DiscoverParsing the Truth: One Byte at a Time
Parsing the Truth: One Byte at a Time

Parsing the Truth: One Byte at a Time

Author: Parsing the Truth

Subscribed: 10Played: 322
Share

Description

Former FBI senior forensic examiners Becky Passmore and Stacy Eldridge dive into the world of digital forensics—one byte at a time. Now running their own firms and teaching the next wave of cyber sleuths, they share real-world case insights, expert tips, and a sharp sense of humor. From computer and iPhone forensics to ransomware attacks, this podcast unpacks how digital evidence solves modern crimes. Perfect for cybersecurity pros, students, and true crime techies. Join us as we Parse the Truth, One Byte at a Time.

We focus on how digital evidence is used to find facts in today's crimes.
66 Episodes
Reverse
Ahmad Gatlin (16) and 2 other teenagers are on trial for a drive-by shooting. What will significant locations, Uber, and Snapchat data reveal? Listen to the second half of the state's digital forensics examiner's testimony. Everything in this case is leading up to a surprise ending...This is Part 2 of a multiple-part series.Support the podcast by becoming a Patreon Member at ⁠⁠https://patreon.com/parsingthetruth⁠⁠Episode SummaryStacy Eldridge and Becky Passmore examine digital-forensics testimony from the Tennessee case State of Tennessee vs. Ahmed Gatlin. This episode discusses the second half of the state's digital forensic examiner's testimony. They discuss how investigators interpret phone extractions, photo and video metadata, Snapchat messages, and location data in an attempted-murder investigation. The episode also explores how timestamps can be misunderstood, why the original device matters, and how later handling of a phone may affect the interpretation of evidence.What You'll Learn:✔️How Apple Maps and phone-location data can be misinterpreted in court✔️Why timestamps, call logs, and digital artifacts require careful context✔️How the presentation of forensic evidence can shape a jury’s understanding
Ahmad Gatlin (16) and 2 other teenagers are on trial for a drive-by shooting. What will significant locations, Uber, and Snapchat data reveal? Tune in and find out in this case that brings a surprise ending.This is Part 1 of a multiple-part series.Support the podcast by becoming a Patreon Member at https://patreon.com/parsingthetruthEpisode SummaryStacy Eldridge and Becky Passmore examine digital-forensics testimony from the Tennessee case State of Tennessee vs. Ahmed Gatlin. They discuss how investigators interpret phone extractions, photo and video metadata, Snapchat messages, and location data in an attempted-murder investigation. The episode also explores how timestamps can be misunderstood, why the original device matters, and how later handling of a phone may affect the interpretation of evidence.What You'll Learn:How EXIF data and file-system timestamps can differ and why neither should automatically be treated as definitive proof. Why Snapchat evidence can be difficult to analyze Learn why phone-location evidence should be supported by additional artifacts.
The digital evidence contained no leads until Steve Bunting searched for nothing in the 2021 Keith Gibson murder case.Special Guest: Steven BuntingStacy Eldridge and Becky Passmore talk with digital forensics veteran Steve Bunting about the 2021 Keith Gibson murder case and the breakthrough that came from tracking phone inactivity instead of location data. Bunting explains how iPhone logs, unified logs, and FSEvents exposed a hidden “quiet time” window tied to the Delaware homicide, even when the original reader report showed nothing useful. He also breaks down why Apple location tiles only suggest a general area, why airplane mode is not the same as powering off a phone, and how a simple Python script can reveal patterns across millions of log entries.What You’ll learn:Why “nothing” can be the strongest digital clueHow power-off gaps show up in iPhone logsWhy location data can be misleading in courtHow to spot quiet time in noisy forensic dataWhy critical thinking matters more than button-pushingDownload the tool and start finding nothing todayhttps://buntingdigitalforensics.us/tools/fsevents-gap-finder/Read More About the Casehttps://buntingdigitalforensics.us/insights/the-art-of-hunting-for-nothing/Books written by Steve Buntinghttps://buntingdigitalforensics.us/publications/
Deepfakes are everywhere, and determining the Provenance of digital evidence is more important and challenging than ever before. Lars Daniel joins us to discuss the steps digital forensic examiners can take in their next case.Special Guest: Lars DanielConnect with Lars:⁠https://www.thelarsdaniel.com/⁠⁠https://www.linkedin.com/in/larsdaniel/⁠Support the podcast ⁠⁠⁠https://patreon.com/parsingthetruth⁠⁠⁠About this EpisodeStacy Eldridge and Becky Passmore talk with Lars about the growing risk of AI generated evidence, why screenshots and consumer device media are increasingly unreliable on their own, and why provenance now has to be treated as a core evidentiary issue.The conversation focuses on how examiners, attorneys, judges, insurers, and law enforcement can respond before fake media becomes routine in litigation and investigations.Key topicsIn this episode, Lars explains how his work in trucking and accident investigations led him into the deeper problem of AI manipulated media and digital evidence triage.He breaks down the practical categories he uses with counsel and claims professionals:He describes the business case for a layered review process: automated screening, human review, then a digital forensics expert when litigation is possible.The discussion emphasizes that the best way to prove authenticity is still to return to the original device and source evidence whenever possible.Lars warns that consumer device evidence often arrives with weak or no provenance, unlike enterprise systems that may have stronger built in controls.The hosts and Lars discuss how deep fake claims may become a litigation tactic, forcing the other side to spend time and money disproving authenticity even when the evidence is real.He explains the liar’s dividend and why it can be used not just as a defense, but as a strategy to raise costs and create uncertainty.A recent civil case example shows how a manipulated video, including added water to suggest a slip and fall, was initially treated as real until deeper analysis raised questions.Lars stresses that examiners need to stay in their lane, know when to refer specialized work, and avoid claiming expertise across every digital forensics niche.Listeners will learnHow deep fakes, shallow fakes, and enhancement differWhy screenshots are no longer enough to trust digital evidenceHow to build a layered authenticity review processWhy provenance matters in legal and investigative settingsWhen to return to the original device for verification
Part 2: We continue the conversation with Jessica Hyde regarding the Daubert Standard, AI, and Peer Reviews.Special Guest: Jessica Hyde, HexordiaSupport the podcast ⁠https://patreon.com/parsingthetruth⁠Detailed Summary of Part 2:In this episode, we explore the critical intersection of digital forensics, legal standards, and artificial intelligence. Jessica Hyde shares her expert insights on the importance of proper testing, validation, peer review, and the evolving standards that govern forensic evidence in court.Key topics in Part 2:The fundamentals of the Daubert standard for admissible scientific evidenceHow digital forensics tools and methodologies meet (or don’t meet) Daubert criteriaChallenges introduced by AI and machine learning models in forensic analysisThe critical role of peer review, including internal lab processes and community validationThe importance of independent testing and error rate assessment for evidence reliabilityUpcoming legislative and regulatory efforts around AI in forensic evidencePractical steps for examiners to prepare for Daubert challenges and improve credibilityThis episode emphasizes that sound scientific methodology, rigorous peer review, and validation are the backbone of credible digital forensic testimony. Links:The Daubert Standard ⁠https://www.law.cornell.edu/wex/daubert_standard⁠Rule 702 ⁠https://www.law.cornell.edu/rules/fre/rule_702⁠NIST Foundations document ⁠https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354.pdf⁠NIST OSAC Guidelines for Dataset Development ⁠https://www.nist.gov/system/files/documents/2026/01/16/OSAC-DE-Guidelines%20for%20Dataset%20Development.pdf⁠DFIR Review ⁠https://dfir.pubpub.org/⁠Upcoming work from SWGDE in this area including the draft Quality Management System ⁠https://www.swgde.org/25-q-001-draft/⁠ Hexordia Creating Mobile Text Data FREE Online Class ⁠https://learn.hexordia.com/courses/Creating-Mobile-Test-Data-66eae235a2b4ef2d6b79cef3⁠Hexordia FREE Mobile Peer Review Checklist ⁠https://www.hexordia.com/blog/gc0vnvj80ogwx724ovu7avzwvjl742?rq=peer%20review⁠Rule 707 Regarding AI ⁠https://www.purduegloballawschool.edu/blog/news/ai-generated-materials-federal-rules-evidence ⁠Connect with Jessica Hyde on LinkedIn ⁠https://www.linkedin.com/in/hydejessica/⁠Connect with Hexordia on Twitter ⁠https://x.com/hexordia⁠
loading
Comments