We have been training attorneys on digital forensics for more than two decades. Military trial defense counsel. Federal and state public defenders. Criminal defense attorneys and civil trial lawyers. Narcotics investigators. Paralegals and legal investigators. Law students. The topics change as the technology changes. The core problem stays the same — attorneys are making decisions about digital evidence without understanding what that evidence actually shows.
We close that gap.
If your bar association, practice group, public defender office, or firm wants a CLE presentation on any digital forensics topic, contact us. We come to you, we tailor the content to your practice area, and we leave attorneys better equipped to handle digital evidence in their cases.
Who we have trained
Our examiners have presented at the Naval Justice School, the U.S. Army Trial Defense Service annual conferences, military Trial Defense Service regional conferences, the Kentucky Department of Public Advocacy annual conference, the Kentucky Association of Criminal Defense Lawyers, the Southwest Ohio Trial Lawyers Association, the Kentucky Narcotics Officers’ Association, the Military Law Symposium in Wiesbaden Germany, the National Association of Legal Investigators, Salmon P. Chase College of Law, and dozens of smaller group sessions for individual firms and public defender offices.
What attorneys learn that they did not know before
The most consistent finding after any training session is that attorneys did not know there were two entirely different categories of what a digital forensic examination sees. A basic analysis of a phone — the kind an attorney can conduct by scrolling through a Cellebrite Reader report — shows calendar entries, call logs, text messages, contacts, and browser history. That is a fraction of what the device contains.
A forensic examination reaches the data the attorney does not see. The iPhone Health database, recording step counts, heart rate, and location with timestamps. KnowledgeC and related iOS activity artifacts may record app activity, duration, and device state. When present and properly interpreted, those artifacts can support or challenge an inference that a device was being used at a particular time. Biometric and usage data that establishes a pattern of life independent of anything the user communicated. Deleted content within the underlying databases that the user believed was gone.
When we show attorneys what is in those databases versus what they were looking at in the report, the reaction is always the same. They start thinking about every case they tried without knowing this data existed.
The location data problem
One of the highest-impact topics in our training is location data reliability — and specifically the gap between what the government presents and what the data actually supports.
Forensic tools display all location data the same way. A GPS coordinate accurate to ten meters and a cell tower estimate accurate to 2.5 miles look identical on the map the government puts in front of a jury. The tool does not label one reliable and the other noise. An attorney who does not know to ask for the horizontal accuracy value of each data point cannot challenge the map.
We walk through this in concrete terms. In a murder case we worked, the government’s location presentation showed the defendant’s phone near the scene. Filtering the same data by horizontal accuracy — retaining only GPS fixes with an accuracy of 50 meters or less, and discarding the cell tower noise that dominated the map — produced a completely different picture. The data that the government presented as placing the phone near the scene was not GPS data. It was cell tower data. The actual GPS record told a different story.
Attorneys who attend our training know how to ask that question. Attorneys who do not attend our training do not know the question exists.
iOS and Android both allow users to edit photo timestamps and GPS coordinates since iOS 15 and Android 12 respectively. We cover this. We show what modified photo metadata looks like and what it does not look like. Photo evidence that was never challenged before becomes challengeable.
Screenshots are not evidence
This is one of the single most actionable topics we cover, and it applies across criminal defense, civil litigation, and family law.
A screenshot of a text conversation is a picture of what someone chose to show you. It is not the conversation. Free applications exist that generate convincing fake message screenshots in seconds. More commonly, screenshots presented as evidence in court contain gaps — missing messages in a time window where the actual database would show a continuous thread. The row ID numbering in the underlying database is sequential. A gap in the row IDs tells you a message existed and was deleted — like a deleted file, gone to the user, still there to anyone who knows where to look. A screenshot cannot show you that gap. The database can.
We have presented this material to public defender offices who then used it immediately in pending cases. Attorneys who understand the difference between a screenshot and a database entry know how to challenge evidence that most attorneys accept at face value.
The database is the source of truth. If it did not come from the database, question it.
“Missing” app data is not always missing
Forensic tools support decoding for more than 378,000 applications, but app updates and operating system changes regularly break parsing. When a tool cannot decode an app, the report shows nothing for that application. Most attorneys accept that as meaning the data is gone.
It is often not gone.
In one case we have presented in training, a phone showed all relevant applications deleted and a tool that could not decode them. The government’s report showed no relevant data. Incoming data for those applications had remained in the Firebase Cloud Messaging layer — unread by either major forensic tool, visible to an examiner who knew where to look. The case was dismissed.
We also cover the scenario where missing data is not missing at all — it is data the government chose not to map. Rule 701(a)(6) in courts-martial and its equivalents in federal and state practice require disclosure. An exculpatory cell record that places a defendant away from a location is subject to production. We train attorneys to ask what the government did not map, not just what it did.
Current presentation topics
We present on the following topics and tailor each session to the audience’s practice area and level of technical familiarity.
Digital Evidence from Seizure to Trial — the full workflow from first contact with a device through courtroom presentation. Covers proper seizure procedure, extraction types and why they matter, what analysis reveals, how to challenge the government’s collection methodology, and how to present findings to a jury. Built for criminal defense attorneys and public defenders.
Pins, Pings, and Problems — CDR mapping, timing advance analysis, and the gap between what cell location data shows and what prosecutors claim it shows. Covers how to read a CDR map, the difference between tower-sector coverage and actual device location, timing advance precision and its limits, and how to challenge government cell evidence under Rule 702 and Rule 403. Built for any criminal defense practice.
Messages, Mentions, and Mistakes — missing messages, fabricated screenshots, unreliable location data, and the databases behind the apps your clients use. The most broadly applicable session we offer. Suitable for criminal defense, civil litigation, family law, paralegals, and investigators.
Files, Formats, and Forensics — what to request in discovery, how to evaluate a forensic report, document metadata and AI-generated document detection, cloud data complexity, and Brady issues arising from incomplete productions. Built for attorneys receiving digital evidence who need to know whether they received everything.
Chats, Choices, and Challenges — ICAC undercover operations in court. Covers ICAC operational standards, how to evaluate UC conduct for protocol compliance, entrapment defense strategy grounded in forensic artifacts, and cross-examination of government examiners in ICAC cases. Built for criminal defense attorneys handling online solicitation and related matters.
When Do I Need a Digital Forensics Expert — a practical decision guide for attorneys uncertain whether a case warrants forensic engagement. Covers the categories of cases where digital evidence is most likely to change the outcome and how to recognize those cases before it is too late to engage help. Suitable for any practice area.
If your office, bar association, or practice group is interested in scheduling a CLE presentation, contact us. We offer sessions ranging from one hour to full-day workshops and can tailor any topic to your specific audience and jurisdiction.
Training for military counsel
Military defense and prosecution counsel represent a significant portion of the attorneys we have trained. We have presented at the Naval Justice School, TDS annual and regional conferences, DCAP, TCAP, and directly to individual JAG offices at installations across the country and overseas.
Military courts-martial involve the same digital evidence issues as civilian proceedings — and frequently more of them, given the concentration of communications and location data in cases involving personnel on or near installations. The rules of evidence differ. The investigative procedures differ. The way the government presents cell and device evidence in courts-martial has its own specific failure modes that we cover in military-specific training sessions.
If you are a military defense counsel or a JAG office looking to bring in outside CLE training on digital forensics, contact us to discuss scheduling.
Scheduling a presentation
Inviting us to present is straightforward. We assess your audience, agree on a topic and depth level, and deliver a session that earns CLE credit for attendees. We have presented to groups ranging from three attorneys in a conference room to several hundred at a state conference.
We travel for presentations. We have presented in Kentucky, Tennessee, Ohio, Virginia, and internationally including Germany. If your conference or organization is located elsewhere, contact us to discuss logistics.
We have presented this material often enough to know what lands and what does not. We do not read slides. We explain real cases, real mistakes, and real findings in plain terms, because that is what changes how attorneys handle digital evidence after they leave the room.
To schedule a presentation for your group, reach out through the contact page.
Related services and litigation support
- Expert Testimony and Trial Consulting
- Litigation Support
- Mobile Forensics
- eDiscovery — O365 and Beyond
Contact Cyber Agents to discuss whether cle presentations and training fits your matter.