Curious Case of Alice&Bob: What You Can Do as Digital Investigators

Catherine Ullman

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In "Curious Case of Alice&Bob: What You Can Do as Digital Investigators," Catherine Ullman, known as Investigator Chick, delivered a compelling and foundational talk at DEF CON 32, demystifying the intricate world of digital forensics. The presentation served as an essential guide for both newcomers and experienced professionals, emphasizing the critical thinking and methodical process behind successful digital investigations. Ullman's unique approach involved a dual role as speaker and narrator, weaving a fictional crime scenario around "Alice Aski" and "Bob Byte" to illustrate each stage of the investigative journey.

Watch on YouTube

Visual summary for Curious Case of Alice&Bob: What You Can Do as Digital Investigators by Catherine Ullman
Visual summary for Curious Case of Alice&Bob: What You Can Do as Digital Investigators by Catherine Ullman

Key moments

  1. 0:00 Welcome to Defcon and Creator Stage
  2. 1:30 Introduction of speaker Dr. Catherine Ullman
  3. 2:00 Overview of the talk's investigative process topics
  4. 3:00 Speaker's background: Investigator Chick and sloths
  5. 3:55 Defining forensic science and Locard's Principle

Curious Case of Alice&Bob: What You Can Do as Digital Investigators

Speakers: Catherine Ullman

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=sp91zygVcmE

Overview

In "Curious Case of Alice&Bob: What You Can Do as Digital Investigators," Catherine Ullman, known as Investigator Chick, delivered a compelling and foundational talk at DEF CON 32, demystifying the intricate world of digital forensics. The presentation served as an essential guide for both newcomers and experienced professionals, emphasizing the critical thinking and methodical process behind successful digital investigations. Ullman's unique approach involved a dual role as speaker and narrator, weaving a fictional crime scenario around "Alice Aski" and "Bob Byte" to illustrate each stage of the investigative journey.

The talk meticulously breaks down the digital forensic process into distinct, yet often non-linear, phases: scoping, data gathering, data analysis, data correlation, timeline analysis, and post-incident procedures. Ullman highlights the crucial distinction between traditional and digital forensics, underscoring the non-destructive nature required for digital evidence. Beyond technical tools, the core message revolves around the investigator's mindset, the importance of asking the right questions, and the inherent limitations of what digital evidence can definitively prove.

This presentation is highly relevant for anyone involved in incident response, law enforcement, corporate security, or even general cybersecurity, as it provides a structured framework for approaching complex digital incidents. By detailing the methodological rigor and scientific principles involved, Ullman empowers attendees to conduct more effective and forensically sound investigations, ultimately contributing to better security outcomes and more accurate conclusions in both criminal and civil contexts.

Background

▶ Watch: Welcome to Defcon and Creator Stage (0:00)

The foundation of any forensic science, including its digital counterpart, lies in the application of scientific principles to legal matters, whether criminal or civil. Catherine Ullman introduces the seminal figure in this field, Edmond Locard, a French criminologist whose work on dactylography (the study of fingerprints) laid much of the groundwork for modern forensic investigation. Locard's most famous contribution is his Exchange Principle, often summarized as "every contact leaves a trace." This principle posits that when two objects come into contact, there is an exchange of material between them. In traditional forensics, this might manifest as hair, fibers, or fingerprints left at a crime scene.

For digital forensics, Locard's principle translates directly to digital logs and artifacts. Every interaction with a digital system – a login, a file access, a network connection, an email sent – leaves a trace. These traces are the digital evidence that investigators seek to uncover and analyze. Unlike traditional forensics, where evidence collection might inherently alter or destroy the original sample (e.g., DNA analysis or fingerprint lifting), digital forensics operates under a strict mandate to preserve the original evidence without modification. This is a critical distinction, as digital evidence is expected to remain pristine.

To uphold this principle of non-alteration, two key concepts are paramount: chain of custody and the use of write blockers. The chain of custody is a meticulously documented process that tracks the handling and possession of evidence from the moment it is collected until it is presented in court. A clear, unbroken chain of custody ensures the authenticity and integrity of the evidence, preventing any claims of tampering or alteration. Investigators use specialized property evidence forms to record every transfer of evidence.

Write blockers are essential tools designed to prevent any data from being written to or modified on a suspect's storage device during the acquisition process. These can be physical hardware devices, such as the one pictured in the talk, where a suspect drive is connected, and the write blocker ensures that only read operations are possible. Software-based write blockers also exist, but hardware solutions are often considered the gold standard due to their robust and verifiable protection. By using write blockers, digital investigators can create a forensic image – an exact, bit-for-bit copy of the original drive – without altering the original evidence, thereby preserving its integrity for analysis and legal proceedings.

Key Findings

▶ Watch: Introduction of speaker Dr. Catherine Ullman (1:30)

The core contribution of Catherine Ullman's talk is the elucidation of a structured yet adaptable digital investigative process. She outlines six critical, often iterative, steps that guide a forensic investigator from the initial alert to post-incident actions. These steps are: scoping, data gathering, data analysis, data correlation, timeline analysis, and post-incident procedures. Ullman stresses that this process is rarely linear; investigators frequently revisit earlier stages as new information emerges, highlighting the dynamic and fluid nature of real-world investigations.

A significant finding emphasized in the talk is the critical importance of proper objective setting at the outset of an investigation. Ullman demonstrates how poorly framed initial questions, such as "Did Alice kill Bob?" or "Why did Alice kill Bob?", are inherently problematic for digital forensics. Digital evidence can reveal what happened on a system, when it happened, and who interacted with the system, but it generally cannot definitively assign "hands behind keyboard" or ascertain motive and intent. This understanding is crucial for managing expectations and ensuring that forensic efforts are directed toward achievable goals.

Consequently, Ullman advocates for revising broad, open-ended objectives into specific, forensically answerable questions. For example, instead of asking why someone did something, a better question would be "Was there any activity on the devices around the time of death?" or "Is there evidence to indicate involvement?" This shift from subjective intent to observable digital artifacts ensures that the investigation remains grounded in scientific evidence and avoids premature assumptions. The talk implicitly suggests that a successful digital investigation is not just about technical prowess but also about a deep understanding of the scientific method, the limitations of the evidence, and the ability to adapt to evolving information.

Technical Deep Dive

▶ Watch: Overview of the talk's investigative process topics (2:00)

The technical deep dive into digital investigations begins with the crucial scoping call, which sets the stage for the entire process. The goals of this initial phase are multifaceted: to obtain a comprehensive summary of the incident, gather details about involved individuals, establish key event timestamps, collect other incident-related details, and, most importantly, define the specific objectives for the forensic team. Ullman illustrates this with a narrative involving Detective Olivia Hart, a homicide victim named Bob Byte, and a primary suspect, Alice Aski.

In the "Curious Case of Alice&Bob," the initial information provided to the forensic investigator is that Bob Byte was found deceased at 456 Central Avenue at 12:01 AM on February 13, 2022, with an estimated time of death three hours prior. He appeared to have been stabbed. Alice Aski, living at 123 Main Street, is known to have an existing relationship with Bob and is the primary suspect. The police initially tasked the forensic team with two objectives: "What evidence exists that proves Alice killed Bob?" and "Why did Alice kill Bob?"

Ullman critically dissects these initial objectives, identifying them as problematic for digital forensics. She explains that forensics cannot definitively answer "why" someone committed an act, nor can it always prove "who" was physically "behind the keyboard." Such open-ended questions often stem from incorrect assumptions (e.g., "Alice killed Bob" is an assumption, not a fact at the outset), unrealistic timeframes, or incomplete requests. Digital forensics is about uncovering what happened on a system, not about determining intent or directly linking a person's physical actions to digital artifacts in all cases.

As a result, the objectives are revised to align with what digital forensics can realistically achieve:

  1. Was there any activity on the devices around the time of death?
  2. Is there evidence to indicate involvement (rather than definitive proof of guilt)?
  3. Examine all relevant digital communication between Alice and Bob.

Following scoping, the data gathering phase commences. In the Alice & Bob scenario, the forensic team immediately springs into action at Bob's residence. One technician begins creating a forensic image of Bob's laptop, ensuring a bit-for-bit copy is made without altering the original. Simultaneously, another technician meticulously documents every step of the acquisition process to maintain evidence integrity. Detective Hart identifies Bob's smartphone, which is carefully bagged for further analysis. Concurrently, other police officers visit Alice Aski, encouraging her cooperation. Alice provides her laptop and smartphone, along with passwords, for examination. This comprehensive collection of devices from both the victim and the suspect forms the raw material for the subsequent analytical stages.

While the provided transcript concludes after the data gathering phase of the Alice & Bob narrative, Ullman's agenda implies a continuation through the remaining investigative steps, which would generally involve:

  • Data Analysis: This phase involves examining the acquired forensic images and data for relevant artifacts. Tools like Autopsy, FTK Imager, or EnCase would be used to parse file systems, extract metadata, recover deleted files, and analyze system logs. Investigators would look for specific keywords, file types, or activity patterns related to the incident. For Alice and Bob, this would include analyzing browser history, email exchanges, chat logs, document access times, and system event logs for any activity around Bob's estimated time of death.
  • Data Correlation: Once individual pieces of data are analyzed, they need to be correlated across multiple sources to build a coherent picture. For instance, a login event on Bob's laptop might correlate with a network connection from Alice's IP address, or a specific message on Alice's phone might correlate with a file modification timestamp on Bob's device. This step often involves using tools that can ingest data from various sources (e.g., SIEM systems or specialized forensic platforms) to identify relationships and inconsistencies.
  • Timeline Analysis: This critical step involves organizing all relevant events chronologically. Forensic tools like Plaso/Log2Timeline or custom scripts are used to create a unified timeline of activities from all collected devices and network logs. This allows investigators to reconstruct the sequence of events leading up to, during, and after the incident. For Alice and Bob, this would mean mapping out their digital interactions, device usage, and network activity to pinpoint specific actions around Bob's death. The goal is to identify anomalous activities or confirm/refute alibis.
  • Post-Incident Procedures: The final phase involves documenting findings in a comprehensive report, presenting evidence in a clear and understandable manner, and often testifying as an expert witness. It also includes lessons learned, where the incident is reviewed to identify vulnerabilities, improve security controls, and refine incident response processes to prevent similar occurrences in the future.

The emphasis throughout these stages is on maintaining forensic soundness, meticulous documentation, and an objective, scientific approach to evidence interpretation.

Demo / Proof of Concept

▶ Watch: Speaker's background: Investigator Chick and sloths (3:00)

Catherine Ullman's talk effectively utilized a narrative-driven demonstration to illustrate the digital investigative process, rather than a live technical demo of specific tools. This approach centered around the fictional "Curious Case of Alice&Bob," featuring Detective Olivia Hart, the victim Bob Byte, and the suspect Alice Aski. The story was woven throughout the initial stages of the talk, allowing the audience to apply the theoretical concepts of forensic investigation to a tangible, albeit simulated, scenario.

The narrative began with the discovery of Bob Byte's body and the initial police assumptions about Alice Aski's involvement. This setup immediately highlighted the challenges of scoping, as the initial police objectives ("prove Alice killed Bob," "why did Alice kill Bob?") were presented as problematic. Ullman used this example to demonstrate how a skilled digital investigator would refine these broad, subjective questions into specific, forensically answerable inquiries, such as "Was there any activity on devices around the time of death?" or "Is there evidence to indicate involvement?"

The story continued into the data gathering phase, describing the actions of the forensic team at Bob's house. This included the process of creating a forensic image of Bob's laptop, the mechanical documentation of every step, and the careful bagging of his smartphone. The narrative then extended to Alice Aski's residence, where police secured her cooperation to obtain her laptop and smartphone, along with their passwords. This narrative served as a clear, step-by-step illustration of how evidence is identified, collected, and preserved in a forensically sound manner, emphasizing the critical importance of chain of custody and the non-destructive nature of digital evidence acquisition.

By using this fictional case, Ullman provided a relatable and engaging context for attendees, allowing them to follow the investigative journey from initial alert to evidence collection. This narrative acted as a practical proof of concept for the methodological rigor required in digital forensics, demonstrating how the theoretical steps translate into real-world actions without getting bogged down in tool-specific details, aligning with her stated goal of focusing on process and mindset.

Defensive Implications

▶ Watch: Defining forensic science and Locard's Principle (3:55)

Understanding the digital investigative process, as outlined by Catherine Ullman, offers significant defensive implications for organizations and individuals. By grasping how forensic investigators collect, analyze, and correlate data, defenders can proactively strengthen their security posture and improve their incident response capabilities.

Firstly, the emphasis on Locard's Exchange Principle in the digital realm highlights the critical need for robust logging and monitoring. If "every contact leaves a trace," then organizations must ensure that their systems are configured to capture these traces effectively. This includes comprehensive logging for operating systems, applications, network devices, and cloud services. Detailed logs, with accurate timestamps, are the bedrock of any digital investigation. Without them, even the most skilled investigator will struggle to reconstruct events, making it difficult to identify the root cause of an incident or determine the extent of compromise.

Secondly, the discussion around chain of custody and write blockers underscores the importance of incident response planning and preparedness. Organizations should have clear procedures for how to handle compromised systems or devices. This includes training staff on proper evidence preservation techniques, such as isolating affected systems, preventing further data modification, and documenting every action taken. Having pre-approved forensic tools and processes in place, like hardware write blockers and imaging software, can significantly reduce the risk of evidence spoilage during a live incident.

Thirdly, the focus on scoping and objective setting provides a valuable lesson for incident response teams. When an incident occurs, initial reports can often be vague or based on assumptions. Defenders should resist the urge to jump to conclusions and instead work to define clear, forensically answerable questions. This means moving beyond "who did it?" or "why did it happen?" to focus on "what happened?", "when did it happen?", and "how did it happen?". By framing investigations with precise objectives, teams can avoid wasted effort, manage expectations, and arrive at more accurate and defensible conclusions.

Finally, the iterative nature of the investigative process – moving back and forth between data gathering, analysis, and correlation – implies that flexibility and continuous learning are crucial. Defensive teams should regularly review past incidents, analyze their response, and update their playbooks. This continuous feedback loop, combined with an understanding of the types of digital evidence that can be recovered (e.g., communication logs, file access metadata, network traffic), allows organizations to implement better security controls, improve data retention policies, and enhance their ability to detect, respond to, and recover from cyberattacks.

Key Takeaways

  • Digital Forensics is a Scientific Process: It applies scientific methods to digital evidence for criminal, civil, or corporate investigations, aiming for objective and verifiable conclusions.
  • Locard's Exchange Principle Applies Digitally: Every digital interaction leaves a trace, typically in the form of logs and artifacts, which are crucial for investigations.
  • Preservation is Paramount: Unlike traditional forensics, digital evidence must remain pristine and unaltered. This necessitates strict chain of custody and the use of write blockers during acquisition.
  • Structured, Non-Linear Process: Effective investigations follow steps (scoping, data gathering, analysis, correlation, timeline, post-incident) but often iterate and revisit earlier stages as new information surfaces.
  • Define Forensically Answerable Objectives: Initial, open-ended questions (e.g., "why did it happen?") are problematic. Objectives must be refined to focus on what digital evidence can actually reveal (e.g., "what activity occurred around the time of death?").
  • Mindset Over Tools: While tools are important, a deep understanding of the investigative process, critical thinking, and a scientific mindset are more crucial for successful digital investigations.

About the Speaker(s)

Catherine Ullman, known by her handle Investigator Chick (or Investigator Chiff on platforms like Twitter/X due to character limits), is a highly experienced and respected figure in the digital forensics community. She has dedicated over 24 years to the University of Buffalo, where she has built and managed forensic compliance programs. Ullman is a familiar face at numerous security conferences, including being on staff at the Packet Hacking Village at DEF CON, and volunteers for many other events. Her career path into digital investigations was serendipitous, stemming from a need for a new career in the mid-90s after working in the record industry, and being drawn to tech by a friend's work with worms and infections. She furthered her expertise through SANS training, ultimately developing and leading the forensic compliance program at her university. Beyond her professional accomplishments, she is an avid sloth enthusiast, having adopted a sloth named Flash.

All talks from DEF CON 32 Creator Stage