The clickety-clack of my mechanical keyboard brought me back down to earth.
My fingers poked away at the keys with purpose, each stroke, more rushed yet seemingly more convincing than the one before. To an onlooker, perhaps my commitment to the task at hand was unbridled, even maddening. You see, this case was going to trial! And so, I was relentless to ensure I left no stone unturned. The “what-ifs” tugged at me. I was tortured by a loop of unfinished thoughts – “is it possible that...”, “yes, but could...”, and “did you consider...”. I grunted. I could hear them – the condescending tones. I could see them – menacingly staring at my mouth, eager to snatch the next word said or unsaid. I was determined, therefore, to make an objective conclusion from my analysis, and pull as much truth from the data decoded by my tools. I felt ready. I felt all my bases were covered. I felt invincible!
I was wrong.
You see, I was wet behind the ears – like a child unbothered and unacquainted with the dangers that lurk in the shadows of an unfrequented park – that has a big green tree, but a swing that always swings with no rider. I was so consumed in completing my forensic report. I was so tunnel-visioned with preempting all the questions that might be asked of me in cross-examination that I did not see the blind spots.
Digital forensics is full of blind spots – the artifact you didn’t know existed, the timeline gap that breaks your case, the tool that silently gives you the wrong answer. There were many things I had overlooked, considered too quickly, or failed to question.
As I reflect on what I will regard as youthful exuberance, I’m now grateful for that experience. I appreciate my curiosity and the many things I still don’t know. I’m more judicious in my methodologies, and now question myself a little more. Why does that happen? What causes that to be there? Is that there because the system generated it or because of an interactive action by a user? In short, I’m still learning.
Forensics, at its core, is about asking the right questions, seeking out data, and correctly interpreting that data. I’ve been asking questions for over a decade – working cases in both the private sector and law enforcement, examining mobile devices, file systems, and incident timelines– digging into the artifacts that tell what actually happened. I started Blindspot Forensics to document what I find: the artifacts, the edge cases, and the blind spots that aren’t so obvious. I believe the best way to sharpen your practice, is to write it down, teach it, and share it. So that’s what I’m doing here. If you’re investigating for a living, or just want to understand how devices record the truth, I hope you find something useful here.
