Trial 1 Transcript Jessica Hyde
Trial 1 / Day 25 / June 14, 2024
3 pages · 2 witnesses · 1,991 lines
Jessica Hyde addressed phone-search artifacts and the scope of her analysis. Trooper Joseph Paul testified about vehicle data, followed by voir dire and deferred ruling on a Ring-video opinion.
Jessica Hyde Direct Examination
1

(Court in session.)

2

(Defendant is present with counsel.)

3

(Jury in.)

4

(Testimony commences at 10:22 a.m.)

5

JESSICA HYDE, sworn

6

DIRECT EXAMINATION BY MR. LALLY:

7 34:45

MR. LALLY: Ma'am, if you want, that microphone is adjustable. You can put it pretty much anywhere you're comfortable with, okay?

8 34:56

MS. HYDE: Thank you.

9 34:56

MR. LALLY: Good morning.

10 34:57

MS. HYDE: Good morning.

11 34:58

MR. LALLY: Could you please state your name and spell your last name for the jury?

12 35:01

MS. HYDE: Jessica Hyde, H-Y-D-E.

13 35:04

MR. LALLY: And what do you do for work, ma'am?

14 35:06

MS. HYDE: I'm a digital forensics examiner. I own a digital forensics firm that does training, services, and research.

15 35:12

MR. LALLY: And the digital forensics firm that you own, what's it called?

16 35:16

MS. HYDE: Hexordia, H-E-X-O-R-D-I-A.

17 35:19

MR. LALLY: And how long have you had your own firm?

18 35:22

MS. HYDE: Three years.

19 35:24

MR. LALLY: Now, Ms. Hyde, if I could ask you to talk a little bit about your educational background and your work history. Starting with undergraduate, where did you go and what if any degrees did you receive?

20 35:36

MS. HYDE: My undergraduate degree is a bachelor of science is electronics engineering technologies. I was on active duty in the Marine Corps at the time, so I went to several schools. My final graduation was from ECPI.

21 35:46

JUDGE CANNONE: I want you to slow down your speech.

22 35:48

MS. HYDE: Oh, so sorry, ma'am. Sorry, Your Honor. A So my final graduation was From ECPI College of Technology. However, I attended several universities because I was on active duty at the time.

23 36:01

MR. LALLY: And following your undergraduate, where did you go from there?

24 36:04

MS. HYDE: From there, I went and completed my tour on active duty. I went into work in the field and eventually then did my master's in computer forensics from George Mason University.

25 36:16

MR. LALLY: And when about was it that you received your master's in computer forensics from George Mason?

26 36:21

MS. HYDE: I received my master's, I believe, 2014.

27 36:25

MR. LALLY: And as far as you mentioned that you had started working a little bit post military, but before going to grad school; is that right?

28 36:32

MS. HYDE: Correct. I started working in digital forensics in 2010.

29 36:37

MR. LALLY: And where did you begin when you started working in 2010?

30 36:39

MS. HYDE: I was a contractor for a company called American Systems working at the terrorist explosive device analytical center called TDAC.

31 36:49

MR. LALLY: And following, sort of going forward to when you received your graduate degree, if you could speak a little bit about your work history since then?

32 36:56

MS. HYDE: Sure.

33 36:57

MR. LALLY: So I continued to work at TDAC while I had completed my degree. That was doing digital forensic analysis on phones that were connected to improvised explosive devices. So most of the phones I received was post-blast, and I would recover data from that and analyze that. From there, once I had completed my degree, I went and worked in the regular private sector. I worked for Ernst and Young, now called EY. There, I was one of their mobile forensics experts working a variety of cases, everything from insider threat to insider trading. Then I really missed doing more public service work, so I left to go to the National Media Exploitation Center, which is a -- I worked there as a contractor under a company called Basis Technology. That organization supports 22 government agencies in the intelligence community supporting the things that are either the highest priority or the things that other organizations can't support. So we were the center of excellence for the US government in mobile exploitation, and I ran that team there.

34 38:08

MR. LALLY: Now, and then --

35 38:10

MS. HYDE: From -- from there. I can go from there. From there, I went and became the director of forensics for Magnet Forensics, which is a company that develops tools for digital forensics. So there I was in a position where I did a large amount of research into new artifacts, unsupported access to devices, et cetera. I was there for five years before starting my own firm.

36 38:38

MR. LALLY: And then, what did you -- no, I'm sorry. Let me start again. As far as what, if any, teaching experience do you have in relation to this field?

37 38:46

MS. HYDE: That is an excellent question. I've actually been an adjunct professor at George Mason University since 2016. I've taught 20 terms in their graduate program. I teach the mobile forensic analysis course in their digital forensics master's program.

38 39:03

MR. LALLY: In addition to your work and your teaching and all your training, are there any professional organizations related to your field that you're a member of?

39 39:12

MS. HYDE: Actually several. I am a member of the Organizational Scientific Area Committee on Digital Evidence, which is a part of NIST, the National Institute of Science Technology. I am a member of the Scientific Working Group on Digital Evidence, also called SWIGD-E. I am the chair of a project called DFIR Review. That does peer review of academic work that's done by practitioners in the form of blogs. I've been chairing that project since 2018 when it started with our first publications in 2019. I am the first VP at the international executive committee level of the High Tech Crime Investigation Association, also called HTCIA, which I've been a member of since 2012, and I will ascend to -- I've been elected. I'll ascend to president next September. I am also -- see, I do a lot of volunteer work. I also am an associate member of the American Academy of Forensic Sciences, AAFS. And I just recently finished my term as an associate editor for Forensic Science International Digital Investigation, which is a peer reviewed journal in the academic space of digital forensics, and I'm still a reviewer, but I stepped down from my duties as an associate editor.

40 40:36

MR. LALLY: Bringing me to my next question, what if any sort of articles or publications have you published in relation to your field?

41 40:42

MS. HYDE: That's a great question. I've published a paper on the standardization of data recovery. I worked on that with Dr. Owen Casey and Dr. Nelson. That was published in "Forensic Science International digital Investigations Journal." I also was the second author on a paper related to the use of AI in digital forensics, artificial intelligence. And I published numerous articles, blogs, white papers. I probably have published about 20 of those, but just speaking to the peer review work, too.

42 41:17

MR. LALLY: When you say peer review, can you explain to the jury a little bit about what that means or what that process entails?

43 41:21

MS. HYDE: Absolutely. So a peer reviewed work is when you have a novel piece of research that you then submit that novel, never been presented work to a journal. It then gets reviewed by numerous academic peers. It goes through cycles of revision where they ask more questions. On the Standardization of File Recovery paper, that process took about 14 months for it to be peer reviewed by experts in the field, and then it is published in a journal.

44 41:49

MR. LALLY: So you've had both articles that you've authored that have been peer reviewed and published, as well as you perform the role of reviewer of other people's work.

45 41:56

MS. HYDE: Correct. I perform the in addition to the publications I've done, I reviewed at least 20 to 30 articles, both in a combination of support for "Forensic Science International Digital Investigations Journal" and DFIR review.

46 42:12

MR. LALLY: Now, if you could explain to the jury, when you say the term as far as digital forensics, what do you understand that term to mean with relation to what you do?

47 42:24

MS. HYDE: I would describe digital forensics as the analysis of data from any storage medium that can control data, be that a mobile phone, computer or cloud, for the intention of that data intentionally being used for court.

48 42:41

MR. LALLY: And with reference to your firm Hexordia, where is that located? What state?

49 42:46

MS. HYDE: We are headquartered in New York State in Bridgeport, New York which is outside of Syracuse. We also have an office location in the DC metro area in Tyson's Corner. But we have -- we have employees in six states.

50 43:02

MR. LALLY: And with respect to your duties and responsibilities in regards to your firm, what is it that you do?

51 43:08

MS. HYDE: Great question. So I do perform digital forensic analysis on cases. I currently work on two US government contracts supporting one digital forensic analysis and two novel research and exploitation of mobile devices. So I'm named personnel on two contracts, and then I manage another three. I also developed training for mobile forensics. My courses have been taken by people all over the country, and Hexordia also delivers that training. I also do research and presentations for journals, conferences, et cetera. So a combination of casework, education, and research.

52 43:45

MR. LALLY: Now, Ms. Hyde, if I could turn your attention to May of 2023. At some point during that month, were you contacted by the Northeast District Attorney's Office in relation to this case?

53 43:59

MS. HYDE: Yes, on May 4, I was contacted by Detective Kelly via our website about this case.

54 44:06

MR. LALLY: And eventually, was there a contract that was executed and you agreed to do some work in relation to one -- one specific area of this case?

55 44:16

MS. HYDE: Yes. A contract was executed on May 9, and work began on May 10th of 2023.

56 44:22

MR. LALLY: And as far as the specific information in relation to this case, what was it that that you looked at?

57 44:26

MS. HYDE: The --

58 44:26

MR. LALLY: I'm sorry. Let me start with this. What was it that you were asked to look for?

59 44:30

MS. HYDE: I was asked to look at two specific Google search terms that took place on January 29.

60 44:40

MR. LALLY: And with regards to the information that was provided, and we'll get to that in a moment, but with respect to the question that was asked, was it a question that was posed, or were you asked to find some sort of specific response?

61 44:55

MS. HYDE: I was asked to look at the timelines and time stamps related to those Google searches.

62 45:01

MR. LALLY: Now, with regard to what, if anything, was then provided to you, or what, if anything, did you review in the course of your analysis?

63 45:08

MS. HYDE: I received two reports. I received the affidavit from Richard Green, and I received the report from Trooper -- I don't want to butcher his name, but something along the lines of Nicholas Guarino.

64 45:21

MR. LALLY: Perfect.

65 45:22

MS. HYDE: Oh, good.

66 45:24

MR. LALLY: And is it understanding that Mr. Green was a person that was retained by the defense in this case?

67 45:31

MS. HYDE: Yes, I was aware of that.

68 45:33

MR. LALLY: So you essentially you received reports from the trooper from the state police and a witness for the defense, correct? A That is correct.

69 45:40

MR. LALLY: In addition to those two reports, what, if anything else, did you receive in relation to your analysis?

70 45:47

MS. HYDE: On May 10, I received via US postal mail a copy of the drive with data from a phone that was identified to me as belonging to Jennifer McCabe. It was a full file system extraction from a GrayKey.

71 46:01

MR. LALLY: And so when you received that information, what, if anything, did you do?

72 46:05

MS. HYDE: The first thing I did with that data set after having been retained was I made a forensic copy. I use an ArcPoint ATRIO to copy the data from that original disk, which was then placed in our safe to a working copy drive.

73 46:20

MR. LALLY: And that ArcPoint ATRIO, what is that?

74 46:23

MS. HYDE: It's a forensics tool that does extraction and duplication.

75 46:28

MR. LALLY: And then once that process was completed, what did you do from there?

76 46:31

MS. HYDE: I immediately verified the hash value of my new image to make sure that it matched the hash value of the original image.

77 46:40

MR. LALLY: And what is a hash value?

78 46:42

MS. HYDE: A hash value is an algorithmic numerical representation of the data. So when you have a hash value, that value is unique to a certain set of data. So when you have that same hash value matching, you're ensuring that your copy that you made was correct and not in any way damaged or corrupt.

79 47:03

MR. LALLY: And as far as matching those hash values, were you able to do -- do so?

80 47:08

MS. HYDE: Yes, the hash values of both the copy I made to work from and the original match. They also match the document that came along with the drive stating the original hash value.

81 47:20

MR. LALLY: And then what did you do from there?

82 47:22

MS. HYDE: From there, I processed the image in several forensics tools. I used Cellebrite Physical Analyzer. I used Magnet Axiom. I used a tool called Artex, A-R-T-E-X. I utilized a tool called iLeap, and I later used a tool called Sanderson Forensics SQLite, but I did not use that tool at this point.

83 47:47

MR. LALLY: Now with reference to the tools that you used that you just went through, are those fairly common tools? Are those tools that are commonly used within your industry?

84 47:57

MS. HYDE: Yes, they are commonly used digital forensics tools that are very standard for other forensics examiners to use on mobile exploitation.

85 48:05

MR. LALLY: And as far as those different types of tools, is that -- so I guess my question is, there were a variety of different tools that you used?

86 48:13

MS. HYDE: Correct.

87 48:13

MR. LALLY: And why were you using the different tools?

88 48:16

MS. HYDE: So different forensics tools have different capabilities and look at data a little bit differently. Phones have thousands of applications. If you look at the Apple Store or the Google Play store, you can download a total of six million apps between the two. Commercial forensics tools, they can only support so many applications, so they each work and support different bits of data. So it's important to use multiple tools so you can see the results from different table -- different data sets and be able to compare those results and enhance those with manual analysis.

89 48:52

MR. LALLY: And with respect to using those sort of different variety of tools from Cellebrite to Axioms to Artex, et cetera, is that something that you typically do as far as your normal process of documenting a forensic analysis?

90 49:06

MS. HYDE: Yeah, that's very, very typical for me to process with multiple tools to ensure that I'm getting the most complete interpretations from forensics tools. Of course, you go beyond that with your analysis, but it's absolutely pertinent to do that. I would run some of those tools before others, because of speed and so I can begin analysis while other tools are running.

91 49:27

MR. LALLY: If I could ask you just this about the last one that you mentioned just briefly as far as the Sanderson Tool.

92 49:33

MS. HYDE: Yes.

93 49:34

MR. LALLY: Can you explain to the jury, sort of what that is and how that interplays with the other tools and analysis?

94 49:41

MS. HYDE: The Sanderson Tool is meant to look at a specific type of data structure called the SQLite database. SQLite databases are very nuanced, and this particular tool allows you to take that database and explore it at a deeper level than the other forensics tools allow.

95 50:00

MR. LALLY: And just for the record when you use that term as far as the SQLite database, how is that spelled?

96 50:06

MS. HYDE: It is capital S-Q-L lowercase I-T-E. and SQLite is also commonly pronounced as SQLite, so both pronunciations are acceptable.

97 50:17

MR. LALLY: Now, once you received the extraction, made a copy and then ran it through of those variety of tools, what is it that you specifically were looking at and what is it that you were trying to ascertain, or the question that you were trying to answer?

98 50:34

MS. HYDE: So in looking at that analysis, I was focused specifically on the data that took place on January 29. So the first thing I did was I limited my search within those tools to that period, and I looked at the artifacts that they were parsing pertaining to Safari history, as Safari was the browser that had been used at that time.

99 50:50

MR. LALLY: Now in addition to looking at those search, what if any information were you looking at in relation to deletions?

100 51:04

MS. HYDE: I'm sorry, I could not hear you.

101 51:06

MR. LALLY: In addition to looking at those materials as far as those searches were concerned, what, if anything else, were you looking at regarding that data with respect to deletion?

102 51:15

MS. HYDE: I didn't hear the last word. With respect to?

103 51:17

MR. LALLY: Deletion.

104 51:18

MS. HYDE: Deletion, I apologize. Thank you.

105 51:20

MR. LALLY: My fault. My fault.

106 51:21

MS. HYDE: Yeah. So one of the things that was asked was -- one of the things that was actually in the affidavit from Richard Green was that it was stated that there was belief that one of the search terms had been deleted. So I was specifically looking at that search term to see if what the reason was for the suspicion of deletion. There is -- the tools denote things based on how they are running as an automatic process. So tools are designed to parse through large amounts of data to make it easier. So the tools will often flag certain data as recovered, and sometimes there is confusion between what recovery and deletion means. That actually was the subject of the paper I referenced earlier that I co-authored. And the tools are sometimes misinterpreted that that statement of recovery means deletion. So I was exploring that.

107 52:26

MR. LALLY: Now, you mentioned specifically there were two searches of interest that you were exploring; is that correct?

108 52:33

MS. HYDE: That is correct?

109 52:34

MR. LALLY: And what were those two searches and what, if any, information did you have in relation to those?

110 52:39

MS. HYDE: I had the information from the two reports that had been written in terms of what they found and the two search terms, one was hos, H-O-S, long tit to die in cold. And the other one was, how long ti die in clkd.

111 52:59

MR. LALLY: And what if any information from your starting, if you could, walk the jury through as far as your analysis, what you first observed, and what your analysis consisted of as it evolved?

112 53:13

MS. HYDE: Absolutely. So when I first looked at it, some of the tools surfaced the data from a specific storage called the -- let me just make sure I get the entire path for you com.apple.mobile.Safariplist. It is very common in mobile devices for it to look like a reverse domain name. Like you normally would go to a site like cnn.com. Typically, those names are like the opposite. So com.apple is going to be representative of a native Apple application. So this particular P list was related to that. A P list is -- or called a property list -- is a data structure that's unique to Apple devices, and there is data pertaining to Google search -- not Google -- well, not just Google searches -- search history that's stored there. There's also, I found evidence of the search terms in knowledge CDB. The knowledge C database is an Apple database that is meant to store information about users so it can determine future functionality, what you're looking for, et cetera. So that's the knowledge CDB.

It's more of a system level artifact. And then there was also -- and these were the observed search terms, and most of the tools picked up both of those search terms in there. They're not all tools did pick up the one that was from the wall which was the instance of "Hos long to die in cold." That's how I'm pronouncing the H-O-S. If you would like me to clarify it a different way, that's fine. That particular search term was recovered from a SQLite database, the one I later explored. And Cellebrite, specifically demonstrated and showed that particular search term as a suspended state tab. And that's a really intricate artifact, whenever we're ready to explore that. That is the one that was marked as recovered. So those were my initial findings just looking at what the automated tools parsed. However, Cellebrite was the tool that found that particular search term.

113 55:34

MR. LALLY: Now, you used a term in there as far as a WAL or a write ahead log file; is that correct?

114 55:41

MS. HYDE: That is correct.

115 55:47

MR. LALLY: Can you please explain to the jury what your understanding of that term is based on your training and experience?

116 55:52

MS. HYDE: Absolutely. This is a really interesting data structure the way it works. So the way SQLite databases work is the data before being committed to the database, which is almost like an Excel spreadsheet if you think about that. Each table is like a page on an Excel spreadsheet. The data before going there goes kind of to almost like a text file, like, if you were to have a DOC of writing all the changes that need to happen to that Excel spreadsheet. And they're not made to that spreadsheet until it closes. So what happens is as you're doing things - either adding a website by searching for it or closing a tab or deleting a text message in a SQLite database in general, those things you add are written to that text document or things you delete. So they all hang out there together. So it's any changes that are going to be made since you started using that application until it's closed, then they change there, and then it reopens.

So to make an analogy, if you're in a restaurant and you order some food, the food being the data, and you at the table being the table that the data is going to, when you request that data and you say, I'm adding it, it goes to the area where the waiter or waitress, the server is going to grab it from, right, that warming station. That is almost like a write ahead log. And so different tables are ordering food, and food is constantly being put there. If somebody, maybe their steak came out rare and it needs to be cooked more, when they send it back, it'll also go to that warming area. So you can see there that you've got things waiting to go out to the tables and things being sent back to the kitchen. So simultaneously, that storage area contains both the newest stuff waiting to go out and the stuff coming back.

And that's really what a WAL file winds up containing - your newest Google searches, your newest text messages, et cetera, as well as anything that you've been deleted, that you've said was deleted because the reference in there is going to be delete this entry. And so then all of those don't happen until the application is closed and reopened. If the application's been closed, when we do the extraction, we actually don't get the WAL file. We only get the WAL file if at the time of extraction, that database had not been closed. So that just means that Safari, in this instance, was still running when the extraction was done. Most of you when you use your phones, you leave the applications up. So because of that, we have a WAL file, and so that WAL file is going to contain both the data that's been requested to be deleted and new data. Now when I say deleted in this instance, I don't mean like you as a user saying delete the full text message. What I mean when I say deleted in this issue -- this instance is removed from the database. So when we're talking about something like a Safari tab, deletion from the database can occur because you close the tab. We all open tabs when we use our browsers on our phone, and we all close them. And so closing in that instance would be a deletion in the database. But what that's doing is not a user requesting deletion. So I just want to be clear on that term.

117 59:06

MR. LALLY: And to that point, as far as so when you say something has been deleted specifically with reference to the write ahead log or the WAL file, that's not something that's necessarily initiated by the user; is that correct?

118 59:18

MS. HYDE: Correct. And I think that's a common misconception, yes.

119 59:22

MR. LALLY: Your Honor, just in regard to a side issue, may we approach just briefly?

120 59:26
sidebar Leading Questions and Report Tables
121

(Sidebar commences.)

122

JUDGE CANNONE: We are very hard at sidebars because we need to do the white noise which makes it very difficult for Madam Court Reporter to hear.

123

MR. LALLY: Understood.

124

JUDGE CANNONE: So keep your voice up, Mr. Lally.

125

MR. LALLY: I will. Your Honor, so what I was going to flag for the Court is Ms. Hyde within her report has a couple of different tables which I intended to use as chalks, but I just wanted to get the Court's permission before I asked it for them to be displayed on the screen.

127

MR. YANNETTI: I don't have a problem with that. But while we're at sidebar, Your Honor, I'm sensitive to Mr. Lally leading the witness. The last question was a leading question. I'm not inclined to object after every leading question and to prolong the process. I would just ask that he refrain from leading.

128

JUDGE CANNONE: Refrain from leading.

129

MR. YANNETTI: Thank you.

130

MR. LALLY: Yes, Your Honor.

131

end of sidebar.)

132 1:00:51

MR. LALLY: Now, Ms. Hyde, you had used the term earlier in your testimony regarding something within your field called an artifact; is that correct?

133 1:00:55

MS. HYDE: That's correct.

134 1:00:55

MR. LALLY: And can you explain to the jury what you understand that term to mean?

135 1:00:58

MS. HYDE: An artifact is any trace that's left behind by any action on a digital piece of data.

136 1:01:07

MR. LALLY: And can you give the jury an example of sort of when an artifact might be or an artifact might look like?

137 1:01:12

MS. HYDE: Absolutely. So an artifact of you sending a text message would be that we would find the database where text messages are stored, and inside that database, we would see the time and date that you sent it, who it received and who it was sent to. It might not be their name. It might be a numerical representation that we have to tie to another database. Then we would have the message itself. It may be in plain text, or it may be encrypted or encoded. And then we may have something called a blob, and that would be a reference to data that's too large to store in the database, so it would be elsewhere. So that would be if your text message included, let's say, a picture or a video.

138 1:01:56

MR. LALLY: Now, in regard to your analysis and your ultimate conclusions in this case, you wrote a report; is that correct?

139 1:02:02

MS. HYDE: That is correct.

140 1:02:03

MR. LALLY: And within that report, there are a couple of tables and a specific figure; is that correct?

141 1:02:08

MS. HYDE: That is correct.

142 1:02:09

MR. LALLY: Your Honor, with the Court's permission, if I could, I'd like to publish to the jury table one from Ms. Hyde's report.

143 1:02:20
144 1:02:27

MR. LALLY: Ms. Hyde, do you have a copy of your report with you as well?

145 1:02:30

MS. HYDE: I do.

146 1:02:32

MR. LALLY: Your Honor, with the Court's permission, just because I'm here and it may be a little difficult to see from where she's seated, if she could refer to the table and --

147 1:02:37
148 1:02:37

MS. HYDE: Thank you.

149 1:02:38

MR. LALLY: Ms. Hyde, what's up on the screen, and I'm sorry, there should be a laser pointer on the desk before you. Do you see that?

150 1:02:47

MS. HYDE: I do. Let me -- oh, yes.

151 1:02:49

MR. LALLY: So using that laser pointer, if you could, call the jury's attention or direct the jury's attention, I should say, with respect to what are we looking at in this specific case?

152 1:03:00

MS. HYDE: Absolutely. So this table here has a couple of different elements that I'm showing in terms of what searches were searched, where, when, and what source of data they came from. So if we look at this first search, I have them in the time stamp order that is associated with the artifact. I want to clarify that we need to discuss the meanings of these time stamps as we go. So this first one that you're going to see is - and I'm just going to reference my paper because of the size - is 2:27, 02:27 and 40 a.m. So that's two o'clock in the morning, twenty-seven minutes and forty seconds. And it is a search for the term: "-H-O-S long to die in cold," and that is time stamped, in this instance, is from the browser state DB, which is right here. The browser state DB is an artifact that speaks to when tabs are moved. So when you're using your browser and you open different tabs, you may have a search that this time pertains to the time that that tab moved. It could be lots of things.

It could be you switch tabs. It could be you close the tab. It could be you minimize the application, depending on the version of iOS, what can be that browser state of the tab that changes the time stamp differs. But what's very special to know about this time stamp is that that is not the time necessarily of this search. If a browser is opened and a single search is made, those will match. However, as long as that browser hasn't been closed, moved to the background, et cetera, if that browser has had any activity that happens to that tab in terms of application, closing, minimizing, this can update. That is what that time stamp is for. This search term is always going to be the most recent search term in that tab. That means the last item that was opened in that tab was H-O-S long T-I in cold. We cannot tell by this particular artifact what time that search occurred. It is a high likelihood that that tab was opened at this time because there was another search that occurred at 2:27 in the morning. It was a sports site. I cannot pronounce it. It began with an H. Honk -- hock --

153 1:05:30

MR. LALLY: Hockomock?

154 1:05:30

MS. HYDE: Hockomock. Okay. Thank you very much for the pronunciation. Hockomock Sports. There were a couple of searches pertaining to that done immediately after, but it appears that that's when this tab was opened and the first search done there. So this search, we know was done by this, and we know that it was the last search in the tab because it comes from this source, the browser state DB, and that means that particular time stamp and search pertains to what has happened with the tab. And that's what allows you to open your Safari browser on your iPhone and then open it on your iPad or your Mac and have the same tab. That's the function there. This search here. This is really interesting. So at 6:22:49 a.m., we have an entry in cache DB that is specifically if we dig into this URL, this is an Apple suggested term. So when you use a browser and you start to type a search you've never typed before, the browser tries to help you and say, "Are you searching for this?" So as the user began to type the phrase in the immediate search after which is, "How long T-I to die in C-K-L-D," this particular suggestion came up, indicating, in all likeliness, that the search term being typed had not previously been searched because Apple suggested, instead of a previous search, it suggested, how long does it take to digest food. After how long to digest food had been suggested, the user then has a search at that -- at that time 6:23:51 for, "How long T-I die in cold," and that is coming from the mobile Safari P list, com.apple.mobileSafari P list I mentioned earlier, and the search is also shown in the knowledge CDB. That's commonly what we would expect. We would expect that search to be in both of those -- both that P list and that database. Then the --

155 1:07:35

MR. LALLY: All right. Can I stop you there?

156 1:07:36

MS. HYDE: Yeah, absolutely.

157 1:07:37

MR. LALLY: As far as the expectation of that being in both of those, the P list and the other database, why is that?

158 1:07:45

MS. HYDE: That is because the search is not being tracked, not only by the P list for Safari, but also by the system itself to be able to do that predictive coding. So in the future, when you start to type how long it gives you what you searched last time.

159 1:07:59

MR. LALLY: And with respect to that, how long it takes to digest food, based on your analysis, was that a search term that was ever entered into this phone?

160 1:08:09

MS. HYDE: Correct. The source of that, if you look at the first in line where it says CDN2smooth.apple.com(ph), that's what indicates that this is an Apple suggested term, not a user input term.

161 1:08:24

MR. LALLY: I'm sorry. I interrupted you. If you could please continue with that.

162 1:08:27

MS. HYDE: Absolutely. The next search that was done immediately after the search at 6:23, the next search was "how long T-I die in C-L-K-D," Again, we see that search both in the knowledge CDB and the mobile Safari P list. And then we have, yeah, so we see it in both databases. Then -- so that's how long to die in cold. Sorry, I moved onto the next line. Then at 6:24, we get the next search, which is, "-H-O-S long to die in cold." And we have that search again both in the knowledge CDB and the P list. If I were time lining this based on activity, as opposed to time stamps associated, what I see here is the beginning of a user typing a search, Apple making a suggestion of how long to digest food. The user does not take that suggestion and rather inputs "how long T-I die in C-K-L-D." They then make a second search of "hos long to die in cold." that search winds up being the last search in the tab, and that is why we see it in the -- this particular browser state DB. It should be noted that this is in one of those WAL files and not the raw file.

163 1:09:47

MR. LALLY: And so as far as sort of toward the top there, I know we'll get a little more to this in a moment, but as far as that reading at 2:27:40 in the morning as far as the time stamp associated with the search, why would that time stamp be associated with it if it's search later on in the morning?

164 1:10:05

MS. HYDE: Because that table isn't showing the time of that search. It's showing the state of the database. So it's saying that the last time that tab was touched, moved to the background or foreground, was 2:27 a.m. The website, as you search more websites in the tab, that gets updated. So the current state that this is showing is that it was -- the tab was moved to the background or opened or some action for the tab at 2:27 a.m. when the Hockomock Sports -- I got it right. Hockomock Sports website was visited, and then once the Hockomock Sports website was visited, that tab was in continual use. There were other searches J|and activities that happens. We don't see that happens. Eventually, this search gets made at 6:23 a.m., this search at 6:24 a.m. That winds up being the last search in the tab, and because it's the last search in the tab, that's what the final update is and the final status.

165 1:11:04

MR. LALLY: So when you say last search in the tab in reference to time in reference to what time, specifically?

166 1:11:09

MS. HYDE: I'm sorry. I don't understand the question.

167 1:11:14

MR. LALLY: Bad question. Let me rephrase. So as far as the 27 tab is closed, and then another search done at 6:23; is that correct?

168 1:11:22

MS. HYDE: Two twenty-seven isn't necessarily one time when the tab was closed. That's -- in my report, I say that it's undetermined because there's a lot of things that can cause that time stamp to be there, including tab being moved, tab being minimized. I don't know exactly what caused the tab to get that particular entry, but it is not -- that time stamp is not indicative of the time of the search or any URL that's visited there. That time is indicative of movement of the tab and the search is the most recent search. So they update at different times.

169 1:11:56

MR. LALLY: So I guess my question is, as far as how much your analysis is here, is there any use of that tab between -- or is there any evidence or artifact of use of that tab between the 2:27 timestamp and the 6:23 time stamp.

170 1:12:13

MS. HYDE: So the fact that the time -- that that time stamp exists at 2:27 combined with the fact that the only existence of this search is at 6:24 means that, yes, that time that -- that particular tab was used after 2:27 when the Hockomock Sports was searched. I apologize for not being familiar with that name.

171 1:12:36

MR. LALLY: That's absolutely fine. Now, if I could ask you at this point if you would talk about one in particular database having sort of an intricate artifact.

172 1:12:50

MS. HYDE: Mm-hmm.

173 1:12:50

MR. LALLY: If you could remind the jury what that is, and if you could explain that.

174 1:12:56

MS. HYDE: So the artifact that needed a little bit more explanation and digging was this browser state tab, and that's because if you look at the end of a file name, you'll see it's a DB dash WAL. That means it wasn't in the regular database. It was in the write ahead log. And to Cellebrite's credit, they -- that tool actually parsed the write ahead log and displayed it where the other tools did not. If you remember before we talked about write ahead logs, and we talked about the fact that they can contain data that is both removed from a database and data that's not yet to be committed. And this database, we cannot -- we do not know which that is. But what I did was I manually went through, and that's in the figure, I manually went through and reconstructed the WAL files using the Sanderson SQLite tool. And in reconstructing the WAL files, I found many -- I'll tell you exactly how many if I can refer to my notes --

175 1:13:54
176 1:13:54

MS. HYDE: Can I refer to my notes? A Approximately 16 instances of that existing in the WAL file. Now, what's interesting in that figure is that the -- each entry of something in a write ahead log gets a unique identifier. So it gets a -- it gets a number, right, that makes it unique. Just like each one of us has a phone number that's unique to us, each entry in the database that starts in the write ahead log gets its own unique identifier. And that unique identifier in this instance in all 16 entries in the WAL file is the same, which shows that it's truly only one search, not multiple searches for that search term in terms of what exists in the WAL file. So that's -- that's the first piece of nuance there that it only truly was searched one. And you would -- you would have to really dig into that WAL file to expose that, but I think it was pertinent to know how many times this was searched.

177 1:15:01

MR. LALLY: I'm sorry.

178 1:15:01

MS. HYDE: Yes, please.

179 1:15:02

MR. LALLY: Let me stop you there for one moment.

180 1:15:05

MR. LALLY: And, Your Honor, with the Court's permission, if I could ask Ms. Gilman to publish table two now.

181 1:15:11
182 1:15:11

MS. HYDE: Oh, wonderful.

183 1:15:12

MS. HYDE: May I look at table two?

184 1:15:16
185 1:15:16

MS. HYDE: Thank you, Your Honor.

186 1:15:19

MR. LALLY: And Ms. Hyde, do you recognize what's up on screen?

187 1:15:22

MS. HYDE: I do. That is table two of my report on page four.

188 1:15:25

MR. LALLY: And if you could, again, using the laser pointer that you have before you, direct the jurors' attention to what, if anything, of significance is depicted in table two up on the screen.

189 1:15:28

MS. HYDE: So table two here is designed to share with us what each of the locations that can potentially have Safari data, what kind of data they hold. And one of the things that many of us are interested in sometimes is do these things hold our private searches, like, if we're in Incognito mode in Google or private searching here. So this table denotes if we're seeing private or nonprivate searches, if it includes tabs that are open or closed, so that we know which artifacts are giving us what kind of information, as well as what some of the associated time stamps mean. So this was designed as a guide to really understand table one more in depth. So this first one here. This refers to the history DB WAL file, and that file has nonprivate searches. It includes closed tabs and the visit time there is the time that a user reopened the tab. We don't always have the artifacts we want, and in this instance, we did not have that particular one. Then we have the Safari tab CB.

This has private tabs and nonprivate tabs and it only -- it shows only tabs that have not been closed. So this is an active tabs database. The next one we have is the browser state DB and its WAL file. And this is the one we were referencing where that -- that we keep talking about where that 2:27 a.m. number is coming from. So this one is going to be nonprivate searches. It includes closed tabs, which is important, and the last viewed time, so when an item went to the background. So it's about the tab, not about the search. That's probably the most important demarcation. And one of the issues here is when the tools parse the data, they call the columns what the columns are called raw in the data. Those don't necessarily tell us what they mean. We have to verify and validate what they actually mean. So when I'm saying last underscore view time, that's what the database name is, not necessarily the actual function or not what we would presume it to mean. The next one, the last one here, is the mobile Safari P list, and this one actually tells us the date here, gives us the time that something was queried, reliably.

190 1:18:08

MR. LALLY: Now, if I could ask you, if you could, just explain to the jury as far as these SQ or SQLite databases, how exactly do they work, and what if any relation do they have with regard to data and information with write ahead log or the WAL file.

191 1:18:31

MS. HYDE: So SQLite databases work and function as a storage for anything that the phone may need to reference later that you're doing. They're stored for a variety of things. Most of your third-party apps use SQLite databases and multiple applications do. So SQLite gets information in and it allows for that information to be updated, added to, or removed from. So data that's in that situation, that it's sitting in the database, that is what we refer to as live data. Then data that is waiting to be put into the database, that is sitting in the WAL or has been requested to be removed, that is what's in the write ahead log, and we call that nonlive data because it's not in the active database.

So when you're using an application and it's putting that data to that temporary storage area, that WAL, that write ahead log, what happens is, then when you request data by going into your contacts, let's say, and looking at the people who are stored in your contacts, right, your mom, your dad, your brother, your sister, all those people, when you're looking -- your best friend -- you're looking up their numbers, that data is all stored in that database. So when you add someone, it does that entry to the WAL. Now, so if I just added Sally, how do I know that Sally's in there, right? Well, what happens is the interpretation of the SQLite database goes to the wall, checks and sees if it's in the WAL, and uses the WAL to incorporate it together to present you everything as if it's in there. Then when you close the application, you close contacts, you don't just put it away, like go switch apps. You actually close it. When it closes, all of those changes get committed.

So now the items that you've requested to be deleted, that contact you don't like anymore, that X, whatever their data is no longer in there. The data that you've added is now in there, and now that's all live. Sometimes we can get more complex and recover some of those items that are left over because they are marked for deletion but still sit in the database, or they're sitting on a page that is no longer active in the database. So there's a lot of places that we can recover data from in addition to the WAL that exists in a database after something has happened. But that isn't pertinent to this particular use case.

192 1:20:55

MR. LALLY: Now, as far as that sort of interplay between the SQLite database and the WAL, what if any sort of -- asa forensic examiner, what if any sort of complexity provides?

193 1:21:08

MS. HYDE: Oh, one of the biggest complexities is the assumption that because data exists in a write ahead log, that a user took an action to delete it. When I teach at the university, when I peer review my colleagues' reports, this is one of the most common mistakes I see, and it's really because some of the forensics tools to indicate that the file has been recovered, they put a big X on it. And that was actually a big subject of that Standardization of File Recovery paper I referenced earlier, and it speaks about all kinds of files, but actually has a special section on SQLite, specifically because that nuance is often missed by examiners.

194 1:21:46

MR. LALLY: Now, in reference to that being marked as deleted or misinterpreted as deleted by a user, is there a specific tool of the tools that you mentioned before, as far as Cellebrite versus Axiom versus that has that information that others may not.

195 1:22:14

MS. HYDE: So Cellebrite and Magnet Axiom - both Cellebrite Physical Analyzer and Magnet Axiom both have file system viewers that then have SQLite database viewers. I would say that those SQLite database viewers have more of a basic function in terms of looking at data in the live database. They don't allow for deep analysis of the write ahead logs which is why in my analysis, I use the specialized Sanderson forensic browser for SQLite.

196 1:22:42

MR. LALLY: And so when you see something like that in a Cellebrite extraction, is there -- what if any further analysis do you do to sort of look behind?

197 1:22:51

MS. HYDE: Absolutely. Anytime I see an entry marked as recovered, and I'll use the term recovered instead of deleted, by Cellebrite and the source is the write ahead log, I would go and begin reconstruction of the write ahead logs using Sanderson's forensics tool to get the meat of is this something that has been deleted, or is this something that has yet to be written to the database. You can often see remnants of that based on how many unique entries there are of it, and you -- what the other thing we do is, so I mentioned that when we have the WAL file, it hasn't been applied. So if I take the SQLite database and the WAL file out, and I make another copy of them -- so I've got one copy I'm looking at Sanderson, and I take another copy, and I actually open it, what's cool is it does the commits. So then I have a copy of the database that actually has all those changes. So I now know if the entry was deleted by Just comparing the two. So I can do that analysis by basically making the database think it was reopened by reopening it with a nonforensics tool in that instance just to see what it would look like in real life, and then I can look at the difference between the two and determine if something was marked for deletion or addition.

198 1:24:05

MR. LALLY: Now, are there different reasons from your training, your experience, and your knowledge of these systems, is there different reasons for why it's your conclusion that that particular search or those search terms were not deleted by the user, specifically?

199 1:24:25

MS. HYDE: Yeah, well, there's a couple of reasons. First, the way tabs work from a functional perspective, you can close a tab, but there's not really a user deletion function for the tab, and there was no evidence of other deletion, if that makes sense. I also -- it doesn't make sense that the term was -- I don't see evidence that the term was searched prior to that 6:24 time. So since the term wasn't searched prior to that 0624 time, the existence of the tab being closed would not mean that that search was deleted because then it would be evident in the other databases pertaining to the actual search not the databases pertaining to the state of the tab. Is there a possibility that the tab was closed? Absolutely. But that is -- that is not a deletion. Secondly, an existence in the WAL file, as we mentioned, could be that it's something new, not something that was deleted. So just it's mere existence in the WAL file doesn't mean it's deleted. I should say that that same X in the tools, you have to check the file because it could be from a free list or a free page in which case - I know we didn't go into those details nuance of SQLite databases that actually doesn't pertain to this. However, those would be truly deleted items. So there's other places where we would expect potential recovery, not necessary in this instance, and you can have something that's in a WAL file and deleted without being in those other locations just stating that its existence in WAL file itself doesn't mean deletion. But there are other SQLite things that would clearly indicate deletions that aren't applicable to this particular search.

200 1:26:13

MR. LALLY: Now, Your Honor, with the Court's permission, if I could ask Ms. Gilman to publish show figure one from Ms. Hyde's report.

201 1:26:21
202 1:26:22

MS. HYDE: Ma'am, may I -- thank you, Your Honor.

203 1:26:24

MR. LALLY: And, again, Ms. Hyde, do you recognize what's up on the screen?

204 1:26:30

MS. HYDE: Yes, this is figure one. This is a direct screen capture from Sanderson's tool from the browser state DB limited to the "hos long to die in cold" search.

205 1:26:42

MR. LALLY: And if you could using that laser pointer, again, direct the jury's attention to what, if anything, of significance or of note that you observed in using the Sanderson tool that's depicted in figure one.

206 1:26:56

MS. HYDE: Absolutely. So all of the searches are the exact same term, and here we have the order index, and here we have that last viewed time. And by looking at the last view time, which is the raw title of that artifact for the time stamp we were looking at, these -- and these are identical. This -- and more importantly, there are actual UID for these are identical which is right here. Now the offsets are different. And what that means is that this is just appearing several times in the write ahead log. It has moved as the database has moved data through the write ahead log to different positions, but has in every instance the same unique identifier meaning that all of these entries are the same entry - just shown multiple times in the same database.

207 1:27:51

MR. LALLY: To that point, as far as the multiple times that it's listed within there, what if any relationship does that have to how many times it was actually searched by a user?

208 1:28:00

MS. HYDE: Well, that UID shows that in this particular instance that it existed once in the last time in the tab because this artifact does not tell us how many times something was searched by the user. This artifact is limited just to the tab. We would look at the mobile Safari P list which has one entry service time stamp or knowledge CDB, which also only has one entry for this search. Those is where -- those two locations are where we would determine how many times it had been searched as opposed to this location which could tell us that if there were multiple entries, but there is only one. But since this is laid(ph) -- limited to just the last search that's showing in a tab, it isn't a good source to say how many times was it searched, just not this particular artifact.

209 1:28:49

MR. LALLY: But from other artifacts -- from other artifacts, you were able to determine that?

210 1:28:53

MS. HYDE: Absolutely. You can determine that from both mobile Safari P list and knowledge CDB.

211 1:28:58

MR. LALLY: And I'm sorry. I jumped in there. And just bring your attention back to figure one. What if anything else of significance do you note in that in that?

212 1:29:07

MS. HYDE: That's really what's of significance is that it is the same entry there multiple times, and we can tell by the U -- unique identifier, that it is the exact same entry also, but -- and it's -- although it's the same search term and the same time stamp, it's only one instance of it, just it's stored in the database multiple times at multiple offsets.

213 1:29:29

MR. LALLY: Now, from the time stamps associated with that depicted in this figure, what, if anything, can you say as to the -- or what, if anything, were you able to conclude from your analysis as to the time that the website was viewed?

214 1:29:43

MS. HYDE: Well, I guess I should really clearly for people who may not be familiar, that doesn't look like a normal time, right? That's because this is an Apple WebKit time stamp. So we actually convert it to a regular time. So when you look at this number raw, you can actually see that it's consistent throughout, even though you don't know what it is. But if we put it into a decoder, this particular time stamp is where we're getting January 29, 2022 at 0247 a.m. And to be clear, just for real clarity, when we actually translate this time stamp, it's in universal time constant, not in local time. But for the sake of conversation, I'm using the local time here as opposed to the time in the universal time constant, which is how this artifact is particularly stored.

215 1:30:41

MR. LALLY: Now, with your analysis, is there some kind of testing that you conduct or can you explain to the jury sort of what that is and how it how it relates to your analysis here?

216 1:30:53

MS. HYDE: Absolutely. So with this artifact and being able to determine what this time stamp really means, I actually did quite a bit of testing, which is fun, but that's okay. So we went ahead and did -- took a jailbroken iPhone, and the purpose of a phone being jailbroken is we're bypassing the security protocol so we can monitor the data and its storage in real time and bring the data through. We did this both -- we did this manually in terms of pulling the data out, and we also did multiple forensic images at different stages. We manipulated tabs. We did some Google searches, and then we would close tabs, move tabs, and perform several different searches that we scripted out first what we were testing, and then check to see how that time stamp was moving. We even did some really interesting things where we tried --

217 1:31:45

MR. YANNETTI: Sorry, objection.

218 1:31:46

MS. HYDE: Yes.

219 1:31:47

MR. YANNETTI: Can we approach sidebar, please.

220 1:31:49
221 1:31:49

MR. YANNETTI: Sorry.

sidebar Foundation for Firm Work
222

(Sidebar commences.)

223

MR. YANNETTI: I am sorry to interrupt. My objection, Your Honor, is that she is speaking in terms of we did this, we did that. We don't have any report that anybody else worked on this. I have no information about who the “we” is, and I would object to her speaking about somebody else’s work because we weren’t provided notice of that.

224

JUDGE CANNONE: What do you say, Mr. Lally?

225

MR. LALLY: Whatever work was done, she’s the owner of the firm, so she supervised that work. I don't know that there are any other people involved in it. I can certainly ask that question.

226

MR. YANNETTI: I would just like her to speak to her own work. That's all.

227

JUDGE CANNONE: Go ahead and build a foundation.

228

MR. LALLY: Sure.

229

MR. YANNETTI: Thank you.

230

(end of sidebar.)

231 1:32:58

MR. LALLY: Ms. Hyde, I'm sorry.

232 1:33:00

MS. HYDE: It's okay.

233 1:33:00

MR. LALLY: So you had -- I think when you were talking about some of the testing that you had conducted, you used the term "we".

234 1:33:10

MS. HYDE: Oh, I --

235 1:33:10

MR. LALLY: So there are other individuals that worked on this particular assignment?

236 1:33:15

MS. HYDE: I had somebody peer review and test my testing. So they didn't -- they didn't work on the case, but as I was testing, one of my team members just validated that I would -- that I was following my test plan. That's just normal practice that we use peer review.

237 1:33:30

MR. LALLY: So the testing that you were testifying about is testing that you --

238 1:33:33

MS. HYDE: I conducted, correct, correct. But I had peer review by my team member on the script I had made to do my testing. So and I use the -- when I do testing, I'm following the NIST guidelines for data set generation and testing that's outlined by OSAC, which ironically, I should disclose, I'm a coauthor on.

239 1:33:56

MR. LALLY: And then if you could, I'm sorry, Ms. Hyde, just continue as far as your testing --

240 1:34:01

MS. HYDE: Absolutely. Yes, so then populated the device and looked at all of the different data that came back from the different states while it was jailbroken and the changes that happened. What I was saying was interesting is then tied it to a Mac and saw how the browser state changed if we change the browser and the tab on a Mac and how that would affect it, and because we could see the differences. And by we, I mean that my -- I had my testing peer reviewed, because I could see the differences of what the data looked like when I was altering it both in the Mac and on the phone, I was getting differences in those time stamps and those different conditions. So in other words, I could get a time stamp that showed in the browser state DB That was earlier than the current search by a variety of means, including manipulating the tabs, closing them, opening them, switching which one was in proper view forward, as well as looking at that tab on an external device, including a Mac and an iPad on the same account.

241 1:35:12

MR. LALLY: Now, throughout the course of your work, I think you alluded to it earlier in your testimony as far as your experience is concerned, you had occasion to work both as a forensic -- excuse me -- forensic extractions -- forensic investigator, I'm sorry.

242 1:35:27

MS. HYDE: Yes.

243 1:35:28

MR. LALLY: As well as working also in research and development; is that correct?

244 1:35:33

MS. HYDE: Correct.

245 1:35:33

MR. LALLY: And so from the R and D side, what if any role does that play as far as your analysis in general terms and your analysis here when it came to some of the devices or some of the tools that you were implementing?

246 1:35:46

MS. HYDE: I believe that my experience in research, development, and reverse engineering throughout my career pertaining to artifacts, of course, influences and my analysis processes in terms of wanting to ensure I understand how things work. I think it actually gives me a better understanding in many ways of how data moves through devices as well as how understanding why the tools parse and represent data the way they do in terms of the fact that they are using the -- they are presenting the data as they parse it using the proper algorithms to dissect that data and determine what it is based on testing and knowledge. So I think it actually influences in a positive way the depth that I go through in my analysis.

247 1:36:44

MR. LALLY: Now, you had mentioned earlier in your testimony that you had reviewed both Trooper Guarino's report as well as an affidavit from Mr. Green; is that correct?

248 1:36:52

MS. HYDE: Correct.

249 1:36:52

MR. LALLY: And with regard to the affidavit from Mr. Green, what if any issues, of course, of significance did you observe in his analysis?

250 1:37:01

MS. HYDE: In Mr. Green's analysis, there is a conclusion that is drawn that a search occurred at 0247 a.m. on January 29, based on the artifact recovered from browser state DB that Cellebrite parsed out. And there are two errors with that? The assumption that that is the time of the search is a misunderstanding of the browser state DB artifact because that artifact is not the time of search. It's the time of movement at the tab as well as the statement that -- that it was deleted due to the demarcation of Cellebrite as recovered.

251 1:37:46

MR. LALLY: And based on the totality of your analysis or testing and everything that you looked at in this case, what if any conclusions did you come to?

252 1:37:56

MS. HYDE: My conclusion is that there was a search at 0247 a.m. for Hockomock Sports, that that browser was in use, and there were continual searches due through the night. The phone was, I do agree with Mr. Green's findings, that the phone was in use at that time at 0227. Later, the phone is a web search is done at 6:23 a.m. for how long. At that moment, Apple produces a suggestion for how long to digest food. The search is instead completed with "how long T-I die and C-K-L-D," at 6:23. A new search is conducted at 6:24 of "hos long to die in cold." "Hos long to die in cold?" That search is then the last search that is made in that particular tab, and that's my conclusion.

253 1:38:46

MR. LALLY: What if any conclusion did you come to it in regard to items being deleted pertaining to those artifacts you were looking at?

254 1:38:54

MS. HYDE: In regards to those artifacts pertaining to those search terms, I had no evidence of deletion.

255 1:38:59

MR. LALLY: May I have a moment, Your Honor?

256 1:39:00
257 1:39:01

MR. LALLY: Your Honor, may we approach?

258 1:39:03
sidebar Proposed Tables as Exhibits
259

(Sidebar commences.)

260

MR. LALLY: Your Honor, I’m sorry. I was just going to seek the Court’s permission. Initially I was just going to use the tables and the figures as chalks. I think my inclination now would be to attempt to introduce them as exhibits. I don’t have printed versions right this second. But I can certainly print them at the break, and I would offer them as exhibits.

261

MR. YANNETTI: May I have a moment, Judge?

263

(Defense counsel confer.)

264

MR. YANNETTI: We won’t object.

265

JUDGE CANNONE: All right. [REDACTED] We’ll take fifteen minutes. How long do you think you’ll be on cross?

266

MR. YANNETTI: I’m not going to be lengthy. Fifteen minutes or so.

268

MR. JACKSON: While we are up here, would it be -- should I go ahead and call off the doctor for this afternoon?

269

JUDGE CANNONE: You’ve got your -- who’s your next witness?

270

MR. LALLY: Trooper Paul.

273

(end of sidebar.)

274 2:14:05

JUDGE CANNONE: Mr. Lally.

275 2:14:07

MR. LALLY: Yes, Your Honor, the Commonwealth would seek to introduce and admit as the next three exhibits, table one, table two and figure one from Ms. Hyde's report.

276 2:14:14

JUDGE CANNONE: Okay. There's no objection, Mr. Yanetti.

277 2:14:17

MR. YANNETTI: There is no objection, Your Honor.

278

(Whereupon Exhibit No. 580, Table 1 - Web History Tool Results Combined, was marked as an exhibit.)

279

(Whereupon Exhibit No. 581, Figure 1 - Instances of Google Search, was marked as an exhibit.)

280 2:14:24

MR. LALLY: Just table one, table two. I think the order I gave them. Thank you. And thank you, Your Honor. And thank you very much, ma'am. I have no further questions, Your Honor.

281 2:14:40

JUDGE CANNONE: All right. Mr. Yannetti.

282 2:14:41

MR. YANNETTI: Thank you very much, Your Honor.

283

CROSS-EXAMINATION BY MR. YANNETTI:

284 2:14:42

MR. YANNETTI: Good afternoon, Ms. Hyde.

285 2:14:46

MS. HYDE: Good afternoon, sir.

286 2:14:49

MR. YANNETTI: Ms. Hyde, you just spent maybe 45 minutes to an hour, whatever the time period was, explaining to these jurors, what is really a complex set of facts that led you to conclude that the 2:27 a.m. timestamp on that Google search was triggered by the closing of a tab. Did I essentially sum that up correctly?

287 2:15:15

MS. HYDE: Essentially, except it's not 2:27 a.m. timestamp on a Google search. It's a 2:27 a.m. timestamp on a tab.

288 2:15:22

MR. YANNETTI: Fair enough. Thank you. And in the context, or in the course of your explanation, you discuss WAL files?

289 2:15:30

MS. HYDE: That is correct.

290 2:15:32

MR. YANNETTI: SQ like database?

291 2:15:33

MS. HYDE: Yes.

292 2:15:34

MR. YANNETTI: PLIS database?

293 2:15:35

MS. HYDE: Yes.

294 2:15:36

MR. YANNETTI: Knowledge C database.

295 2:15:37

MS. HYDE: Yeah, PLIS is not a database. Just it's a structure. So just a small correction.

296 2:15:42

MR. YANNETTI: Thank you for the correction. Opening tabs and closing tabs, correct?

297 2:15:47

MS. HYDE: Yes.

298 2:15:47

MR. YANNETTI: And other issues related to your analysis of the phone extraction, correct?

299 2:15:53

MS. HYDE: Would you call them issues as that were --

300 2:15:55

MR. YANNETTI: Well, maybe that's a bad word to use. Other elements.

301 2:16:01

MS. HYDE: Elements, fair. Fair enough, yes. Yes.

302 2:16:02

MR. YANNETTI: I'm really not trying to trick you. I know I wouldn't be able to. Would you agree with me that another simple explanation for that 2:27 a.m. timestamp was that the user of that iPhone, conducted that search at or before 2:27 a.m.?

303 2:16:25

MS. HYDE: Can you rephrase, please?

304 2:16:29

MR. YANNETTI: I'm going to phrase it the same way and hope I don't --

305 2:16:31

MS. HYDE: Repeat it. Repeat it, please.

306 2:16:32

MR. YANNETTI: Sure. Thank you. Would you agree with me that another simple explanation for that 2:27 a.m. timestamp, was that the user of that iPhone conducted that search at or before 2:27 a.m. on January 29th of 2022?

307 2:16:52

MS. HYDE: That timestamp is not indicative of a time of search. So the question is difficult to answer, because I can't say that that timestamp tells me anything about the time of search.

308 2:17:04

MR. YANNETTI: So you're -- as I take your answer --

309 2:17:10

MS. HYDE: Mm-hmm.

310 2:17:11

MR. YANNETTI: -- you're not denying that the timestamp, and whatever you get from that timestamp, doesn't rule out that the Google search was done at or before 2:27 a.m., correct?

311 2:17:27

MS. HYDE: If I'm understanding your question, there was a double negative so I just want to clarify. The question is if the timestamp could exist because of a search happening at that time?

312 2:17:40
313 2:17:40

MS. HYDE: Okay.

314 2:17:41

MR. YANNETTI: What I'm saying is your analysis of the phone does not rule out that the user of that phone performed that Google search at or before 2:27 a.m.?

315 2:17:51

MS. HYDE: There is no indication of a Google search at or before 2:27 a.m.

316 2:17:57

MR. YANNETTI: But again, I'm getting to whether you can rule that out, ma'am. That's really the crux of my question. Can you rule out that the user of that phone conducted that search at or before 2:27 a.m. on January 29?

317 2:18:13

MS. HYDE: There is a very unlikely possibility based on the fact that there is no evidence that the search occurred before that time. That's just like saying that the user searched for pandas at 2:27 a.m., could you rule that out? I can't rule out something that doesn't exist.

318 2:18:28

MR. YANNETTI: All right. Well, you would agree with me that with regard to your analysis, this phone extraction --

319 2:18:34

MS. HYDE: Mm-hmm.

320 2:18:35

MR. YANNETTI: -- you were given very specific instructions in terms of what to look at, correct?

321 2:18:44

MS. HYDE: Correct. I had a very limited scope in this analysis.

322 2:18:46

MR. YANNETTI: And who was it that gave you that limited scope?

323 2:18:50

MS. HYDE: That scope was relayed to me by Detective Tully.

324 2:18:53

MR. YANNETTI: Okay. And Detective Tully instructed you specifically to only look at the part of the phone extraction that dealt with the Safari search history?

325 2:19:04

MS. HYDE: Safari's history, search history, specific to January 29, 2022, that is correct.

326 2:19:10

MR. YANNETTI: And he instructed you not to look at anything else on the phone, correct?

327 2:19:14

MS. HYDE: I looked at related artifacts such as the -- such as what was being done at that time, the phone being on, the phone being used, but not anything else outside of that, correct.

328 2:19:26

MR. YANNETTI: And you were not instructed, for instance, to look at other user activity on the phone including examining call logs on the phone, correct?

329 2:19:36

MS. HYDE: Correct.

330 2:19:37

MR. YANNETTI: And you would agree with me that if you were allowed or instructed to examine the call logs, that could reveal deletion of calls that morning, correct?

331 2:19:51

MS. HYDE: Of course.

332 2:19:51

MR. LALLY: Objection.

333 2:19:52

JUDGE CANNONE: Okay. The objection is sustained.

334 2:19:55

MR. YANNETTI: Thank you, ma'am.

335 2:19:57

JUDGE CANNONE: Any follow-up, Mr. Lally.

336 2:19:59

MR. LALLY: No, Your Honor. No redirect.

337 2:20:01

JUDGE CANNONE: Ms. Hyde, you are all set.

338 2:20:04

MS. HYDE: Thank you very much.

339

(End of requested testimony.)

Continue to next page Joseph Paul — Direct (Part 1)