Showing posts with label deleted data. Show all posts
Showing posts with label deleted data. Show all posts

Monday, February 14, 2022

When the Absence of Evidence is Good Evidence

February 14, 2022


When the Absence of Evidence is Good Evidence


Fielding dozens of inquiries every month for nearly 9 years as a digital forensic service provider, we start to get a good sense about what many cases involve, even before the details of an incident are revealed.  Whether the case involves mobile device evidence, computer evidence, cellular records analysis or electronic-based investigation, the general approach to the case, depending on the scope, is about the same.  What many attorneys and their clients are seeking is the proverbial “smoking gun” or “nail in the coffin” of their case.  As we often tell them, that does happen, from time to time.  But it is not the norm.  


More often than not, we are provided data that is lacking or missing something important.  The question then becomes why is the data missing, when did it go missing and who (if anyone) caused it to become missing?  In this game of piecing the digital puzzle together, often what is absent can also be key to the case.  But there are some definite considerations that go along with this notion as well.




The Value of Missing Data


There are circumstances where missing data can tell a decent part of the story.  For instance, on some mobile devices, items in certain areas are stored sequentially and numbers (or indices) in the sequence are not repeated.  Accordingly, if we find that there are missing numbers in the sequence, we can conclude that something was removed from the table that stores this information.  Can we always recover the data itself?  No.  But we can often determine that it was removed and at the very least approximate when it was removed, using process of elimination.


We can further determine the prior existence of this data by:


1) Searching for the likely file names or monikers of the missing data to see if there are any other records of those files being accessed or used on the system or device.

2) Looking at the timeline of activity on the device or system to determine what took place during the time frame that the data is suspected to have been removed.  Many other areas of the device may have been used around these times to help show the overall activity around these times.

3) Looking at patterns of removal of data, either in this or other categories, to see if perhaps a mass-deletion of data may have taken place.  There are always alternative explanations which need to be explored before coming to concrete conclusions.


We can also try to determine if some or all of the missing data might have been stored elsewhere.  Alternative and backup data storage such as computer syncing and cloud-based storage are valuable, common areas that could potentially store either more data and/or the deleted data to help answer these important questions.


The Expert’s Conclusions re: Missing Data


The ultimate goal in missing data analysis is to be able to come to some conclusion within a reasonable degree of certainty.  This is not always easy and it’s almost never 100%.  However, as analysts and Experts who testify in legal matters, digital forensic practitioners can be *mostly* sure about what happened through thorough analysis and testing, depending on the scope of the case and the needs of the Client.  


The important point about our conclusions with regard to when items were deleted, who deleted them and when lies in the thoroughness of our work.  Leaving no stone unturned is a good approach, but it’s also time-consuming and expensive.  Many clients will not want to support this cost expenditure, mostly because they don’t see the need for it.  Ultimately, it is the analyst’s reputation and work that is to be scrutinized in court and by other experts, therefore, the analyst should be steadfast in their calls for whatever measures are appropriate to support their conclusions in court.  Whatever the conclusion(s) is/are, they must be articulated, defensible, repeatable and supported by the data.  Otherwise, they will not pass evidentiary muster and ultimately the client will not be served by the expenditure.


This is another area where peer review can play a vital role.  No digital forensic analyst knows everything about every data storage medium, file system, application, mobile device, etc.  However, with a thoughtful and thorough peer review of the procedures, findings and conclusions, we take another valuable step to validating those conclusions for the finder of fact.   




A Brief Case Study


We once worked a divorce case involving an iPod with internet connectivity.  The husband, our client, found videos on a computer of his wife engaged in sexual relations with another man.  When the Court ordered her devices turned over, including the iPod on which she was suspected to have chatted for months with her paramour, there were no messages found.  However, there were suggestive pictures and videos located on the iPod, which supported the suspicion of chatting behavior.


Additionally, the Court ordered her laptop hard drive to be analyzed.  On the laptop hard drive, there were a number of iPod backup files, nearly all of which contained the application-based chats with the paramour, including their sexually explicit conversations and his admission to killing another person in another state.


Wrapping It Up


We like to take the approach that the data is virtually always somewhere.  But even if it’s not anywhere, we can often find markers, indicators, patterns and evidence that it existed in some form prior to our obtaining the data enough to be able to come to some conclusion about it.  The key lies in the ability, competency & knowledge of the digital forensic analyst to be able to determine what may have happened, when and who is responsible.  Just because it’s not there doesn’t mean your case is dead or that your analyst can’t do anything to help.  Tenacity is a virtue in digital forensics.  Make sure to scrutinize the characteristics of your analyst before asking them to work your case.  Not all analysts (or lawyers or clients or… ) are created equally.


Author: 

Patrick J. Siewert

Founder & Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/  

Wednesday, July 14, 2021

Three Myths About Digital Forensics as a Practice

July 14, 2021


Three Myths About Digital Forensics as a Practice


Following up on last month’s article about “Three FAQs About Digital Forensics as a Service”, we thought it useful to spend some time debunking some myths about digital forensics from both a general practitioner and service provider perspective.  


Every industry comes with “urban legends” or popularized myths that surround the practice.  Many of these rarely represent reality and some are outright false.  The more intriguing or interesting the field, the more pervasive these falsehoods can be.  Digital Forensics is no different than any other industry in this respect.  The reality is that TV and movies have sensationalized what we do to the point where there are several misconceptions about the practice of digital forensics, which run the gamut of the various sub-sets of the practice and affect those in law enforcement, private sector litigation support, incident response and government contractors.  While Hollywood has tried to make the profession “sexy”, there are some realities to this field, including the long hours spent staring at a computer monitor, developing a script or researching an application.  While not overly exciting, those are activities in which any practitioner worth their salt needs to engage on a regular basis… But it doesn’t make for good TV.


In order to dispel some common myths about our field, three of these misconceptions are discussed in this article.  This selection of industry myths has been garnered through discussing and working cases with people outside the industry over the combined time in law enforcement and private sector practice of digital forensics for the past 12 years.


Myth #1:  Nothing Is Ever Truly Deleted


I wish this were true.  However, the reality is that it is not.  Not only are there anti-forensics methods readily available to users on the market (i.e., Hillary Clinton and “BleachBit”), but increasingly there are measures being put in place at the manufacturing level for both mobile devices and higher-end computer systems that make deletion of data a permanent state.  To be more accurate, the security over the stored data is such that when and item is deleted, it is often not recoverable.  


For example, on an iPhone, data is stored in the same basic way for most applications.  However, if an item is deleted from the phone, depending on the type of item (i.e., picture or video vs. text message), the item is sent to free space on the phone memory, which is encrypted and not accessible through the forensic process.  The image may not be gone, per se, but it is not accessible or viewable.  On newer Mac computers and other devices equipped with solid-state memory (i.e., not a spinning hard drive), there is a process in place called “Trim” which also helps clean up the free space of the memory and makes recovery of deleted items extremely difficult, if not impossible.  In the era of heightened data security, these measures are becoming more commonplace.  Deleted text messages that were once partially recoverable are now increasingly unavailable, even with the most state-of-the-art forensic tools.  




There are almost always alternative storage methods, however.  Hard backups (computer-based) or copies or cloud-based data can all be potential areas where valuable evidence can exist, but the reality of the digital consumer marketplace is that if all we have is the device and nothing else, we may not get your deleted data.  



Myth #2:  If It’s Deleted, It’s Gone


I know this sounds totally contradictory to the previous comments and Myth #1, but just because it’s deleted, doesn’t mean the evidence you need is gone.  Indeed, this is and always has been at the heart of the forensic process.  We utilized industry-standard methods to acquire, analyze, recover and report about the data.  The emphasis with this myth is the recovery part.  I tell potential clients and attorneys all the time, the data is *usually* stored in more than one place.  The aforementioned cloud-based data storage being the most ubiquitous, but there can also be additional data stored in some surprising places.  The more data we can get our hands on that is related to the matter at-hand, the more success we will have in getting you some evidence that will help confirm or refute your assertions in the case.  There are also methods of analysis that a trained, competent examiner will attempt to incorporate in many cases, including partial recovery of valuable data from places like file-slack (leftover space where a file may have previously existed) or volume shadow copies that are automatically created in Windows.  




In most cases, the proverbial smoking gun is not a realistic possibility.  We have certainly worked and seen cases where the smoking gun has come about and it has always met with great success, but the reality of our practice is that we will likely find *something* to help you, but it may not be the one piece of evidence that will confirm or refute the matter at-hand.  Will it add value?  Most likely.  The real value comes in with the examiner’s ability to articulate what they did, how they found what they did and to explain these findings in non-technical terms that everyone can understand.  


Tools don’t do the work.  They present the data for the analyst to do the work, so make sure your analyst is knowledgeable and not afraid of doing the work.



Myth #3:  It’s Just A Phone… What’s The Big Deal?


It’s not unlikely that the origination of this myth is rooted in our innate perception of the fact that the size of things should equal more cost.  Bigger vehicles cost more than smaller vehicles.  Bigger houses cost more than smaller ones, and so on.  So why should a device that fits in my pocket be more of a challenge to acquire and analyze data than my laptop or desktop computer?  


In recent years, the marketplace has demanded that phones be more complex, store more data and be much more secure than your computer.  Apple comes out with a new iteration of iPhone every year, and they usually (and much more quietly) update their computer hardware and software as well, but the emphasis since the inception of the iPhone has been on the mobile device.  So what’s so problematic about it?




As I tell attorneys and their clients frequently, many times we are acquiring the data that Apple allows us to have.  To be clear, this is almost always more than what the user could do themselves and in a forensically sound manner appropriate for evidence presentation, but Apple can be quite restrictive for non-law enforcement to obtain data.  We get the basics – messages, photos, videos, web history, and supported app data.  Many times we can also analyze unsupported app data as well.  But much of the deleted data is unavailable.  In recent years, more advanced methods for acquiring iPhone data have come about, but they are only available on certain iterations of the iPhone hardware and software.  But to be clear, we always try to get as much data as possible.


Android phones are increasingly problematic as well.  Last year, we had a Samsung Galaxy S20 in for acquisition and analysis.  I was amazed at how little data we obtained, despite multiple attempts at multiple different methods of acquisition.  Fortunately, the mobile forensic tool developers are always coming out with newer ways to get more data for our use and analysis, but it’s a constant game of catch-up.  


A final point about the volume of data that can be analyzed on phones, Apple currently has up to 512 GB of storage on an iPhone.  Some Android phones are pushing to 1TB or more worth of storage.  That may not seem like a lot when you’re using the phone, but it’s A LOT of data.  And the more we have to search that mountain of data, the longer it takes.  These are not the Nokia flip phones we all had in the mid-2000’s.  They’re not even the Blackberry Pearl you had and thought was so cool.  These are complex computer devices with as much storage capacity as many commonly used computer systems, with many enhanced security measures.  They may be small, but they’re mighty!


Wrapping It Up


The myths discussed here are a small sample of the push-back we sometimes get when it comes to the length of time and the cost associated with acquisition, analysis and reporting about the data on these devices.  For those in law enforcement, phones are seized daily and sometimes the means by which to simply acquire the data are challenging and time-consuming (if not impossible).  We are not miracle workers, but we do try to get you data that you can use in your case to help confirm or refute your suspicions or claims.  Just know, it’s not always easy, it’s not always quick and it’s unfortunately not always possible.  Sometimes, we just don’t know until we get into analyzing the data!


Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business servicing litigators and their clients, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/ 





Friday, May 13, 2016

Don’t Forget the Victim (And Their Device)!



May 13, 2016

Don’t Forget the Victim (And Their Device)!

Regardless if your case involves computers, tablets, iPhones, Android devices or all of the above, one thing the investigative community can agree on is, every case is different.  Sure, certain cases will follow a workflow pattern, but the circumstances of every case, the suspects/targets, investigators and victims all take on different faces, which can alter your approach to conducting digital forensic analysis in the case slightly or dramatically.  We’ve all seen a surge in criminal (and civil) cases involving smart phones and other mobile devices and with that comes the mountain of evidence that is contained on a those powerful pocket computers that store up to 128 GB of data (or more, depending on when you’re reading this).  But consider this: You may only be getting half of the story if the only device you seize and analyze is that belonging to the target of your investigation.




Case Application

The best case example we can use to illustrate this point is the investigation of a rape allegation.  Rape doesn’t happen in a bubble, it takes two people (or more) for a rape to occur.  And virtually everyone involved in these incidents owns & uses a smart phone on a daily basis.  Frequently, rape occurs when the alleged perpetrator knows the victim, either in some sort of early-stage relationship, a family friend, relative, etc.  Because experienced investigators know this to be true and many reports will validate this, it is your investigative responsibility to prove or disprove the claim.  In order to help do that, you need to seize not only the target’s phone data, but also the alleged victim’s phone data – all as soon as possible.

The best (and sometimes worst) thing about mobile device forensics is, once we have the data extraction, it’s ours.  It is a digital snapshot of whatever was present on the device at the time the extraction took place and, depending on the device, may also give us access to deleted information.  So in the interest of conducting a thorough investigation, I put forth that when an alleged rape victim makes the report, investigators should make it a regular and common practice to ask for consent to perform a data extraction on his/her phone.  It is simply the easiest way to get a 360-degree view of the case.




A More Holistic View of the Data

Consider also what happens in the mind of the target after they know they may have committed a crime.  Text and chat messages are deleted.  Pictures of the alleged victim get erased from the device.  They may even dispose of the device altogether and replace it with a new, fresh phone that has virtually no useful evidence contained on it.  Wouldn’t it be nice if the other side of those conversations still existed on another device?  What’s more, by grabbing the data from the alleged victim’s phone, you work toward a more complete investigation of the allegation.  It is an unfortunate reality that there are often false reports of serious crimes.  This certainly doesn’t mean that we automatically assume the victim may be lying, but it is our responsibility to fully investigate the case to determine what actually happened.  Victims and eye witnesses are notoriously unreliable for different reasons.  When victims are subjected to trauma, their accurate recollection of the incident can suffer to a degree, so that puts even more oneness on the investigator to try and piece the puzzle together.

The best part about the data is, it doesn’t lie.  It has a perfect memory and it’s all documented, complete with date and time stamps, exif metadata, GPS coordinates, network activity and other great pieces of evidence that are very hard to spoof or fake, if not nearly impossible for most mobile device users. 

Spoofing is a Thing

While the data doesn’t lie, it can be manipulated somewhat by either or both parties.  As demonstrated in this news piece we helped out with, one can simply download a free app, assign a desired number to it and send text messages to themselves as if they were someone else, perhaps an ex-boyfriend or some other acquaintance.   Then, if the messaging app is deleted, to the untrained investigator, this evidence looks legitimate on its face.  But it’s only part of the story. 



In the somewhat rare instance where this happens, it is absolutely vital to get the alleged victim’s cell phone dump.  Getting even a logical extraction from the device might show what happened, but it’s always advisable to get as much data as you can in the form of a physical extraction, SIM card data, SD card image, etc.  I realize these things may take time, but remember, the victim came to you for help.  If they back off on wanting that help, don’t ignore your instincts.  That could be a warning sign that you’re dealing with a false claim. 



A Brief Note About Encryption

Encryption is the big bugaboo in forensics.  More and more devices are coming to the consumer out-of-the-box with some sort of encryption already in place.  Heck, this is the whole rub between Apple and the FBI…
But consider that if your suspect or target has a device with encryption in place, the alleged victim may be much more willing to hand over their device for extraction, whether their device is encrypted or not.  From a law enforcement investigative perspective, the victim is generally much more cooperative and, in theory, would be willing to provide you with a passcode (as well as other potential credentials) in furtherance of the investigation on their behalf.  It could be the only digital evidence you get!

Conclusion

Never forget there is always more than one person involved in the investigation.  Grabbing the alleged victim’s cell phone data in this circumstance could mean the difference between an innocent person being convicted of a serious crime or being exonerated fully.  When all the facts have been completely uncovered, the truth must remain and will have to hold up in a court of law. 

Author:
Patrick J. Siewert, SCERS, BCERT, LCE
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Globally


We Find the Truth for a Living!

About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation cases in Virginia court history.  A graduate of both SCERS, BCERT, the Reid School of Interview & Interrogation and various online investigation schools (among others), Siewert continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations.
Twitter: @ProDigital4n6