Parsing the Truth: One Byte at a Time

Parsing the Truth: One Byte at a Time

By Parsing the TruthTechnology
Download on the App Store

Parsing the Truth: One Byte at a Time episodes

  • TN vs Ahmad Gatlin: Part 4

    In this episode of Parsing the Truth One Bite at a Time, Stacy Eldridge and Becky Passmore unpack digital evidence and courtroom testimony in the Tennessee v. Ahmed Gatlin trial. They examine how Snapchat files, phone settings, timestamps, Uber location data, Wi-Fi activity, and iPhone records can shape — or complicate — a forensic timeline. The discussion highlights why a file’s location and metadata matter, how device time settings can affect timestamps, and why different digital records may tell different parts of the story. For listeners interested in digital forensics, true crime, or how electronic evidence is challenged in court, this episode offers a plain-language look at the details behind high-stakes testimony.


    Three things you will learn from this Episode:


    ✔️Why Snapchat images or videos may appear in multiple places on a phone, and why that matters when examining a file.

    ✔️How time-zone and daylight-saving settings can affect the timestamps used to build a digital timeline.

    ✔️What Uber location updates, Wi-Fi records, and call logs can each indicate — and what they may not prove on their own.

    29 min
  • TN vs Ahmad Gatlin: Part 3

    This episode explores the cross-examination of a digital forensics expert in the Ahmed Gatlin case, revealing how mobile phone evidence, cloud storage, app permissions, and location data can be interpreted in court. It also offers practical lessons for expert witnesses on preparing for testimony and answering technical questions accurately.


    What You'll learn:

    ✔️Why digital forensic experts should know the legal basis for accessing a device and bring notes or reports to court.

    ✔️Why gaps in phone activity data don’t, by themselves, prove whether a phone was off, idle, or simply not recording.

    ✔️How app-specific location permissions differ from phone-wide settings—and why mobile data may be stored on a device, in the cloud, or both.

    30 min
  • TN vs Amad Gatlin: Part 2

    Ahmad Gatlin (16) and 2 other teenagers are on trial for a drive-by shooting. What will significant locations, Uber, and Snapchat data reveal? Listen to the second half of the state's digital forensics examiner's testimony. Everything in this case is leading up to a surprise ending...


    This is Part 2 of a multiple-part series.


    Support the podcast by becoming a Patreon Member at

    ⁠⁠https://patreon.com/parsingthetruth⁠⁠


    Episode Summary

    Stacy Eldridge and Becky Passmore examine digital-forensics testimony from the Tennessee case State of Tennessee vs. Ahmed Gatlin. This episode discusses the second half of the state's digital forensic examiner's testimony. They discuss how investigators interpret phone extractions, photo and video metadata, Snapchat messages, and location data in an attempted-murder investigation. The episode also explores how timestamps can be misunderstood, why the original device matters, and how later handling of a phone may affect the interpretation of evidence.



    What You'll Learn:

    ✔️How Apple Maps and phone-location data can be misinterpreted in court

    ✔️Why timestamps, call logs, and digital artifacts require careful context

    ✔️How the presentation of forensic evidence can shape a jury’s understanding

    27 min
  • TN vs Amad Gatlin: Part 1

    Ahmad Gatlin (16) and 2 other teenagers are on trial for a drive-by shooting. What will significant locations, Uber, and Snapchat data reveal? Tune in and find out in this case that brings a surprise ending.


    This is Part 1 of a multiple-part series.


    Support the podcast by becoming a Patreon Member at

    https://patreon.com/parsingthetruth


    Episode Summary

    Stacy Eldridge and Becky Passmore examine digital-forensics testimony from the Tennessee case State of Tennessee vs. Ahmed Gatlin. They discuss how investigators interpret phone extractions, photo and video metadata, Snapchat messages, and location data in an attempted-murder investigation. The episode also explores how timestamps can be misunderstood, why the original device matters, and how later handling of a phone may affect the interpretation of evidence.


    What You'll Learn:

    • How EXIF data and file-system timestamps can differ and why neither should automatically be treated as definitive proof.
    • Why Snapchat evidence can be difficult to analyze
    • Learn why phone-location evidence should be supported by additional artifacts.
    32 min
  • When nothing is all you got

    The digital evidence contained no leads until Steve Bunting searched for nothing in the 2021 Keith Gibson murder case.


    Special Guest: Steven Bunting

    Stacy Eldridge and Becky Passmore talk with digital forensics veteran Steve Bunting about the 2021 Keith Gibson murder case and the breakthrough that came from tracking phone inactivity instead of location data. Bunting explains how iPhone logs, unified logs, and FSEvents exposed a hidden “quiet time” window tied to the Delaware homicide, even when the original reader report showed nothing useful. He also breaks down why Apple location tiles only suggest a general area, why airplane mode is not the same as powering off a phone, and how a simple Python script can reveal patterns across millions of log entries.


    What You’ll learn:

    • Why “nothing” can be the strongest digital clue
    • How power-off gaps show up in iPhone logs
    • Why location data can be misleading in court
    • How to spot quiet time in noisy forensic data
    • Why critical thinking matters more than button-pushing


    Download the tool and start finding nothing today

    https://buntingdigitalforensics.us/tools/fsevents-gap-finder/


    Read More About the Case

    https://buntingdigitalforensics.us/insights/the-art-of-hunting-for-nothing/


    Books written by Steve Bunting

    https://buntingdigitalforensics.us/publications/

    46 min
  • The Problem with Deepfakes

    Deepfakes are everywhere, and determining the Provenance of digital evidence is more important and challenging than ever before. Lars Daniel joins us to discuss the steps digital forensic examiners can take in their next case.


    Special Guest: Lars Daniel


    Connect with Lars:

    ⁠https://www.thelarsdaniel.com/⁠

    ⁠https://www.linkedin.com/in/larsdaniel/⁠


    Support the podcast ⁠⁠⁠https://patreon.com/parsingthetruth⁠⁠⁠

    About this Episode

    Stacy Eldridge and Becky Passmore talk with Lars about the growing risk of AI generated evidence, why screenshots and consumer device media are increasingly unreliable on their own, and why provenance now has to be treated as a core evidentiary issue.The conversation focuses on how examiners, attorneys, judges, insurers, and law enforcement can respond before fake media becomes routine in litigation and investigations.


    Key topics

    • In this episode, Lars explains how his work in trucking and accident investigations led him into the deeper problem of AI manipulated media and digital evidence triage.
    • He breaks down the practical categories he uses with counsel and claims professionals:
    • He describes the business case for a layered review process: automated screening, human review, then a digital forensics expert when litigation is possible.
    • The discussion emphasizes that the best way to prove authenticity is still to return to the original device and source evidence whenever possible.
    • Lars warns that consumer device evidence often arrives with weak or no provenance, unlike enterprise systems that may have stronger built in controls.
    • The hosts and Lars discuss how deep fake claims may become a litigation tactic, forcing the other side to spend time and money disproving authenticity even when the evidence is real.
    • He explains the liar’s dividend and why it can be used not just as a defense, but as a strategy to raise costs and create uncertainty.
    • A recent civil case example shows how a manipulated video, including added water to suggest a slip and fall, was initially treated as real until deeper analysis raised questions.
    • Lars stresses that examiners need to stay in their lane, know when to refer specialized work, and avoid claiming expertise across every digital forensics niche.


    Listeners will learn

    • How deep fakes, shallow fakes, and enhancement differ
    • Why screenshots are no longer enough to trust digital evidence
    • How to build a layered authenticity review process
    • Why provenance matters in legal and investigative settings
    • When to return to the original device for verification
    40 min
  • The Daubert Standard Part 2 - What you Need to Know

    Part 2: We continue the conversation with Jessica Hyde regarding the Daubert Standard, AI, and Peer Reviews.

    Special Guest: Jessica Hyde, Hexordia


    Support the podcast ⁠https://patreon.com/parsingthetruth⁠


    Detailed Summary of Part 2:

    In this episode, we explore the critical intersection of digital forensics, legal standards, and artificial intelligence. Jessica Hyde shares her expert insights on the importance of proper testing, validation, peer review, and the evolving standards that govern forensic evidence in court.


    Key topics in Part 2:

    • The fundamentals of the Daubert standard for admissible scientific evidence
    • How digital forensics tools and methodologies meet (or don’t meet) Daubert criteria
    • Challenges introduced by AI and machine learning models in forensic analysis
    • The critical role of peer review, including internal lab processes and community validation
    • The importance of independent testing and error rate assessment for evidence reliability
    • Upcoming legislative and regulatory efforts around AI in forensic evidence
    • Practical steps for examiners to prepare for Daubert challenges and improve credibility


    This episode emphasizes that sound scientific methodology, rigorous peer review, and validation are the backbone of credible digital forensic testimony.


    Links:

    • The Daubert Standard ⁠https://www.law.cornell.edu/wex/daubert_standard⁠
    • Rule 702 ⁠https://www.law.cornell.edu/rules/fre/rule_702⁠
    • NIST Foundations document ⁠https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354.pdf⁠
    • NIST OSAC Guidelines for Dataset Development ⁠https://www.nist.gov/system/files/documents/2026/01/16/OSAC-DE-Guidelines%20for%20Dataset%20Development.pdf⁠
    • DFIR Review ⁠https://dfir.pubpub.org/⁠
    • Upcoming work from SWGDE in this area including the draft Quality Management System ⁠https://www.swgde.org/25-q-001-draft/⁠
    • Hexordia Creating Mobile Text Data FREE Online Class ⁠https://learn.hexordia.com/courses/Creating-Mobile-Test-Data-66eae235a2b4ef2d6b79cef3⁠
    • Hexordia FREE Mobile Peer Review Checklist ⁠https://www.hexordia.com/blog/gc0vnvj80ogwx724ovu7avzwvjl742?rq=peer%20review⁠
    • Rule 707 Regarding AI ⁠https://www.purduegloballawschool.edu/blog/news/ai-generated-materials-federal-rules-evidence ⁠
    • Connect with Jessica Hyde on LinkedIn ⁠https://www.linkedin.com/in/hydejessica/⁠
    • Connect with Hexordia on Twitter ⁠https://x.com/hexordia⁠

    33 min
  • The Daubert Standard: What you need to know Part 1

    Jessica Hyde joins us to explain what you need to know about Daubert to help you ensure your evidence doesn't get tossed in your next big case. We'll also discuss a new proposed rule of evidence regarding AI.


    Special Guest: Jessica Hyde, Hexordia


    Support the podcast https://patreon.com/parsingthetruth


    Detailed Summary of Part 1:

    In this episode, we explore the critical intersection of digital forensics, legal standards, and artificial intelligence. Jessica Hyde shares her expert insights on the importance of proper testing, validation, peer review, and the evolving standards that govern forensic evidence in court.

    Key topics:

    • The Daubert standard: what it is and why it matters for forensic evidence
    • Five Daubert factors: testing, peer review, error rates, standards, and general acceptance
    • Challenges of using black box AI tools and generative models in forensic analysis
    • Why clicking 'export report' without validation is a legal liability
    • The upcoming Federal Rule of Evidence 707 and its impact on AI-generated evidence
    • The importance of independent testing, standardization, and peer review in court readiness
    • Nightmare scenarios: when evidence fails Daubert criteria, leading to inadmissibility
    • The role of certification, experience, and standardization for digital forensic examiners
    • How practitioners can proactively prepare for Daubert challenges and legislative changes
    • Practical steps for conducting rigorous testing and peer review of forensic artifacts


    This episode emphasizes that sound scientific methodology, rigorous peer review, and validation are the backbone of credible digital forensic testimony.


    Links:

    • The Daubert Standard https://www.law.cornell.edu/wex/daubert_standard
    • Rule 702 https://www.law.cornell.edu/rules/fre/rule_702
    • NIST Foundations document https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354.pdf
    • NIST OSAC Guidelines for Dataset Development https://www.nist.gov/system/files/documents/2026/01/16/OSAC-DE-Guidelines%20for%20Dataset%20Development.pdf
    • DFIR Review https://dfir.pubpub.org/
    • Upcoming work from SWGDE in this area including the draft Quality Management System https://www.swgde.org/25-q-001-draft/
    • Hexordia Creating Mobile Text Data FREE Online Class https://learn.hexordia.com/courses/Creating-Mobile-Test-Data-66eae235a2b4ef2d6b79cef3
    • Hexordia FREE Mobile Peer Review Checklist https://www.hexordia.com/blog/gc0vnvj80ogwx724ovu7avzwvjl742?rq=peer%20review
    • Rule 707 Regarding AI https://www.purduegloballawschool.edu/blog/news/ai-generated-materials-federal-rules-evidence
    • Connect with Jessica Hyde on LinkedIn https://www.linkedin.com/in/hydejessica/
    • Connect with Hexordia on Twitter https://x.com/hexordia
    48 min
  • Brett Shavers and the Investigative Mindset

    This episode with Brett Shavers explores why the most important skill in digital forensics is an investigative mindset—using critical thinking, legal authority, and objective analysis to follow the evidence, avoid bias, and tell a clear story from the data.More about this episode:In this episode of Parsing the Truth One Bite at a Time, Stacey Eldridge and Becky Passmore sit down with digital forensics expert Brett Shavers to explore what really separates strong examiners from great investigators. Rather than focusing only on tools and software, the conversation dives into the investigative mindset, critical thinking, confirmation bias, legal authority, and how to build defensible conclusions from digital evidence.


    Listeners will learn why forensic tools are only a means to an end, how to challenge assumptions during an examination, and why clear communication is just as important as technical skill. Brett also shares practical insights on AI in digital forensics, explaining where it can help, where it can mislead, and why human judgment still matters. Whether you work in digital forensics, teach the subject, or want to understand how investigations are built from evidence, this episode offers actionable lessons you can use immediately.


    Connect with Brett Shavers Online

    ⁠https://www.dfir.training/about-brett-shavers⁠

    ⁠https://www.linkedin.com/in/brettshavers/⁠

    Grow your Investigative Mindset with Brett Shavers Books

    ⁠https://brettshavers.com/my-books⁠


    Support the Podcast

    ⁠https://www.patreon.com/c/ParsingtheTruth⁠


    Get Parsing the Truth Swag and Merch

    ⁠https://parsing-the-truth.printify.me/⁠

    48 min
  • The People vs Michael Jackson Part 2

    In the 2005 trial of the People vs Michael Jackson, the FBI examined numerous Mac computers and laptops, but there was no testimony regarding any of that digital evidence. What did the FBI find? Or rather, what didn't they find? And why wasn't there any testimony? We discuss all that and more in this week's episode.


    Support the podcast by joining our Patreon community!

    ⁠https://www.patreon.com/cw/ParsingtheTruth⁠


    Parsing the Truth merchandise is finally available

    ⁠http://parsing-the-truth.printify.me⁠


    Learn more about our Episode Sponsor

    https://acecomputers.com/forensics/


    The FBI Vault on Michael Jackson

    ⁠https://vault.fbi.gov/Michael%20Jackson⁠


    Michael Jackson Trial Transcripts

    ⁠https://www.themichaeljacksoninnocentproject.com/transcripts-patrons-only/⁠

    More on this episode...

    Discover how case notes, chain-of-custody logs, and redacted FOIA documents reveal a story of procedural missteps, technical confusion, and the challenges of late 90s and early 2000s digital forensics. You’ll uncover:

    • How law enforcement and forensic experts classified, stored, and tracked digital evidence in a high-profile case
    • Why crucial digital evidence was excluded from the courtroom
    • The significance of the FOIA releases, redacted case notes, and courtroom transcripts that show the struggle of proving or disproving digital misconduct
    • How the complexities of Mac computers, confusing acronyms, and outdated technology hindered the case’s digital narrative
    • Why this case remains a cautionary tale in digital forensics, highlighting the importance of proper evidence collection, documentation, and expert testimony

    This episode is perfect for legal professionals, digital forensic investigators, courtroom enthusiasts, or anyone interested in understanding how digital evidence can make or break a trial — especially when it’s mishandled or misunderstood. If you’ve ever wondered what really happens behind the scenes when law enforcement investigates digital devices, this episode is your answer.

    31 min

About Parsing the Truth: One Byte at a Time

From the publisher's feed

Former FBI senior forensic examiners Becky Passmore and Stacy Eldridge dive into the world of digital forensics—one byte at a time. Now running their own firms and teaching the next wave of cyber sleuths, they share real-world case insights, expert tips, and a sharp sense of humor. From computer and iPhone forensics to ransomware attacks, this podcast unpacks how digital evidence solves modern crimes. Perfect for cybersecurity pros, students, and true crime techies. Join us as we Parse the Truth, One Byte at a Time.

More shows like Parsing the Truth: One Byte at a Time

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Dateline NBC by NBC News

Dateline NBC

46,924 Listeners

The Thing About Pam by NBC News

The Thing About Pam

15,526 Listeners

Morning Wire by The Daily Wire

Morning Wire

26,552 Listeners