Showing posts with label digital evidence. Show all posts
Showing posts with label digital evidence. Show all posts

Tuesday, August 10, 2021

Apple’s New CSAM Detection Policy Analysis

 August 10, 2021


Apple’s New CSAM Detection Policy Analysis


Several times a year, there seem to be current events or topics that strike a chord both inside and beyond the digital forensic community.  We’ve discussed these in previous articles with regard to the Carpenter v. US decision and Apple’s previous spat with the FBI in the wake of the San Bernardino, CA terrorist attack.


As no stranger to these current event discussions (i.e., controversy) when it comes to matters of privacy and cooperation with Law Enforcement, last week we had another “bombshell” dropped by Apple that in a new US-based update, they will be subjecting user’s on-device photos to hash analysis attempting to track down images of known child sex abuse material (CSAM) that may be uploaded to iCloud and forwarding this information for follow-up to the National Center for Missing & Exploited Children (NCMEC) or other law enforcement investigative entity.  Here, we’ll discuss how this works and explore both sides of the issue.







How CSAM Detection Works


It is a commonplace practice for internet (or electronic) service providers (ISPs/ESPs) to work in conjunction with law enforcement to detect known CSAM images.  The first question naturally is, what is a known CSAM image?  Simply put, an image becomes known CSAM when a victim has been positively identified in the image.  This routinely comes through the investigation of new/unknown images and positive identification on the children in those images.  Often times, the images are within a series, depicting child sex abuse of one or more victims in the same setting with the same abuser and around the same time frame.  Law enforcement entities such as NCMEC, DHS and the FBI all maintain file hash databases of these images for use by law enforcement in investigation.  These file hash values are used to track down purveyors of child pornography across peer-to-peer networks, as well as those who may upload and share CSAM images to cooperating ESPs such as DropBox, Gmail, Yahoo, Kik, etc.  


Once a known CSAM image has been identified by the ESP by hash value, the offending party’s account information as well as the specific date/time of upload and manner of upload are all provided to NCMEC as an investigative lead.  NCMEC then performs a variety of open-source intelligence gathering on the offending party and provides the information to law enforcement in what is known as a Cybertip.  An affiliate or cooperating law enforcement agency receives the Cybertip for investigative follow up, which can include knock-and-talk, search warrant, additional investigation or a combination of these (or other) investigative methods.  Some Cybertips go nowhere.  Some, like one I worked while a member of law enforcement, are not eligible for a search warrant, but end up in a knock-and-talk, consent search and confession from the offending party of not only possessing CSAM, but molestation of his 10 year-old step daughter.  The value of Cybertips in the hands of properly trained investigators cannot be overstated.


Whether or not you know it, you are explicitly agreeing to this process in the End User License Agreement (EULA) by using any of these services.



One Side of the Argument: Privacy


Privacy is understandably an important issue to users of technology across the spectrum.  Apple has traditionally been very privacy-centric in their practices, including refusal to help the FBI unlock the iPhone belonging to a terrorist couple who killed several people.  And privacy is very important to almost all users.  The argument here on the privacy side is that, by Apple’s own statement, they are installing an agent on iDevices to subject photos to a hashing algorithm and then alert law enforcement if a “threshold” of CSAM content is discovered.  This is a half-step further in a direction than what Google, Yahoo or Kik do to detect CSAM content in that they detect content uploaded to their servers and report what is suspected CSAM to NCMEC.  Apple is detecting content on individual devices and reporting suspected CSAM content that may be shared via iCloud which meets the “threshold” to NCMEC. 




In some spirited discussion about this new policy on Linked In recently, it was pointed out that this may be a violation of a user’s 4th Amendment rights against unreasonable search & seizure because Apple is acting as a would-be agent of law enforcement and “searching” people’s photos on their devices without a warrant.  We’ll discuss this a bit further in the next section, but this is a valid argument on its face.  But like with most things in life, the devil is in the details.  


Another point brought up in discussion was the fact that Apple is projecting that they have the technology to scan files on your device generally, which could be more of a concern in the future.  This is very powerful technology that has the capability of infiltrating people’s devices without their express knowledge and potentially providing information to a third party, possibly for criminal investigation.  Furthermore, it opens the door for a would-be hacking entity to exploit this new door that Apple has opened on a much wider scale.  The security and data privacy implications may only be in the early stages.


The Other Side of the Argument: Child Safety


As a former law enforcement investigator on the Internet Crimes Against Children Task Force, I can assure you that proliferation of CSAM images across the internet is a real problem.  While doing this work also in the private sector, I’m sometimes asked how law enforcement knows that the images are of children and not simply people in their upper-teens who could easily be mistaken for someone over 18.  They know.  The most egregious examples of CSAM material involve infants and toddlers in sexually exploitative scenarios that no investigator can ever un-see.  These images are by-in-large not questionable in age or physical development.  They are small children, even sometimes babies.  Are there exceptions to this?  Yes.  Teens who possess smart devices also possess the ability to make their own images and share them with whomever they wish, particularly if their parent/guardian is not tech-savvy or they have not been taught the impact that the decision to share explicit photos can be long-lasting when it comes to the internet.  These images sometimes become part of criminal investigations as well, and they can be added to the CSAM database if the correct criteria and procedures are in place.


So why is Apple’s decision generally a good one for law enforcement?  The approach that investigators take with CSAM images is that a child is victimized every time these images are viewed or shared.  This then requires law enforcement investigation and intervention to help stem the flow of these images across the internet and decrease child sexual exploitation.  Apple’s cooperation in this mission opens a door not previously available without another third-party alerting NCMEC of images potentially stored on a device.  Additionally, with the proliferation of human trafficking, particularly of missing children, Apple’s new policy gives law enforcement another tool in the proverbial toolbox to help track down and locate missing children.




The argument that this practice goes against 4th Amendment protections against unreasonable search & seizure is a compelling one.  But there are some arguments to the contrary.  First, no one has a Constitutional right to own an iPhone.  If you don’t like Apple’s new policy, switch to Android.  Second, whenever we get a new i-Device (iPhone, iPad, iPod, etc.), we are prompted to “Agree” to Apple’s terms of service in the EULA, and this is in perpetuity for the time we use their software and hardware.  It is Apple’s discretion to change or updated the terms of this policy, as they have done recently with implementation of this new practice.  In short, we gave them permission to do this.  Finally, an argument can be made that while Apple’s practice for detecting CSAM images goes a half-step beyond other ESPs, the protection of children from sexual exploitation is worth whatever freedom we give up.  There is a tried & true adage that liberty and security rarely go hand-in-hand.  We frequently give up liberty for security.  Been to the airport lately?  


Finally, the argument was also brought up about mistaken identification of traders of CSAM images through this new process.  If we take Apple’s statement at face-value, there is a one in “one trillion chance per year” that this could happen, meaning it is far less than statistically insignificant.  I’m also quite certain the army of Legal Counsel at Apple have thoroughly reviewed and signed-off on this practice.




Wrapping It Up


This is a hot topic that won’t soon go away.  Apple has caught heat many times for many different approaches over the years and this is just the latest measure to garner such attention.  It is ultimately up to us as the consumers of Apple to decide… Do we want to give up a tiny bit of privacy (for now) in furtherance of the mission to stem the flow of child sex abuse images or do we care more about privacy over the content of our devices?  It’s a personal choice and fortunately, we still have the freedom to choose in the United States!


NOTE:  Article with additional information published on 8/9/2021:  https://www-bbc-com.cdn.ampproject.org/c/s/www.bbc.com/news/technology-58145943.amp 


Author: 

Patrick J. Siewert

Founder & Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!


Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business servicing litigators and their clients, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/  

Wednesday, July 14, 2021

Three Myths About Digital Forensics as a Practice

July 14, 2021


Three Myths About Digital Forensics as a Practice


Following up on last month’s article about “Three FAQs About Digital Forensics as a Service”, we thought it useful to spend some time debunking some myths about digital forensics from both a general practitioner and service provider perspective.  


Every industry comes with “urban legends” or popularized myths that surround the practice.  Many of these rarely represent reality and some are outright false.  The more intriguing or interesting the field, the more pervasive these falsehoods can be.  Digital Forensics is no different than any other industry in this respect.  The reality is that TV and movies have sensationalized what we do to the point where there are several misconceptions about the practice of digital forensics, which run the gamut of the various sub-sets of the practice and affect those in law enforcement, private sector litigation support, incident response and government contractors.  While Hollywood has tried to make the profession “sexy”, there are some realities to this field, including the long hours spent staring at a computer monitor, developing a script or researching an application.  While not overly exciting, those are activities in which any practitioner worth their salt needs to engage on a regular basis… But it doesn’t make for good TV.


In order to dispel some common myths about our field, three of these misconceptions are discussed in this article.  This selection of industry myths has been garnered through discussing and working cases with people outside the industry over the combined time in law enforcement and private sector practice of digital forensics for the past 12 years.


Myth #1:  Nothing Is Ever Truly Deleted


I wish this were true.  However, the reality is that it is not.  Not only are there anti-forensics methods readily available to users on the market (i.e., Hillary Clinton and “BleachBit”), but increasingly there are measures being put in place at the manufacturing level for both mobile devices and higher-end computer systems that make deletion of data a permanent state.  To be more accurate, the security over the stored data is such that when and item is deleted, it is often not recoverable.  


For example, on an iPhone, data is stored in the same basic way for most applications.  However, if an item is deleted from the phone, depending on the type of item (i.e., picture or video vs. text message), the item is sent to free space on the phone memory, which is encrypted and not accessible through the forensic process.  The image may not be gone, per se, but it is not accessible or viewable.  On newer Mac computers and other devices equipped with solid-state memory (i.e., not a spinning hard drive), there is a process in place called “Trim” which also helps clean up the free space of the memory and makes recovery of deleted items extremely difficult, if not impossible.  In the era of heightened data security, these measures are becoming more commonplace.  Deleted text messages that were once partially recoverable are now increasingly unavailable, even with the most state-of-the-art forensic tools.  




There are almost always alternative storage methods, however.  Hard backups (computer-based) or copies or cloud-based data can all be potential areas where valuable evidence can exist, but the reality of the digital consumer marketplace is that if all we have is the device and nothing else, we may not get your deleted data.  



Myth #2:  If It’s Deleted, It’s Gone


I know this sounds totally contradictory to the previous comments and Myth #1, but just because it’s deleted, doesn’t mean the evidence you need is gone.  Indeed, this is and always has been at the heart of the forensic process.  We utilized industry-standard methods to acquire, analyze, recover and report about the data.  The emphasis with this myth is the recovery part.  I tell potential clients and attorneys all the time, the data is *usually* stored in more than one place.  The aforementioned cloud-based data storage being the most ubiquitous, but there can also be additional data stored in some surprising places.  The more data we can get our hands on that is related to the matter at-hand, the more success we will have in getting you some evidence that will help confirm or refute your assertions in the case.  There are also methods of analysis that a trained, competent examiner will attempt to incorporate in many cases, including partial recovery of valuable data from places like file-slack (leftover space where a file may have previously existed) or volume shadow copies that are automatically created in Windows.  




In most cases, the proverbial smoking gun is not a realistic possibility.  We have certainly worked and seen cases where the smoking gun has come about and it has always met with great success, but the reality of our practice is that we will likely find *something* to help you, but it may not be the one piece of evidence that will confirm or refute the matter at-hand.  Will it add value?  Most likely.  The real value comes in with the examiner’s ability to articulate what they did, how they found what they did and to explain these findings in non-technical terms that everyone can understand.  


Tools don’t do the work.  They present the data for the analyst to do the work, so make sure your analyst is knowledgeable and not afraid of doing the work.



Myth #3:  It’s Just A Phone… What’s The Big Deal?


It’s not unlikely that the origination of this myth is rooted in our innate perception of the fact that the size of things should equal more cost.  Bigger vehicles cost more than smaller vehicles.  Bigger houses cost more than smaller ones, and so on.  So why should a device that fits in my pocket be more of a challenge to acquire and analyze data than my laptop or desktop computer?  


In recent years, the marketplace has demanded that phones be more complex, store more data and be much more secure than your computer.  Apple comes out with a new iteration of iPhone every year, and they usually (and much more quietly) update their computer hardware and software as well, but the emphasis since the inception of the iPhone has been on the mobile device.  So what’s so problematic about it?




As I tell attorneys and their clients frequently, many times we are acquiring the data that Apple allows us to have.  To be clear, this is almost always more than what the user could do themselves and in a forensically sound manner appropriate for evidence presentation, but Apple can be quite restrictive for non-law enforcement to obtain data.  We get the basics – messages, photos, videos, web history, and supported app data.  Many times we can also analyze unsupported app data as well.  But much of the deleted data is unavailable.  In recent years, more advanced methods for acquiring iPhone data have come about, but they are only available on certain iterations of the iPhone hardware and software.  But to be clear, we always try to get as much data as possible.


Android phones are increasingly problematic as well.  Last year, we had a Samsung Galaxy S20 in for acquisition and analysis.  I was amazed at how little data we obtained, despite multiple attempts at multiple different methods of acquisition.  Fortunately, the mobile forensic tool developers are always coming out with newer ways to get more data for our use and analysis, but it’s a constant game of catch-up.  


A final point about the volume of data that can be analyzed on phones, Apple currently has up to 512 GB of storage on an iPhone.  Some Android phones are pushing to 1TB or more worth of storage.  That may not seem like a lot when you’re using the phone, but it’s A LOT of data.  And the more we have to search that mountain of data, the longer it takes.  These are not the Nokia flip phones we all had in the mid-2000’s.  They’re not even the Blackberry Pearl you had and thought was so cool.  These are complex computer devices with as much storage capacity as many commonly used computer systems, with many enhanced security measures.  They may be small, but they’re mighty!


Wrapping It Up


The myths discussed here are a small sample of the push-back we sometimes get when it comes to the length of time and the cost associated with acquisition, analysis and reporting about the data on these devices.  For those in law enforcement, phones are seized daily and sometimes the means by which to simply acquire the data are challenging and time-consuming (if not impossible).  We are not miracle workers, but we do try to get you data that you can use in your case to help confirm or refute your suspicions or claims.  Just know, it’s not always easy, it’s not always quick and it’s unfortunately not always possible.  Sometimes, we just don’t know until we get into analyzing the data!


Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!



We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Founder & Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business servicing litigators and their clients, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/ 





Thursday, January 7, 2021

Cellebrite Reader: You Don’t Know What You’re Missing!

January 7, 2021

Cellebrite Reader:  You Don’t Know What You’re Missing!

As a digital forensic practitioner who logs approximately 70% of cases in the mobile device forensics arena, it has become the norm for us to receive discovery in any number of forms from opposing counsel, law enforcement agencies, etc.  Being one of the most commonly used mobile forensic tools on the market (particularly by law enforcement), Cellebrite has wisely developed a way for people who wish to view the data on a particular device to do so, also with the capability of generating their own report.  This pared-down or lightweight version of the Cellebrite Physical Analyzer program, called the Cellebrite Reader, is a great free way to browse the 30,000-foot view of the data, particularly for laypersons who may just want to get text messages, pictures, videos, etc.  These are traditionally the “high points” of the data on the phone or tablet and can sometimes include deleted items, but a serious warning should accompany the Cellebrite Reader file:  You don’t know what you’re missing!



Who Should Use The Cellebrite Reader?

The Cellebrite (or UFED) Reader is a lightweight version of the paid version of the analysis tool that accompanies a full Cellebrite product license called Physical Analyzer.  To say it’s a “lightweight version” of Physical Analyzer is a bit of an understatement.  At first glance in the user interface, the two applications look very similar, but as with most things in digital forensic analysis, the devil is in the details.  So then who should use the Cellebrite/UFED Reader?  If your case involves any of the “basic” data areas, such as undeleted text messages, photographs and some location data, then the UFED Reader tool is probably fine.  The tool is best for on-staff investigators, paralegals, private investigators and other mostly non-technical support staff.  If you have absolutely no need to dig into the data at all, the UFED Reader program should serve your purposes just fine.  The issues emerge when we dive into how the data is generated and what is included, or rather not included, by the person who generated the Reader file.


The “Analyzed Data” portion provides a great overview of the simple data areas decoded automatically by Cellebrite, including *some* deleted data (red parentheses)


How Is a Cellebrite Reader File Generated And What Is Included?

A Cellebrite/UFED Reader File is generated within the larger licensed tool called Cellebrite UFED Physical Analyzer.  Many times, because of case backlog or by specific request, the person doing the data extraction from the device(s) will create a “data dump” report, viewable in the UFED Reader.  This creates a .UFDR file, which is only able to be opened and read in the UFED Reader program, which accompanies the UFDR file at no cost to the user.  In the case of a data dump report, ostensibly all of the readily viewable and automatically decoded data on the device is included in the UFDR file. 

However, one strong warning about UFDR files is that they can easily be generated by the analyst cherry-picking or selectively choosing the data to include in the UFDR file, which is NOT a data dump.  For example, the person responsible for generating the Cellebrite Reader file can choose only certain picture file types or certain text messages or message strings to include in the Reader file. This could *look* the same as a data dump within Cellebrite Reader, but would have far less data than the 100% dump of everything available from the device.  There is no clear indication that a data dump file has been generated versus one that is selectively created by the analyst and exported into a UFDR and Cellebrite UFED Reader file.  It is not unlikely that the person generating the Cellebrite Reader file for your review has not included things like the databases from the device (pictured below).  We’ll discuss the importance of this shortly…


The other strong warning about Cellebrite Reader (UFDR) files is that they MAY NOT include all of the data.  While companies like Cellebrite, Oxygen, MSAB and Magnet Forensic try very hard to keep up with the trends in mobile technology, they are always playing a game of catch-up with their support of hardware and software because mobile technology moves so fast.  Add into the support equation that only a fraction of third-party applications are supported for decoding by these tools and the point becomes clear that if you are relying solely on UFED Reader files, you are likely missing data!  There is currently no exception to this rule.

The analogy we often use is that the Cellebrite Reader file is like a “prepared meal”.  A competent digital forensic analyst wants to inspect the ingredients that went into preparing that “meal” to make sure there’s nothing missing.


What Data Is Missing From Cellebrite Reader Files?

At a basic level, all application data (i.e., apps) on mobile devices is stored in roughly the same way.  This common storage approach is in a series of databases that are created, updated and stored as part of the application itself.  The databases work in the background of the user interface to store and present the data to the user on the device in the native user experience.  The problem is that, as stated earlier, a mere fraction (probably 10% or less) of the applications available on the Apple App Store (iPhone) or Google Play Store (Android) are supported for automatic decoding in Cellebrite or any other mobile forensic analysis tool.  This means that manual analysis of these databases will frequently become a necessity in your cases.  And these databases may not included as part of a UFED Reader file, and you may only be provided with automatically decoded data from supported applications.  The illustration below shows a snapshot of how many applications are decoded by Cellebrite on an iPhone 8 Plus running iOS 14.  Among the applications not decoded are common applications like Snapchat, Twitter, Instagram and others:



Even if an application like WhatsApp is supported for automated decoding in your tool, when the developers of WhatsApp make even minor changes to the application in development and roll the new version of the application out to their users, this could cause the mobile forensic tool to no longer be able to decode and display the data automatically.   This is another circumstance where manual analysis of the database(s) for the application will be required and as stated previously, the databases may very well not be included in your Cellebrite Reader file.

This is why you should always consult with a digital forensic professional in any case where you are provided data from an opposing party, particularly if there is a possibility that any of this data could be presented as evidence.


Wrapping It Up

While Cellebrite and their UFED Reader program are used as an example in this article, many other mobile forensic tools also have similar lightweight versions for simple review of the data.  These are often called “portable case files”, or something similar.  Regardless of the tool and what they call their lightweight application, the same limitations and warnings apply.  And when faced with the possibility that your client could go to prison for a significant period of time or lose custody of their children or perhaps even lose a large sum of money, due diligence dictates consultation with an expert who knows how this data is stored, how to appropriately analyze it and what steps should be taken to ensure nothing is missed.  Lives depend on it!


Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/


Wednesday, May 13, 2020

So You Want To Start A Digital Forensic Business


May 13, 2020

So You Want To Start A Digital Forensic Business

Pro Digital Forensic Consulting is about to embark on it’s 7th year in full-time operation.  It’s hard to believe that when I made the decision to transition from law enforcement to the private sector, my little company would have come this far, servicing hundreds of clients through the years.  Because of my background and the contact I have with the DF community via this blog and professional associations, I usually receive inquiries about starting up a digital forensic consultancy/business several times a year.  In fact, I got another one just the other day via Linked In.  And with the current state-of-affairs (Covid-19 shut down) and people’s livelihoods being somewhat in question, it seems natural that some might consider taking on a new venture.  So, in the spirit of answering some of the frequently asked questions about what to expect if and when someone starts a digital forensic business, it seems a good idea to write down my thoughts and experience for future similar inquiries.  To be clear, I could (and may) write a book about this topic, but this blog is fairly well-established, so it seems the appropriate vehicle for sharing these lessons learned.  As a slight disclaimer, this article and the tips to follow are geared mainly toward sole-proprietor and small consulting firms.  I’m pretty sure Kroll and KPMG have this figured out J.



Tip #1:  Have A Supplemental Income Plan

Virtually no business starts off day 1 churning revenue and making a profit.  When Pro Digital was launched full-time in June of 2014, we billed a whopping $7,800 for the from that point to the end of 2014.  It would have been much less were it not for one large computer forensic case which accounted for nearly 85% of the billings for 2014.  Alongside the work that went into opening a business, I was also fortunate to have some things to fall back on personally, such as part-time and/or contract work, some of which had nothing to do with forensics.  The take-away here is that it’s important to have a supplemental income source that you can use to help keep your newly-formed lights on while the business is growing and you’re working on creating awareness and “buzz” for the business.  The downside is the marketing and awareness campaigns for your new shingle are a full-time business in themselves, so it can be double the work.  I’ll touch on marketing more in Tip #6.

Tip #2:  Keep Abreast of Trends

Most of my notable work in law enforcement was working for a full-service agency on the Internet Crimes Against Children (ICAC) Task Force.  Accordingly, all of my training and equipment was paid for by grants and other funding.  My last year in law enforcement was in an administrative role for a small campus police department, which had no use for any digital forensic expertise, so the skill sets that I’d worked on for the previous 5+ years sat on a shelf and collected dust.  When the business was launched full-time, I quickly realized how much things had evolved, changed and blown past me for the year I was not doing forensics.  This is a field driven by current events and evolving technology.  Try explaining the differences between and HFS+ and APFS file systems to someone who hasn’t been doing Mac forensics for a year or more.  It’s a vast change and the changes don’t stop.  I was amazed at how much I’d forgotten in that year and the learning curve was much steeper than I would have liked.  It’s imperative to keep up to date with the field.  Blogs, webinars, free training, list serves and colleagues are all great resources to keep current with what’s going on in the world of digital forensics. 

Tip #3:  Invest In GOOD Tools & Equipment

The start-up investment capital for Pro Digital was not a lot of money and was all self-funded.  Accordingly, I did some research on tools and cost/benefit analysis on the investment in those tools and/or training.  Initially, I purchased tools and equipment that wouldn’t break the bank and would get the job done.  It wasn’t long before I realized that certain things will save me time and therefore, money.  Along with that, it’s hard to work cases using tools no one has ever heard of before, particularly when the more tech-savvy attorneys with whom I work know the difference between one tool and another.  Some of these tools I still use.  Some of the software companies have basically gone belly-up and some I’ve gotten rid of over the years for one reason or another.  Additionally, some tools have been purchased for case-specific needs.  But the point remains that you need to invest in these things as if you were working a case for a loved-one.  Would you want the analyst on your father’s case using sub-par tools that no one really uses?  Probably not.  Spend the money and get the good stuff.  You’ll make your money back many times over.  The adage is true, you have to spend money to make money.

Tip #4:  Be Picky About Your Clients

When you’re hungry, everything looks like filet mignon.  The problem is, if you eat everything you’re “fed”, you’ll have a host of side-effects that will be hard to manage.  We used to work any and all cases that caused the phone to ring.  The most notable and frequent of these are the “I’ve been hacked” cases.  It is an unfortunate truth that there are many mentally ill people in the world and the internet gives them free reign to research to their hearts content and contact those whom they feel may be able to assist them in whatever issues they believe they are having, many of them tech-related.  But these cases are a forensic and business quagmire.  If you’re fortunate enough to get a client who will actually pay for your services, they will never be happy with the results.  This could eventually have an adverse effect on your professional reputation as well.  This is a reputation and referral-based business, so if you have clients that are in a position to ruin your reputation or malign you publicly, you will likely see fewer referrals over time. 

As a matter of policy, Pro Digital has transitioned to a purely litigation support model.  If you are not actively involved in litigation or a representative of a corporation that needs digital forensic services, we likely will not take your case.  If you’ve hired a PI to work your case, we may take it as a referral from a trusted source.  We don’t need anybody’s money *that* badly to work a case for someone who is obviously suffering from some form of mental illness or someone who wants to spy on their spouse to dig up enough dirt to file for divorce.  This is an ethical decision, but can also lead to legal issues if you’re not careful, i.e., theft of property, theft of data, unauthorized access to personal information, etc..  Also consider that if you are the digital forensic equivalent of an ambulance chaser, eventually you’ll devalue these services for everyone, including yourself.  Be picky.  It’s worth it.  You’ll get the clients you want and you’ll preserve your professional reputation, this much I know and have seen first-hand.  The big take-away here is always ensure you have written consent from the owner and/or an order from the court to access whatever you’re acquiring and analyzing.

Tip #5:  YOU Are Your Brand

Digital Forensics is a small community.  Whether you are in law enforcement, have transitioned out of law enforcement or have branched into digital forensics as an arm of your IT or infosec training, we generally know each other and recognize names and faces.  We also recognize when someone is either a charlatan or is pushing an obvious agenda to try and attract clients.  Everything you put out for public consumption (including blog articles) is subject to scrutiny, whether it be by the DF community, potential attorney-clients, opposing counsel, referral sources and/or other professional contacts.  If you have an opinion about something, make sure you’re on solid footing before getting into public discourse about it.  Take this recent example from a public post on Linked In from a professional contact (name and ID redacted):



I’ve worked many independent analysis cases for criminal defense attorneys and have been appointed by the court dozens of times.  I don’t know what this person is referring to, nor do I agree with their approach to putting this comment out publicly.  Business is relationships and everything that you put in writing can come back to haunt you.  I’ve received more referrals from my former law enforcement colleagues than I can remember over the years.  Do you know why?  Because I don’t take a public stand with an obvious agenda which maligns professionals.  Not only would I never call out the law enforcement community as essentially being crooked and/or liars, I don’t believe that they are because I haven’t seen it in my 7 years working full time in the private sector.  I have seen errors.  I have seen mistakes.  I have seen over-zealous investigators.  But I have not seen liars. There’s also nothing “science” about this post.  It’s an opinion and it’s part of an agenda to market specifically toward the criminal defense bar.

The reality of our industry is that the majority of who it serves is law enforcement and government, including government contractors.  The government is generally not on the cutting edge of anything, but they’ve certainly been on the cutting edge of digital forensics.  Can private practitioners access tools like Gray Key?  No.  But I have almost never had a need for Gray Key.  Why is that?  Refer back to tip #4.  I virtually always get a pass code and any necessary passwords either by consent or court order.  The only exception to this has been when the owner doesn’t remember the password, usually on an older device.  And to be clear, about 70% of the cases we work deal with mobile devices.

When in business, it may be beneficial to remember the wise words of Michael Jordan, who still has his own shoe brand, despite being out of basketball for over 15 years.  When asked at a press conference why he stays out of politics, his reply was simple:  “Both Republicans and Democrats buy shoes!”  Discretion is the better part of valor.

As a final point to this tip, I was in a discussion with a colleague in law enforcement recently while at a conference.  They said to me very confidently “The customer is always right, so you have to do what the client says no matter what!”  My reply:  “No I don’t!”  What’s the point?  Your professional integrity and reputation is your most valuable asset in this business.  Lose it and you’re done.  We will not alter any facts or data in any report or testimony to counsel or their clients, period.  I’m sorry if the data doesn’t support your case.  The data stands on its own and is irrefutable.  Truth is not fungible.

Tip #6:  Market Yourself (Because No One Else Will)

When I was a member of the ICAC Task Force, I was a fairly big fish in a pretty small pond.  The agency for whom I worked had less than 60 sworn officers and was in a rural area.  I did all of the tech-based investigation, search warrant planning & execution, evidence collection and as time progressed and casework grew, the forensic analysis.  And because many of these cases garnered a lot of public interest, the command staff frequently put me as the media relations person with these cases.  I never liked it.  As a cop, I considered myself a modest personality.  Others nominated me for awards and I was never comfortable in the spotlight.  When I launched the business, I quickly realized all of that had to change.

Because I had media contacts already in place, I offered my knowledge and experience as a local media resource for tech-related stories.  For a while, I was getting multiple calls every week from local media.  Because I had a lot of time (i.e., no clients) in the beginning, I also churned out blog articles virtually once a week.  I issued self-written press releases and worked hard on SEO for the company’s website.  I also began sponsoring several associations for litigators in my area because, as previously noted, this is a referral-based business.  In short, I had to become my own cheerleader because no one else was going to do it.  Furthermore, I learned VERY quickly that just having a good professional reputation and a business does not make the phone ring.  If you build it, they will not come – at least not like they did in Field Of Dreams.

If you want the business, you have to go get it.  And you have to keep on going out there to get it.  The minute you lapse on marketing, the phone will stop ringing.  This is why I’m constantly trying to add fresh content to the Pro Digital website.  Having a website is great.  Paying for Google ads is fine, but content is key.  I had to learn this and be taught what works and what doesn’t over time.  And I still make mistakes and spend money where I probably shouldn’t, but no one gave me a blueprint for running this business.  Tips, advice, counsel & support?  Yes.  But this is such a niche business, it requires a special marketing skill set.  If you don’t have it, you will likely fail.  This is the biggest area I think many ex-law enforcement are not comfortable with and probably what turns many of them off to launching their own business.  Quiet professionals don’t normally like the public spotlight.

Wrapping It Up

Some may read this article and wonder why on earth I would tell potential competitors how to run a successful digital forensic business?  One last tip I’ve learned over the years:  There’s plenty of work to go around.  I find it silly that a competitor of mine seemingly reported the Pro Digital Twitter as “spam”, which caused Twitter to shut it down.  I don’t want their clients.  I have my own and I am fortunate to bring on new ones every month.  If any of these tips can help someone be successful, I’m happy to share what I’ve learned.  No one taught me these things when I started out.  Hopefully by sharing some of these tips, I can pay it forward to the next old cop who wants to try his hand at something new(ish).  Until then, I’m off to work the next case and hopefully clear out my backlog queue.  Good luck!

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation
About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator and Physical Analyst as well as certified in cellular call detail analysis and mapping.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Email:  Inquiries@ProDigital4n6.com