, Navy, Air Force, Marine, Coast Guard).  The Federal and State Courts are each divided into “lower” and “higher” courts.  The lower courts are usually District Courts and the higher courts are usually circuit, appellate and supreme courts.  Trials are conducted at the District and Circuit levels, but cases are only reviewed and ruled upon based upon evidence presented at trial in Circuit Courts in the Appellate and Supreme Courts.  No additional evidence is heard at the Appellate or Supreme Court levels, only written and oral arguments by the litigators involved.  


In addition to the different venue and types of courts, there are types of cases – Criminal or Civil.  Criminal cases are those which an accused is arrested based upon a complaint or criminal accusation and faces a fine, jail/prison time or some other punishment laid out in the criminal or penal law.  Civil actions are those brought before the court when there is a dispute between two entities, such as two companies or a company and a former employee.  Divorces, intellectual property theft, monetary or property disputes and other types of lawsuits are heard in Civil court.  Some cases can cross-over between both courts, depending on the circumstances.  In Virginia in 2016, Pro Digital was involved in a divorce case which had a criminal element to it, so different parts of the case were heard in two different courts.  While most minor cases start in lower courts District courts and proceed up to the Circuit level, many cases may start directly at the Circuit Court level.

Key Element #2:  How The Courts Work Differently

State & Federal Courts do operate somewhat differently, but the differences mainly lie in the types of cases that are heard in each court.  In State Criminal Courts, cases brought by local and state law enforcement are heard.  Usually, private citizens can also take out certain criminal charges on someone they feel has committed a crime against them and the police are either not willing or unable to conduct an investigation.  In Federal Criminal Courts, cases are usually brought by one of any number of 3 or 4-letter federal law enforcement agencies (FBI, DEA, ATF, HSI, etc.) and have specific jurisdiction over the cases via Federal Law.  For instance, many child sexual abuse material (CSAM) cases are brough before federal criminal courts because the images are traded/downloaded/traffic across the internet, so the nexus of the case is interstate commerce… Because all traffic over the internet has to cross state lines, whether the accused left their house in commission of the crime or not.  Add into the mix that many local law enforcement agents belong to Federal Task Forces for CSAM, drug investigations, etc., which can also affect in which court the case is heard.

Civil Actions in State Court are generally between two people who either entered into a contract/agreement locally (including marriage) or conduct business on a more local level or inside a state’s boundaries.  Federal Civil actions usually deal with the Civil side of interstate commerce, larger national/international business disputes, anything covered under entities like copyright or patent law and so forth.  Essentially, the court in which the case you’re working is heard in is determined by jurisdiction.  Only courts with jurisdiction to hear a particular case will be appropriate to do so.

Key Element #3:  Practical Application

So what does all of this mean and why is it important to digital forensic practitioners?  Whether you know it or not, implement this mindset or not or ever see it in practice or not, you may very well become a first-hand participant in the justice system.  Even incident response professionals have the potential to be called as a witness if their investigation leads to criminal charges or a civil action.  As such, we should always begin with the end in mind.  When being assigned or at the intake phase of a case, ask yourself (or your team) some basic questions:


• What basic facts does this case deal with?

• What elements of the case/incident are relevant to prove or disprove?

• Who are the potential bad actors and where are they located?

• What best practices need to be put in place to ensure that your investigation is conducted in an appropriate manner for court?

• What documentation should you have with regard to your methods, procedures, findings and conclusions AND…

• Is that documentation appropriate and acceptable for use in Court?


Beyond those basic front-end questions, there are considerations after you conduct your analysis and come to your conclusions.  The first is how the system moves along.  It is not unlikely that you could be called for a pre-trial hearing to testify about any number of issues such as access to the evidence (pre-examination), irregularities with the evidence or limitations to the analysis of the evidence.  During this testimony, you may be qualified as an expert witness, and if you’ve never been through the qualification process, you’ll want to work with the attorney handling the case to ensure that you’ll have success in that process.  For more details about that process, please check out this recent article.

After any pre-trial hearings are concluded, the attorney(s) handling the case should have lengthy discussions with you about your procedures and findings.  Everything you do in the course of your data acquisition & analysis needs to be defensible and repeatable so that someone with similar qualifications could do what you did and come to the same conclusions.  This is where details matter.



But what matters most -- and what is arguably the most intangible piece to this whole process -- is not just the ability to relay what you did, why you did it and how you came to your conclusions, but to do so in a manner that is understandable to non-technical people.  Lawyers, Clients, Executives, Judges and juries are largely non-technical people.  You will need to possess, hone and refine the ability to explain your findings to them in a manner that they will easily understand.  Bonus points if you can make it interesting!

Wrapping It Up

Some may read this article and wonder what on Earth it has to do with digital forensics?  To paraphrase Steve Whalen of Sumuri, forensics is the application of methods & procedures to come to conclusions that are sound and presentable in a court of law.  That’s what is meant by “begin with the end in mind”.  We all have stories about that one case or the one examiner who did a halfway-job and somehow skates by without anyone calling them out on their sloppy work.  The larger issue is not the one examiner, rather what that examiner represents in our industry.  If we accept that our work product will be lackluster, bare minimum or just plain bad, that will eventually affect all DFIR practitioners.  And none of us wants that!

Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia USA.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury & plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator, Physical Analyst, Advanced Smartphone Analyst and Instructor, as well as certified in cellular call detail analysis and mapping.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: www.ProDigital4n6.com 

Pro Digital LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/ 

Monday, September 14, 2020

Digital Forensics: Adding Value To Title IX (Title 9) Cases

September 14, 2020

Digital Forensics: Adding Value To Title IX (Title 9) Cases


For the past several years, there have been multiple business articles stating how the private sector digital forensics industry will be growing exponentially in the near future.  This is partially due to increased data breaches, increased civil litigation filings where data is at issue and increased electronically-facilitated criminal activity.  One area where we are seeing a decided uptick in the need for forensic data acquisition, analysis, consulting & expert testimony services is Title IX cases, which occur largely on college campuses.  According to Harvard University:

“Title IX is a US federal civil rights law passed as part of the Education Amendments of 1972. This law protects people from discrimination based on sex in education programs or activities that receive Federal financial assistance.
Title IX states that:
‘No person in the United States shall, on the basis of sex, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any education program or activity receiving Federal financial assistance.’”



Since it’s initial passing, Title IX has grown to include claims involving sexual harassment, discrimination and sexual violence.  The odd procedural issues with Title IX claims are that they may be made personally or anonymously, may or may not lead to a formal administrative charge against the accused and the accused may or may not even know the claim was ever made about them until long after the claim has been filed and/or adjudicated.  This can lead to problematic issues surrounding due process, rights to face one’s accuser and false claims made against the accused.  Further, if the accused graduates college and submits to any type of background investigation for employment, the presence of the claim on their formal educational record will likely cause expulsion from the hiring process.  Because of all of these controversial factors, recent years have also seen Title IX civil litigation blossoming into another area where justice may be sought by either the accuser or the accused.

Digital Forensics In Title IX Cases

Because Title IX claims deal mainly with college-aged claimants and accused persons, who undoubtedly use their mobile devices to a high level, the likelihood of having data in some form that may show extensive contact between the parties and serve to add value to the case is fairly high.  Whether the data is stored on a mobile device via chat or texting apps, pictures, call history, voice recordings, web history and/or email, the appropriate forensic acquisition of this data is of paramount importance to identifying the circumstances surrounding the alleged event.  Title IX cases are legal proceedings, however there may be no law enforcement investigation and the proceedings may not have a judge or attorneys present, which can put one or both sides of the matter at a procedural disadvantage.  However, the accusation and disposition of the proceedings have a long-lasting effect on the accused and/or the claimant.  Because the outcomes of these proceedings are essentially permanent and potentially impactful for a lifetime, the use of screen shots or tools with which the mobile device’s data can be easily altered prior to presentation to document contact between the parties involved is highly discouraged, as discussed in our recent article here. 



Another area that should not be overlooked in Title IX claims is data that may reside on one or both party’s computer systems.  While it’s a digital evolutionary fact that much of modern class and professional work can be conducted on mobile devices, many mobile devices are still not ideal for composition of long-form text such as research papers, lengthy emails and files or documents with larger data sets.  Email exchanges between the accused and the claimant as well as synced text message contact (iMessage, WhatsApp, etc.) over desktop applications could also be vital evidence in the Title IX claim, some of which may not be present or available via forensic data acquisition from the mobile device. Additionally, it’s very likely that the mobile device in use by either party has been charged and/or synced by the computer system at some point in the recent past.  Depending on a number of different parameters, this may lead to a backup of the mobile device data being created, which can then be acquired, analyzed as if it were the mobile device itself and used as evidence in Title IX proceedings.  While the Rules of Evidence or Civil Procedure may not be an overwhelming consideration in Title IX cases, the potential that evidence may be used in later formal courtroom litigation dictates that the evidence used in the administrative proceedings should be acquired and analyzed in a forensically sound manner.

Conclusions

Title IX cases present a host of challenges for virtually all parties involved.  As with all formal proceedings, the truth of the matter can ultimately boil down to the evidence, and particularly the strength of that evidence.  Because so much can be at stake with regard to the future of both the claimant and the accused, the appropriate documentation and forensic acquisition and presentation of data in the case is vital to proving or disproving the claim.  People increasingly live their lives on their devices, whether it be a mobile device (phone, tablet) or a computer or a combination within the various data storage ecosystem.  The good (and sometimes bad) thing about this ubiquitous connection to electronic devices is that they document nearly everything for us.  This becomes evidence in many legal and administrative proceedings, but the “devil in the details” can ultimately rest on the proper handling, acquisition, analysis and presentation of the data involved in the case.  When someone’s future is at stake, why risk presenting bad, unverifiable or lacking evidence?

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation
About the Author:
Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia USA.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator and Physical Analyst and Instructor, as well as certified in cellular call detail analysis and mapping.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Email:  Inquiries@ProDigital4n6.com
Patrick Siewert LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/  

Monday, June 1, 2020

Beyond Location Data In Cellular Records Analysis


June 1, 2020

Beyond Location Data In Cellular Records Analysis

For reasons I’m not sure I can put a firm grasp on, there still seems to be a debate over the value of cellular call detail records and their strength in being able to prove or disprove location in litigation.  Clearly the location data is generally what is sought after the most, because it carries weight with regard to a particular incident and/or time frame at the heart of the dispute.  However, some still try to debunk this data as “junk science”.  The reasoning for this is a great topic for another article, and is touched upon in our previous article entitled Three Reasons Why Call Detail Records Analysis Is Not “Junk Science”.  However, there’s much more to the cellular records than location data, or at least much more that is ancillary to location data.  This deeper level of analysis can further lend validity to the records themselves and any conclusions drawn from their analysis, location or otherwise.



Dataset #1:  Link Analysis

Along with location data, properly obtained cellular records also tell us a great deal about who our target is talking to, when they are talking and how often.  This is most commonly referred to as link analysis, but effective analysis of these records goes beyond that.  For instance, target is suspected of marital infidelity with a married woman.  The call detail records (CDR) show he calls and texts the married woman several dozen times a day.  A private investigator tracking the married woman spots the two of them together on a particular date and time.  What is likely to happen?  They’ll stop calling or texting each other during that time because they’re in the same location.  In another example, suspect #1 is arrested and charged with robbery.  His defense team has information that he was NOT the only one involved in the robbery, and perhaps was not the primary involved in the robbery.  Analyzing who the suspect called and texted the most leading up to the robbery and afterward can be of great value in determining whom an accomplice may have been.  Usually what we see with link analysis is the people will call and text their loved ones the most – husbands/wives, parents, best friends, etc.  This all goes to show a pattern of usage and helps identify who they talk to the most and potentially, their activity with regard to those people as well.

Dataset #2:  Usage Patterns

Often in conversations with litigators about analysis of these records, we get asked “what if they turned their phone off?” or “What if he simply left his phone at home or at work?” during the time of interest.  All valid questions!  The issue becomes, what can we tell is likely during the time frame of interest in relation to other usage patterns.  If a cheating husband is meeting his paramour in a hotel during his lunch hour once or twice a week and he leaves his cell phone at the office, we’ll be able to tell from looking at 1) the usage patterns from when he is not with his paramour and 2) a pattern of missed calls and/or texts for the period of time he was separated from his phone.  Let’s also not overlook that he may have had a flurry of text messages or calls with the paramour leading up to this activity.  There are very interesting and often very valuable items we can tell by looking at the record, such as: 

·      If the phone rang and went to voicemail
·      If the phone was turned off and calls when directly to voicemail
·      If calls were received and unanswered in succession for a period of time (and later returned)
·      If text messages were received and  unanswered for a period of time (and later returned)
·      Whether any of this activity is normal, as compared to other activity for time frames outside of the time frame of interest

People are creatures of habit.  By analyzing the usage patterns in the records, we can see what their habits are in relation to the use of their device.  This is the single biggest reason we advise all litigators who wish to use these records to obtain at least 30 days of records on either end of the incident in question.  The more data, the better.  Usage patterns are of great value when conducting this analysis.



Dataset #3:  Where They Lay Their Head

Much of usage analysis mentioned previously has little or nothing to do with location.  One area that has to do with location, although not necessarily during the time frame of the alleged incident(s), is where your target lays their head.  As stated earlier, people are creatures of habit.  Their phones are with them virtually all the time.  So even outside of the time frame of the incident, we can likely tell where that person is staying at night.  By in large, during late night and early morning hours, we see the mobile device stationary, only using one sector of one cell site for an extended period.  This information in the records tells us likely where they lay their head.  By filtering down to late night & early morning hours, we can also see if they have more than one place where they may stay at night.  This typically generates a “hot list” of cell sites that are used most often, and this is also included in any reports we generate.  It’s relevant insofar as it shows the finder of fact or opposing counsel that where their stated address is may not be where they stay.  It could also provide additional information for follow-up if the house and likely person with whom they are staying can be determined.  It’s a fantastic piece of evidentiary data!

Wrapping It Up

As illustrated briefly here, there’s more to cellular call detail records analysis than simple location.  These points also further prove that the proper and effective analysis of this data is not “junk science”, rather there may be a contingent of analysts who simply don’t have the ability or desire to perform this type of higher-level analysis in their cases.  Ignorance of the power and effective use of the data does not make the data invalid.  By looking deeper into the data, we can start to sort out what may help to prove or disprove the claims in the case.  It could also help shed light upon or validate who else may be involved in the matter, whether previously known or not.  The ability to analyze behavior patterns in the record cannot be over-stated either.  At the heart of any digital forensic practice is a person, whether it is behind the keyboard, phone screen or a cellular subscriber.  People behave in patterns.  Your analyst should be able to identify those patterns and determine whether or not they are of relevance in your case.  Happy hunting!

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation
About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator and Physical Analyst as well as certified in cellular call detail analysis and mapping.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Email:  Inquiries@ProDigital4n6.com