Parsing the Truth: One Byte at a Time

Parsing the Truth: One Byte at a Time

By Parsing the TruthTechnology
Download on the App Store

Parsing the Truth: One Byte at a Time episodes

  • Karen Read 1-5; Ian Whiffin Testimony P2

    Ian Whiffin's testimony centers on digital artifacts and data analysis. We are covering the second half of his testimony, in which he shares the data he dug up to uncover the facts of this case. His testimony was very technical and descriptive. This is part 2 of 2 for Ian Whiffin's testimony.


    This is episode 5 of our deep dive into the 2024 Karen Read trial.


    Testimony provided by: Ian Whiffin, Cellebrite


    Digital forensics tools mentioned:

    • ArtEx
    • Cellebrite


    Digital forensics artifacts mentioned:

    • KnowledgeC.db
    • browserstate.db
    • com.app.mobilesafari.plist
    • history.db
    • web usage logs

    Key Terms:

    • Hos long to die in cold
    • How long ti die in cikd

    Exhibits:

    ⁠https://docs.google.com/spreadsheets/d/18lUM6dU2A7JcWSxgZb1t5qLeBkQ26z0h_JBWYPGThXQ/edit?gid=1477225811#gid=1477225811

    49 min
  • Karen Read 1-4: Ian Whiffin Testimony P1

    Ian Whiffin's testimony centers on digital artifacts and the analysis of data. We're breaking down the first half of his testimony, where he shares the data he dug into to uncover the facts of this case. His testimony was very technical and descriptive. This is part 1 of 2 for Ian Whiffin's testimony.


    This is episode 4 of our deep dive into the 2024 Karen Read trial.


    Testimony provided by: Ian Whiffin, Cellebrite


    Digital forensics tools mentioned:

    • ArtEx
    • Cellebrite


    Digital forensics artifacts mentioned:

    • KnowledgeC.db
    • browserstate.db
    • com.app.mobilesafari.plist
    • history.db
    • web usage logs


    Key Terms:

    • Hos long to die in cold
    • How long ti die in cikd


    Exhibits:

    https://docs.google.com/spreadsheets/d/18lUM6dU2A7JcWSxgZb1t5qLeBkQ26z0h_JBWYPGThXQ/edit?gid=1477225811#gid=1477225811



    35 min
  • Karen Read 1-3: Jessica Hyde Testimony Part 2

    We continue our deep dive into Jessica Hyde’s testimony, focusing on the second half of her analysis and the critical insights she uncovered. In this portion, she builds on the artifacts and findings introduced earlier, connecting the digital evidence to form a clearer narrative of events. Her testimony is so detailed and technically in-depth that we divided it into two parts. In this episode, we present Part 2 of 2, where the remaining elements of her forensic analysis are brought together to complete the full picture


    Testimony Provided By: Jessica Hyde of Hexordia


    Digital Forensics Tool mentioned:

    • Magnet Axiom Examine
    • Cellebrite
    • iLEAPP

    Digital Forensics Artifacts mentioned:

    • KnowledgeC.db
    • callhistory.storedata
    • com.apple.mobilesafari.plist
    • browser state.db
    • browserstat.db-WAL

    Key Terms:

    • Hos long to die in cold
    • How long ti die in cikd

    Links:

    Jessica Hyde's written report

    • ⁠https://drive.google.com/file/d/13dup-E9h3NmD0Tjhzl6Htudx34DQ0x5_/view?usp=sharing⁠

    List of 2024 Karen Read Trial Exhibits

    • ⁠https://docs.google.com/spreadsheets/d/18lUM6dU2A7JcWSxgZb1t5qLeBkQ26z0h_JBWYPGThXQ/edit?usp=sharing⁠

    Link to ScienceDirect article "Standardization of File Recovery Classification and Authentication."

    • https://www.sciencedirect.com/science/article/abs/pii/S1742287618304602
    30 min
  • Karen Read 1-2: Jessica Hyde Testimony Part 1

    Jessica Hyde's testimony centers around the search term "Hos long to die in cold" discovered on Jennifer McCabe's phone. We're breaking down the first half of her testimony, where she shares information about the artifacts she dug into to find the facts of the case. Her testimony was so detailed that we had to break it up into two parts. This is part 1 of 2 of Jessica Hyde's testimony.


    This is Episode 2 of our deep dive into the 2024 Karen Read trial.


    Testimony Provided By: Jessica Hyde of Hexordia


    Digital Forensics Tool mentioned:

    • Magnet Axiom Examine
    • Cellebrite
    • iLEAPP


    Digital Forensics Artifacts mentioned:

    • KnowledgeC.db
    • callhistory.storedata
    • com.apple.mobilesafari.plist
    • browser state.db
    • browserstat.db-WAL


    Key Terms:

    • Hos long to die in cold
    • How long ti die in cikd

    Links:

    Jessica Hyde's written report

    • https://drive.google.com/file/d/13dup-E9h3NmD0Tjhzl6Htudx34DQ0x5_/view?usp=sharing

    List of 2024 Karen Read Trial Exhibits

    • https://docs.google.com/spreadsheets/d/18lUM6dU2A7JcWSxgZb1t5qLeBkQ26z0h_JBWYPGThXQ/edit?usp=sharing

    Link to ScienceDirect article "Standardization of File Recovery Classification and Authentication."

    • https://www.sciencedirect.com/science/article/abs/pii/S1742287618304602



    36 min
  • Karen Read 1-1: Richard Green Affidavit

    A single Google search. A disputed timestamp. And a murder trial that ended in a mistrial.

    In the high-profile Karen Read case, competing digital forensics experts offered contradictory testimony about when a key witness searched “hos long to die in cold” on an iPhone. But let’s take a step back and first review the affidavit that started it all.

    This session breaks down defense expert Richard Green’s affidavit that challenged the prosecution’s narrative and ultimately won Karen Read access to additional evidence. We’ll discuss the specific artifacts Green analyzed, why context matters, and how no digital evidence artifact stands alone.

    This is Episode 1 of our deep dive into the 2024 Karen Read trial.


    Digital Forensics Tool mentioned:

    • Magnet Axiom
    • Cellebrite


    Digital Forensics Artifacts mentioned:

    • KnowledgeC.db
    • callhistory.storedata
    • com.apple.mobilesafari.plist
    • browser state.db

    Key Terms:

    • Hos long to die in cold
    • How long ti die in cikd

    Links:

    • Richard Green Affidavit
    • https://assets.super.so/669329c3-e11b-4cc8-9a05-1c7f310ff348/files/80f46306-87ad-41c2-a85a-138a816e44b6/Affidavit_of_Richard_Green_in_Support_of_Defendants_Motion_for_Order_Pursuant_to_MASS._R._CRIM._P._17_Directed_to_Brian_Albert_Verizon_and_ATT.pdf
    • Defense Motion
    • https://elderlaw.info/wp-content/uploads/2023/09/sj-2023-0343-petition.pdf
    33 min
  • Karen Read 2024 Trial Series Introduction

    We're starting our series on the 2024 Karen Read trial. We're digging into the testimony given by digital forensic examiners. In this episode, we're going to preview what we've got in store for you.


    What will the facts and artifacts reveal? Tune in every Thursday to find out!

    19 min
  • Was it Suicide or Murder? The Leslie Hartman Case.

    Did Leslie Hartman commit suicide, or was it murder? Did her boyfriend, a sheriff's deputy, murder her, or just make the 911 call? Find out how ChromeCache and trace evidence from Discord helped solve the case.

    Mario Merendon joins us this week to walk us through his role in this case. Mario emphasizes the importance of curiosity, validation, and inter-agency collaboration in digital forensic work. His careful testing and validation of timestamps, web cache data, and chat logs made the difference in solving this complex case. Special Guest: Mario Merendon of VX Digital Defense

    Find Mario at https://www.vxdigitaldefense.com/


    Digital Forensics Tools Mentioned in this Episode:

    • Magnet Forensics Axiom
    • ChromeCache
    • Dcode


    Digital Platforms Mentioned in this Episode:

    • Discord

    Key Topics from this Episode:

    • The importance of verifying digital evidence beyond default tool outputs
    • Utilizing open-source tools like ChromeCache View to dig deeper into web and application caches
    • Correlating timestamps from images, chats, and web activity to build a timeline
    • Challenges and solutions in extracting data from wiped phones and encrypted devices
    • The significance of validation and testing in building a credible digital case
    • Collaboration strategies with law enforcement and prosecutors to strengthen findings
    • Lessons learned: curiosity, thorough documentation, and validation as core to successful forensics
    54 min
  • Part 2: Printed Emails Aren't Digital Evidence

    Last week, we had lots of questions about those printed emails. So we brought on Lauren Hillery, who saw all the emails, to give us the inside scoop.


    Lauren shares the defense's strategy with regards to the emails, the authentication issues, and tells us more about hiring a digital forensic examiner as a public defender.


    This is Part 2 only. Go back and listen to Part 1 in S1 E38

    https://open.spotify.com/episode/3Xpa2gtG0fYI73sQV8Y37V?si=3vk-s0JQS0m3xPU0EW39Cg


    Special Guest: Public Defender Lauren Hillery


    Data Sources Mentioned in This Episode:

    • Twitter
    • Gmail
    • Email
    • iPhone
    1 hr 35 min
  • Part 1: Printed Emails aren't Digital Evidence

    Sixty printed emails. Partial evidence. Incomplete story. Learn how digital forensics can fill the gaps in this real-world case.


    Episode Summary:

    This week, Becky and Stacy explore a case where printed emails became the centerpiece of a legal trial. A mother and daughter presented 60 pages of printed emails, which were actually Twitter DM notifications, as evidence of a crime. Discussions include the complexities of email authentication, the potential for email spoofing, and why forensic examination is essential for verifying digital communications. Will the jury take the printed emails into consideration? Tune in, and find out.


    Key Takeaways:

    • Digital evidence can be easily manipulated, making authentication crucial.
    • Email headers are vital for verifying the origin of messages.
    • Forensic examiners play a key role in legal cases involving digital evidence.
    • Printed emails lack the necessary metadata for authentication.
    • Email spoofing is a common technique used to forge messages.
    • Forensic tools can reveal discrepancies in email timestamps.
    • Legal teams must understand digital evidence to argue effectively in court.
    • The jury's understanding of digital evidence can impact trial outcomes.
    • Forensic examiners must communicate findings clearly to non-experts.
    • Digital evidence issues can determine the outcome of a case.
    29 min
  • The Lauren Giddings Case

    David Freyman shares how collaboration helps put together the digital pieces of the Lauren Giddings murder. Learn how hashes of IP addresses, a seemingly innocuous USB drive, and a previously ignored digital camera reveal vital clues that bolster the case.Special Guest: Retired FBI SA David Freyman


    Digital Forensics Techniques Mentioned in this Episode:

    • MD5 Hashing: Used for verifying data integrity and identifying unique digital signatures.
    • Epoch Time Conversion: A method for interpreting timestamps stored as a series of numbers.
    • File Recovery Software: Utilized to recover deleted video files from a camera.


    The Lauren Giddings case was still making headlines in 2025. Learn more at https://www.13wmaz.com/article/news/local/macon/family-of-murdered-mercer-law-student-lauren-gidding-renew-search-body/93-9fda7367-e568-4c50-924e-8f4d1148631d


    48 min

About Parsing the Truth: One Byte at a Time

From the publisher's feed

Former FBI senior forensic examiners Becky Passmore and Stacy Eldridge dive into the world of digital forensics—one byte at a time. Now running their own firms and teaching the next wave of cyber sleuths, they share real-world case insights, expert tips, and a sharp sense of humor. From computer and iPhone forensics to ransomware attacks, this podcast unpacks how digital evidence solves modern crimes. Perfect for cybersecurity pros, students, and true crime techies. Join us as we Parse the Truth, One Byte at a Time.

More shows like Parsing the Truth: One Byte at a Time

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Dateline NBC by NBC News

Dateline NBC

46,924 Listeners

The Thing About Pam by NBC News

The Thing About Pam

15,526 Listeners

Morning Wire by The Daily Wire

Morning Wire

26,552 Listeners