A discovery process used in child pornography cases

In criminal cases involving Child Sexual Abuse Material (CSAM), the prosecution rarely produces forensic reports or source data to the defense due to the timely redaction process required to exclude CSAM media from the production.  Software applications, commonly used by digital forensic analysts to process and examine sources of digital evidence, have started to include methods for generating reports with the contraband redacted or to export data in a format which excludes all image or video files completely.  While this may not replace the need for an on-site forensic examination by a defense expert, it can save time and expenses for both sides during the discovery phase, and subsequently, the examination phase.  This article provides one technique using Magnet Axiom software, an application commonly used by law enforcement, for accomplishing such an export.  

Background

Discovery is the legal process of one party turning over evidentiary material it has in its possession to the other side.  In criminal cases involving child pornography, more broadly referred to as Child Sexual Abuse Material (CSAM) or referred to within the industry simply as "contraband", the prosecution cannot simply provide the defense with a copy of all evidentiary materials.  In these types of cases, CSAM is contained in the digital evidence seized during a residential search warrant (e.g. mobile device, external hard drive) or in search warrant returns from cloud providers (e.g. Kik, Facebook, or Google).   

18 U.S. Code § 3509 (m) - Child victims’ and child witnesses’ rights - Prohibition on Reproduction of Child Pornography is the primary law which both prohibits copies of CSAM from being made and also  requires the prosecution to provide the defense with an opportunity to review the digital evidence.  It  states the following:

(m) Prohibition on Reproduction of Child Pornography.—

(1)In any criminal proceeding, any property or material that constitutes child pornography (as defined by section 2256 of this title) shall remain in the care, custody, and control of either the Government or the court.
(2)
(A)Notwithstanding Rule 16 of the Federal Rules of Criminal Procedure, a court shall deny, in any criminal proceeding, any request by the defendant to copy, photograph, duplicate, or otherwise reproduce any property or material that constitutes child pornography (as defined by section 2256 of this title), so long as the Government makes the property or material reasonably available to the defendant. 
 
(B)For the purposes of subparagraph (A), property or material shall be deemed to be reasonably available to the defendant if the Government provides ample opportunity for inspection, viewing, and examination at a Government facility of the property or material by the defendant, his or her attorney, and any individual the defendant may seek to qualify to furnish expert testimony at trial.

(3)In any criminal proceeding, a victim, as defined under section 2259(c)(4), shall have reasonable access to any property or material that constitutes child pornography, as defined under section 2256(8), depicting the victim, for inspection, viewing, and examination at a Government facility or court, by the victim, his or her attorney, and any individual the victim may seek to qualify to furnish expert testimony, but under no circumstances may such child pornography be copied, photographed, duplicated, or otherwise reproduced. Such property or material may be redacted to protect the privacy of third parties.

The scope of this article is not going to dissect the laws related to CSAM, primarily because I'm not a lawyer.  But, based on my many years of performing examinations in cases involving CSAM on behalf of the defense, I'm in tune with how this process plays out.

Phases of "reasonably available"

The mechanics of "reasonably available to the defendant" typically involve a combination of two phases:

Phase 1 - Discovery

The prosecution provides discovery to the defense, redacting or excluding any contraband, including affidavits for probable cause, digital forensic and investigative reports, and narratives related to the pre-search warrant investigation (e.g. NCMEC Cyberline tips, returns from Internet providers, etc.), execution of the  residential search warrant, interviews, and subsequent digital forensic analysis.

Phase 2 - Examination

If determined to be necessary by the defense team, an examination is conducted by the defense expert.  The mechanics of this examination will be covered in another blog post, but essentially, the defense expert will go on-site to an office of law enforcement to examine the evidence.  Protocols and/or protective orders are put into place to define how the examination will be conducted, how any generated reports or data will be taken by the defense expert, and how the expert's computer(s) will be wiped/sanitized at the end of the examination (if the expert brought their own equipment).  The goals are to provide the defense an opportunity to review the digital evidence and to ensure no CSAM leaves with the expert.

Improving the Discovery Phase

After being retained by a defense attorney, the attorney provides the expert with the discovery they received from the prosecution.  Within the discovery, there is a usually a reference to a forensic examination or report.  In a non-CSAM case, discovery may include digital forensic artifacts in various formats, including but not limited to, a Cellebrite Reader report/case production from a mobile device, a PDF of a chat thread, or a search warrant return from a provider (e.g. Google).  But in a case involving CSAM, the defense will typically get none of the digital evidence beyond what is in the probable cause affidavit or a narrative summary.

While the discovery review serves great purpose, there is not a lot of "forensics" for the defense expert to review.  Thus, the on-site examination is likely required in order to answer questions the defense attorney has about the digital evidence or to seek support for a defense or mitigation strategy.  If the prosecution could produce digital forensic artifacts and chat threads in a manner which excluded images and videos, it would allow the defense expert to answer some of the defense attorney's questions, or at the very least, prepare better for the on-site examination.

Why would the prosecution want to make things easier for the defense?

Why would the prosecution want its law enforcement examiners to take extra steps to provide the defense with additional discovery when it sounds like this is more work for law enforcement.  

Two reasons:

1. The less time the defense has to spend on the on-site examination, the less time a law enforcement officer has to spend hosting the defense expert at their office.  Typically, a law enforcement officer remains in the same room or nearby as the defense expert performs the on-site examination. By receiving and reviewing the additional forensic artifacts in advance of the on-site examination, the defense expert can prepare to conduct a more efficient examination.

2. It may take an entire day or more for a forensic examiner to wait while forensic software processes and exports artifacts from a single device.  If  a defense expert performs this process during the on-site examination, the defense expert will need to remain at the office of law enforcement throughout the process.  A law enforcement agent who has already processed a case can use the process below to export data in a CSAM case for the defense expert to review ahead of an on-site examination.

Export forensic artifacts and chat previews using Magnet Axiom

Disclaimer: This process should be used at your own risk. In a real-world scenario, the author recommends performing a confirmation test to be sure that no pictures or videos are exported during the process. Transparency and coordination with law enforcement about the removal of any digital artifacts during or after an examination involving CSAM is highly recommended.  Software does have bugs. User error does happen.

Magnet Axiom is commercial software commonly used by forensic examiners and law enforcement agencies during the performance of forensic examinations.  Axiom can process most forms of digital evidence, including mobile devices, computers, email, social media, and search warrant returns.  It has an export process which can export all of its parsed forensic artifacts as CSV files. CSV stands for comma separated values, and it is essentially a text file with an large number of commas separating the other text.  Axiom also has an option to export chat thread previews (e.g. Whatsapp, SMS, iMessage, Facebook Messenger, etc.) to HTML (viewable in any web browser) excluding the attachments.  By following the method below, a law enforcement examiner can export forensic artifacts and chats without exporting any contraband.  While this export will not include any pictures or videos, it does provide a lot of information useful to the defense expert and attorney.


NOTE: Screenshots were taken using Axiom 6.7 in 2022.  Other versions may look different or have various capabilities.

1. Process the evidence in Axiom.
2. Create an export by File->Create Export/report
3. Select CSV as the format.



4. Select All evidence as items to include.

5. Confirm you want all artifacts to be exported.



6. Configure Artifact Details:

- Uncheck Include source files in the attachment folder.
- Check Include chat threads as HTML.
- Select the radio button for Include the full conversation history.
- Uncheck Generate .MSG attachments for email artifacts. 
- Configure Columns to include All Columns. 
 

7. Export.

Sample Results

This process will produce a directory of individual CSV files representing each forensic artifact.  It will also include a "Chat preview report" folder.  The screenshot below is a partial display of an export.

Axiom export to CSV with Chat preview

The "Chat preview report" folder will contain html files for each conversation, as shown below.



The content of one of the chat threads looks like the screenshot below.  Instead of pictures or videos, you'll see the language that I highlighted, "Attachment excluded from report.".



Conclusion

While the method described in this post may not replace an on-site examination by the defense's digital forensics expert, this method can help reduce the cost and labor for both the defense and prosecution as a means to supplement the discovery phase in cases involving CSAM.

Reference

https://www.magnetforensics.com/docs/axiom/html/Content/en-us/axiom/sharing-evidence/exporting-outputs.htm


Popular posts from this blog

Preservation of YouTube videos

Critical cell site information often missing from search warrant returns