3.Kevin Swindon — Direct (Part 1)
396 lines(SIDEBAR CONFERENCE AS FOLLOWS:
MR. FICK: We object to this witness being called at this time in light of the government's late disclosure yesterday of incredibly voluminous material yesterday. Just after 6 p.m., we received a stack of CD-ROMs in our office containing essentially a reworking of the exhibits for this witness. This witness is an expert who is going to be -- at least the government hopes he's going to be the vehicle to introduce literally hundreds of files from computers and dozens of very dense analytic spreadsheets about the contents of the computers. Yesterday the government made this new production which, among other things, adds new spreadsheet analytic exhibits, two of them in excess of several thousand pages. One is, like, 4,600 and one is 2,500 something. Other exhibits are renamed. Other exhibits are modified. Frankly, some exhibits were taken out. Some exhibits were added. Frankly, I haven't had a chance even to really get through and figure out the correlation from the old exhibits to the new ones yet, and there was no accompanying list describing the changes. For that reason, we simply can't be in a position to cross-examine an expert like this today.
MR. CHAKRAVARTY: So the changes to the disks were very modest. The two voluminous documents that were added were the complete file listings for the laptop computer which you heard about today, and there was a desktop computer that was found at the Norfolk Street house.
The reason for the introduction of that as an exhibit is in light of defense strategy throughout the trial of suggesting that we were cherry-picking, as came out clearly during the Twitter cross-examination. We felt it was prudent to have at least the full file listings which shows that we're not hiding the content and have it available. It was never the government's intention that that would go back and the jury would parse through 4,000 pages. We're fine with having that marked for identification, but this witness is simply going to acknowledge that that exists. Everything else simply acknowledges that that exists. They put it onto the disks so that they're not ignoring it. Everything else was taking things off of the disks partially because the defense complained about some of the language, some of the characterizations on the spreadsheets. For example, "jihad-related activity" was changed to "selected activity" so that we were kind of making it more neutral, more appropriate, those kinds of changes.
Organizationally, some files were moved from one folder to another folder. These are extremely modest changes. We did not change the substance or the files that were designated or that we were going to be introducing.
MR. FICK: Even crediting Mr. Chakravarty's characterization, which I actually don't agree with completely, simply the reorganization makes it impossible to do an effective cross or to understand what's coming in during the direct here. Quite apart from the question of whether the thousand-plus-page exhibits are going to come into evidence, at a minimum, we ought to be able to look at it with our expert to determine if there are things we can extract from that to use on cross-examination. I can guarantee you there likely are. Under the circumstances, it's simply unreasonable to expect us to go forward today with this witness.
THE COURT: How long will your direct be?
MR. CHAKRAVARTY: Approximately two hours.
THE COURT: We'll proceed with the direct. If it appears after the direct that you need further time, we can postpone the cross-examination.
THE COURT: Maybe. No. I mean, I'll assess it. I'll see what the direct sounds like. We'll confer again. But that's a solution. We'll at least make some progress with the evidence.
MR. FICK: I expect there are going to be some foundation -- Melendez-Diaz-complication-type challenges to the exhibits along the way just to sort of flag that.
MR. CHAKRAVARTY: Your Honor, one other point. I should have mentioned it in chambers before. But some of the devices about which he's -- he analyzed and processed have not yet been introduced into evidence and presented to the jury. So we'd ask that that testimony be taken de bene depending on what's --
THE COURT: All right.
. . . END OF SIDEBAR CONFERENCE.)
MR. CHAKRAVARTY: Supervisory Special Agent Kevin Swindon.
COURT CLERK: Sir, you want to step up to the box, please.
KEVIN SWINDON, Sworn
COURT CLERK: State your name. Spell your last name for the record. Keep your voice up and speak into the mic so everyone can hear you.
KEVIN SWINDON: Thank you. First name is Kevin. Last name is Swindon, S-w-i-n-d-o-n.
DIRECT EXAMINATION BY MR. CHAKRAVARTY:
MR. CHAKRAVARTY: Good morning.
KEVIN SWINDON: Good morning.
MR. CHAKRAVARTY: Where do you work?
KEVIN SWINDON: I work for the Federal Bureau of Investigations.
MR. CHAKRAVARTY: In what capacity?
KEVIN SWINDON: The supervisory special agent for the Cyber Squad in the Boston division.
MR. CHAKRAVARTY: What does the Cyber Squad do?
KEVIN SWINDON: The Cyber Squad is responsible for investigating cyber matters in Maine, New Hampshire, Rhode Island, and Massachusetts as it relates to computer intrusion matters for criminal and national security.
MR. CHAKRAVARTY: Do you supervise any other units or squads?
KEVIN SWINDON: I do. In our program -- I'm here in Boston. We also have the Computer Forensic Analysis Team, or CART. And, lastly, we have the photo program, which is also under the Cyber Squad here in Boston.
MR. CHAKRAVARTY: What does the Computer Analysis Recovery Team do?
KEVIN SWINDON: The Computer Analysis Response Team is responsible --
MR. CHAKRAVARTY: Response.
KEVIN SWINDON: -- for the imaging and processing of digital media for all the investigative responsibilities for the FBI.
MR. CHAKRAVARTY: How long have you been a special agent?
KEVIN SWINDON: I've been a special agent a little over 18 years.
MR. CHAKRAVARTY: Have you had particularized training in computer forensics?
KEVIN SWINDON: I have. Prior to being the supervisor of the program, I was a certified forensic examiner for ten years.
MR. CHAKRAVARTY: What is a forensic examiner?
KEVIN SWINDON: A certified forensic examiner in the Bureau is an employee who's trained and responsible for the collection and processing of digital media for all types of investigations.
MR. CHAKRAVARTY: You say "digital media." Can you give examples of what digital media is?
KEVIN SWINDON: Sure. Digital media can be a thumb drive. Could be a computer. Could be a server. Could be anything where digital media would be housed or stored.
MR. CHAKRAVARTY: Has that role of computer forensics increased over time?
KEVIN SWINDON: Absolutely. It's increased a hundredfold over time. I think every investigative responsibility that the FBI has has seen an increase in digital media associated with it.
MR. CHAKRAVARTY: Before you became a forensic examiner, did you have particular training in computer forensics?
KEVIN SWINDON: I came out of the computer industry in the private sector before joining the FBI in 1996.
MR. CHAKRAVARTY: And then in the FBI did you have any training?
KEVIN SWINDON: We did. The certification for the forensic program is intensive, requires an A+ and Net+ certifications. There's a two-week basic data recovery, a one-week advanced data recovery, practical exams, and then a moot court in order to be completely certified.
MR. CHAKRAVARTY: You mentioned that you had been in the private industry as well. What was your job then?
KEVIN SWINDON: My private industry job prior to the Bureau, I did network consulting to the hospitality industry.
MR. CHAKRAVARTY: What's your education?
KEVIN SWINDON: I have a bachelor in science and industrial management from University of Lowell. I have a master's in business administration from Northeastern and a master's in finance from Boston College.
MR. CHAKRAVARTY: Aside from your computer forensic certifications, have you had any other certifications in your career in computers?
KEVIN SWINDON: In computers. The cyber training program, to be a cyber agent, there are several phases of classes that you go through or that you progress through. And that was -- those classes were taken through -- there's four phases for a cyber special agent, and I completed the three of the four phases.
MR. CHAKRAVARTY: You also stay up to date through your supervisory duties?
KEVIN SWINDON: Yes. Supporting or managing the program requires a constant update of staying current with technology and aware of the current threats and trends in cyber.
MR. CHAKRAVARTY: Are you active in InfraGard?
KEVIN SWINDON: We have a full InfraGard chapter here in Boston, which is a public/private organization where the FBI partners with private sector to provide training and awareness on cyber threats and trends.
MR. CHAKRAVARTY: Do you present on computer forensics?
KEVIN SWINDON: I do. Typically have -- give presentations 15 to 20 probably per year on cyber-specific threats and trends and then several computer forensic presentations.
MR. CHAKRAVARTY: Have you personally completed computer forensic examinations over your career?
KEVIN SWINDON: I have.
MR. CHAKRAVARTY: About how many?
KEVIN SWINDON: In the -- to get an exact number would be very difficult, but it's over a couple of hundred.
MR. CHAKRAVARTY: In addition, have you participated in and supervised others doing their forensic --
KEVIN SWINDON: I have. I have been the program manager or the supervisor of the CART program for the time that I've been the supervisor in Boston.
MR. CHAKRAVARTY: Over the course of that time, has there been peer review of your work and have you conducted peer review of others' work?
KEVIN SWINDON: Yeah. As a part of the forensic process, there's a certain percentage of -- certain percentage of examinations that get peer reviewed and admin reviewed, and I've been both -- I've participated in both processes.
MR. CHAKRAVARTY: Have you testified previously as a computer expert in computer forensics?
KEVIN SWINDON: I have. Yes, I have.
MR. CHAKRAVARTY: Have you testified before Federal District Court in Massachusetts?
KEVIN SWINDON: I have.
MR. CHAKRAVARTY: And have you testified in other courts as well?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: Have you done computer forensic analysis in terrorism cases before?
KEVIN SWINDON: Yes, I have.
MR. CHAKRAVARTY: About how many times?
KEVIN SWINDON: Probably four or five times specific to terrorism matters.
MR. CHAKRAVARTY: At this point, your Honor, I'd ask to qualify Agent Swindon as an expert in computer forensics.
THE COURT: All right.
MR. CHAKRAVARTY: Agent Swindon, can you explain to the jury what computer forensics is?
KEVIN SWINDON: Computer forensics has really evolved over the last number of years where previous -- as technology started to become what it is today, the process has changed. It's become more of a forensic science where there's a process and procedure for most things that we do including how we handle the evidence upon collection, what we do when we image it, and then how we process it. It sort of has become much more standardized over the course of time.
MR. CHAKRAVARTY: And the forensics part of it, what are the primary objectives of conducting forensic analysis?
KEVIN SWINDON: The primary focus would be to -- you know, to acquire evidence in a forensically sound way so as not to change that evidence but, in the process, being able to collect that evidence and make it usable in legal proceedings.
MR. CHAKRAVARTY: What types of digital media are prone to computer forensic analysis?
KEVIN SWINDON: We process a variety of different types of digital media. It can range from thumb drives or USB thumb drives to external hard drives, to laptops, to computers, to servers in businesses. Anything where digital media would be stored we have the -- we have the ability to process.
MR. CHAKRAVARTY: Is there a general -- are there general phases of the computer forensic process?
KEVIN SWINDON: There are general phases although each may differ slightly based on the type of media or the digital media that you're processing. But, typically, it's sort of a two-phase process where there's an imaging phase and then a processing phase.
MR. CHAKRAVARTY: What is the imaging phase?
KEVIN SWINDON: The imaging phase would be the process by which you acquire the initial image of that evidence. We would use either a piece of hardware or a piece of software to acquire a bit-by-bit image of -- or a forensic copy of that device or digital media.
MR. CHAKRAVARTY: What types of techniques do you use to do that?
KEVIN SWINDON: If it was a software technique, for example, if it was a hard drive, if it was your home computer, and we had to image that home computer, we would remove that hard drive from the computer, connect it to another computer in our lab with a -- the ability to write protect so as to not write back to that drive. And we would use a software application to image that drive.
MR. CHAKRAVARTY: The software applications that you use in your computer forensics work, are those industry standard software applications?
KEVIN SWINDON: They are commercially available, and most of the tools we use are commercially available.
MR. CHAKRAVARTY: Are those used routinely by FBI offices around the country?
KEVIN SWINDON: Yes. Forensic practitioners around the country would be utilizing those tools.
MR. CHAKRAVARTY: Agent Swindon, you used the word "image." Can you explain what that means in the world of computer forensics?
KEVIN SWINDON: Sure. Typically, there are two types of images we can make of a piece of digital media. There's going to be a logical copy and a physical image. The physical image is going to be a bit-by-bit copy of that piece of digital media. It's going to ignore the operating system. So whether it was, for example, an Apple computer or a Windows computer, that imaging process would ignore that operating system and then image that drive bit-by-bit. The other alternative, if that's not available to do, would be a logical copy. For example, if you were on your home computer at home and you wanted to copy files off, you could go to your computer -- Windows computer and copy from your C drive over to another drive, would be a logical copy.
MR. CHAKRAVARTY: So when you're talking about an image, you're not talking a photograph. You're talking about the content of the media?
KEVIN SWINDON: The physical image would be an exact duplicate of what was on that drive at the time it was seized.
MR. CHAKRAVARTY: When you say "bit-by-bit copy," you mean the little bits of data?
KEVIN SWINDON: It goes down to the disk and, again, ignores the sort of operating system that's on that drive and would make a bit-by-bit copy.
MR. CHAKRAVARTY: How do you verify that an image was done properly?
KEVIN SWINDON: There are several techniques that you can do that, but the most widely accepted is going to be an MD5. I'll explain what that is. A MD5 is a technique that we use in forensic sciences to validate or verify that an image is made and collected properly or matches the drive that you're copying. MD5 would be similar to like -- an MD5 value would be similar to say, like, a fingerprint. We would run a program against a folder, a file or a drive, and that program would generate that MD5 hash value. And that value would be unique to that file folder or drive. We then could compare that number, that unique number, to that file folder or drive at any point in time during the process to verify that no changes were made to that image or collection that we made.
MR. CHAKRAVARTY: Is that routinely done when an image is made pursuant to the FBI's CART protocol?
KEVIN SWINDON: Yeah. Most imaging software have it automated as a part of their process now. So when you do make that physical image, it would also calculate an MD5 hash value.
MR. CHAKRAVARTY: You said that was the first phase of the computer forensics process?
KEVIN SWINDON: Yes. Imaging is the first phase and, typically, the most important phase.
MR. CHAKRAVARTY: So what comes after the imaging phase?
KEVIN SWINDON: After the imaging phase, depending on the investigation or the case and the request of the actual case agent who's in charge of the case, we would then process that image or process the data that we would have collected in their image form.
MR. CHAKRAVARTY: What do you process that data with?
KEVIN SWINDON: We -- typically it's commercially available software that we would process with. We would try that first. And then that commercially available software would do a number of things. It would take a look at that image. It would look inside that image that we just made and be able to pull the data out of that image, for example, the documents, the spreadsheets, photos or images that might be on that drive. It would also give us access to other things on that drive that you may not see as a user, which would include deleted files or recovered files that you may think are deleted on the computer but are still recoverable by the forensic software.
MR. CHAKRAVARTY: What are the tools that you typically use at the FBI?
KEVIN SWINDON: Typically use -- we have a number of tools that have been tested and validated. Typically, the primary choice is going to be AD Labs, which is a product made by Forensic Toolkit or AccessData. And then, secondly, X-Ways Forensics has a new tool that's been provided in our toolkit of tools that have been tested and validated.
MR. CHAKRAVARTY: So once you've processed the data that was imaged, can you make that available then for agents or other people to be able to look at that?
KEVIN SWINDON: We do. Once it's processed, we have a -- for lack of a better term, a graphical user interface, that we would provide that processed image to a case agent or an analyst to be able to review. It would allow them to be able to look on that computer or look into that computer to see what files existed or look in that image.
MR. CHAKRAVARTY: That would go for some of the other digital files that you mentioned earlier, like video files or pictures?
KEVIN SWINDON: Sure, yes. The forensic software typically breaks them out and categorizes them by Word documents, Excel spreadsheets, PDFs, JPEG or images that might be on your computer.
MR. CHAKRAVARTY: How does this differ from -- if the typical circumstance where a person might take a memory card out of their camera and plug it into their computer?
KEVIN SWINDON: Well, what happens is when -- if you were to take that card out of your camera and put it into the computer, it would actually make changes to that card. The forensic process, we would make sure that the way that we image that piece of media, there would be no changes made to it or the image upon collection.
MR. CHAKRAVARTY: In addition to the pictures that may be in what we call active space, could you find other data on that card?
KEVIN SWINDON: The software -- the forensic software has the ability to do several things. One of the tools it has, it can identify previously deleted files. So, for example, if you had a file on your computer that you deleted and it still existed or the data still existed on that drive, the application software would have the ability to identify that it had been deleted and then be able to recover that file and make it usable or visible to the person who's reviewing.
MR. CHAKRAVARTY: Once that process is complete and the analysis of the data on a computer is complete, what's the next phase of the process?
KEVIN SWINDON: What typically we would do is, based on the request, we would then provide that processed image to a either case agent or team or team of analysts or a team of investigators who would then review that data.
MR. CHAKRAVARTY: And then, if that team then identified particular files that they wanted to extract from a particular computer device, how do you do that?
KEVIN SWINDON: Typically, the investigative team or the reviewers would then -- they may -- if they were using AD Labs, which is a typical software we would use, they would make bookmarks or they would -- like bookmarks in -- if you were reading a book and put a bookmark to save your page, they have electronic bookmarks that they would mark data that we then, as a forensic examiner, then can go back into that software afterwards and then export those files that they had identified as being significant.
MR. CHAKRAVARTY: How do you export those files without changing the original data on the device?
KEVIN SWINDON: Well, typically, we would then have the -- we would have the MD5 hash value for that file if it was a file of significance. And then we would -- just like you would burn a CD at home, we would burn that file to something or a piece of media that couldn't be written to again. Typically, like, we would use a CD-R which you could burn once. We would write those files to and then provide that to the investigative team as what we would call derivative evidence.
MR. CHAKRAVARTY: Now, as a computer forensic examiner, would you select which files need to be exported?
KEVIN SWINDON: In most cases probably not. It would -- we don't know the most about the cases. The investigators or the analysts know the most about the cases. We can assist them if it was a -- sort of a -- say it was a complex white collar crime, and the agent might be a white collar expert but not a technology expert. We may help them through the process of identifying where the evidence might be, but they're going to know best what evidence is most important to the case.
MR. CHAKRAVARTY: What steps are taken -- you mentioned that there was an MD5 hash taken after an examination, is that right?
KEVIN SWINDON: The MD5 hash is collected or first calculated at the point of imaging.
MR. CHAKRAVARTY: Okay. So you explained that that's a unique number. But what does an MD5 hash value go to? Is it a computer? Is it a file or what?
KEVIN SWINDON: It can actually verify a file, a folder or a complete drive or an image. If you were to run that program or the program that generates the MD5 hash value for that file, folder or drive. You would then hold that, and that becomes a part of your admin file, your log file, so that way later you can compare to make sure that no changes were made to that original evidence.
MR. CHAKRAVARTY: The process that you just described of the imaging, the processing, the analysis, and the export of digital data from media, is that a standard process that the FBI uses?
KEVIN SWINDON: It is. I mean, it's part of the forensic training for new examiners, or for examiners.
MR. CHAKRAVARTY: Is that a process you've done as long as you've examined computers?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: Now, let's draw your attention to this investigation, this case. Have you been working on the Boston Marathon investigation off and on over the last couple of years?
KEVIN SWINDON: Yes, I have.
MR. CHAKRAVARTY: At the beginning of the investigation, what was your role?
KEVIN SWINDON: My role at the time, I was temporarily assigned as an acting ASAC for the office for the cyber and counterintelligence branch.
MR. CHAKRAVARTY: And so after the Boylston Street explosions, what was your duty?
KEVIN SWINDON: Immediately following the Boston Marathon bombing event, I became responsible for overseeing the digital media collection and, operationally, sort of the day shift, if there really was one, in the command post.
MR. CHAKRAVARTY: The digital media collection, what types of digital media were being collected?
KEVIN SWINDON: There was a number -- again, there was a number of different types of media that were collected as a part of this investigation. There were cell phones and thumb drives and computers, DVRs such as the DVRs that were taken from Boylston Street, and a number of different types of evidence.
MR. CHAKRAVARTY: At some point did your role change in the last two years?
KEVIN SWINDON: It did. Operationally, once the person that I was acting for came back from their temporary duty assignment, I then -- I resumed my duties as the supervisor of the Cyber Squad in Boston.
MR. CHAKRAVARTY: What was your role for purposes of testimony in this case?
KEVIN SWINDON: For purposes of testimony in this case, I was asked by the investigative team to validate and verify those -- as we spoke about earlier, those sort of selected files that were made from those processed -- the processed pieces of evidence.
MR. CHAKRAVARTY: Now, how many people have worked on the computer forensics process in this case?
KEVIN SWINDON: Immediately following the bombing, we mobilized teams from a number of different offices, to include, New York, Philadelphia, and as far away as Miami, to come help support the collection or ingest the computer forensic evidence. So I would say, would estimate, there would have been over 50 different sort of certified forensic examiners that were involved in either collection or processing.
MR. CHAKRAVARTY: And that's in addition to the people who actually seized items of evidence?
KEVIN SWINDON: That is in addition.
MR. CHAKRAVARTY: That is in addition to the people who actually analyzed the evidence?
KEVIN SWINDON: Yes. It may be different, yes.
MR. CHAKRAVARTY: Were there other agencies that participated in that process as well?
KEVIN SWINDON: There were several task force agencies during the actual initial event that were assisting in the collection, the collection of -- there were so many scenes that had to be processed, that we utilized some of the other agencies that provided assistance.
MR. CHAKRAVARTY: And were all -- was all of the evidence that was collected by the FBI, the digital evidence, was it processed using the computer forensic process that you described earlier?
THE COURT: Overruled.
KEVIN SWINDON: Yes. At both Black Falcon and One Center Plaza were the two sort of forensic collection points for digital media. They were staffed with fully certified forensic examiners who follow the same SOP, standard operating procedures, and guidelines.
MR. CHAKRAVARTY: Were you supervising them at the time?
KEVIN SWINDON: I oversaw the collection, yes.
MR. CHAKRAVARTY: Did you go to Black Falcon? Did you go to the Center Plaza?
KEVIN SWINDON: I did. I was assigned to Center Plaza, which the forensics lab is right next to, where the command post was set up and made daily visits over to Black Falcon to brief them on the events of what was going on.
MR. CHAKRAVARTY: As part of the FBI's analysis protocol, were there steps to ensure that you have legal authority to actually search these devices?
KEVIN SWINDON: Absolutely. All the evidence in this case was seized pursuant to legal authority.
MR. CHAKRAVARTY: At Black Falcon, you've mentioned, is this the staging area where evidence was taken after the bombings?
KEVIN SWINDON: Black Falcon was initiated to help -- have one place where evidence could be. There was -- evidence was so voluminous that we needed to find a place where we could bring in -- a large enough area to bring in all the evidence. And Black Falcon was provided, I believe, by Massport to be the ingest for evidence, including the digital media.
MR. CHAKRAVARTY: And can you explain a little bit how the computer forensics work was happening at Black Falcon?
KEVIN SWINDON: We set up a lab at Black Falcon that mirrored the lab that we have that's permanent in One Center Plaza. We have a mobile sort of command post per se that came up from New York and has full access and full technology that we would have in a typical permanent lab, and they deployed -- they can deploy it in the field.
MR. CHAKRAVARTY: How was the computer forensic process happening at Center Plaza?
KEVIN SWINDON: According to -- our forensic lab is a permanent lab. So, really, it was -- other than being busier, it was -- it was standard procedure for us there.
MR. CHAKRAVARTY: Let's draw our attention to some particular devices in this case. About how many devices were seized in the course of the Boston Marathon investigation?
KEVIN SWINDON: I believe at last count there were over 600 pieces of digital media that were collected.
MR. CHAKRAVARTY: Did you examine each one of those?
KEVIN SWINDON: I did not examine each one of those.
MR. CHAKRAVARTY: In fact, do you know if any one person has?
KEVIN SWINDON: I do not believe one person has examined all 600 pieces of digital media -- or one single person, I'm sorry.
MR. CHAKRAVARTY: Is it fair to say that, of the 600 devices, there were a variety of different types?
KEVIN SWINDON: Yeah. There were numerous different types, as we described before, whether it be phones, thumb drives, computers, laptops, digital video recorders from businesses.
MR. CHAKRAVARTY: Would the data on those devices amount to, you know, megabytes and gigabytes and terabytes worth of data?
KEVIN SWINDON: Yeah, there were terabytes of data.
MR. CHAKRAVARTY: Were you asked to look at some specific devices in this case?
KEVIN SWINDON: I was. As a part of the process, as we described earlier, there was an imaging, a processing, and then a team views or exhaustively searches the processed material. Once they've identified the files or items of interest, I was then asked to validate and verify that those items of interest existed on the pieces of evidence where they originated from.
MR. CHAKRAVARTY: When you say "pieces of evidence," on the devices that were seized by the FBI?
KEVIN SWINDON: On the devices, right, that were associated with the investigation -- on the number of different investigations, yes.
MR. CHAKRAVARTY: You were confirming what material -- some of the materials that were on those devices?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: And how did you do that?
KEVIN SWINDON: There was a set of disks that we have, and those disks had evidence files that were numbered. And based on a numbering system of an exhibit number, the files were then, to the best of their ability, kept the true name. They were then compared to files on the computer of where they originated from.
MR. CHAKRAVARTY: And how did you compare it with the files from the original computer device that was seized?
KEVIN SWINDON: We went back into -- when we talked about earlier, the forensic software called AD Labs, which is where the evidence or the images of those evidence were staged. We went back in -- or I went back in with the CDs, went into AD Labs, and validated and verified that that -- that those files existed.
MR. CHAKRAVARTY: How did you know which computers they were associated with?
KEVIN SWINDON: The files were labeled where the images or where -- the files were labeled of what piece of evidence, where they came from.
MR. CHAKRAVARTY: Is that pursuant to the standard imaging process that you described earlier?
KEVIN SWINDON: Well, the numbering system is typically established with our Evidence Response Team.
THE COURT: Why don't you reask it.
MR. CHAKRAVARTY: I'll reask the question. How did you know what devices the files were from?
KEVIN SWINDON: It was identified -- there's a numbering system that exists, and we cross-referenced the numbering system for the exhibit numbers to the evidence numbers that -- as we heard earlier, the Evidence Response Team numbers things on scenes -- at scenes.
MR. CHAKRAVARTY: As a computer analyst, do you -- are you generally familiar with where pieces of evidence were found?
KEVIN SWINDON: Typically. I mean, typically, because we would have to review the documentation before an exam proceeded. We'd need to make sure that legal authority was in proper order. We would need to know the locations of where things were from. We would need to know the background of that before the exam began.
MR. CHAKRAVARTY: That's part of the standard practice?
KEVIN SWINDON: That's part of the standard practice.
MR. CHAKRAVARTY: As you verified the contents of these CDs, did you create something that would help explain your testimony?
KEVIN SWINDON: We did. The number of pieces of evidence were so voluminous and the number of files that we're asked to validate and verify, we created sort of a spreadsheet to be able to recall what pieces of evidence that we would be talking about today.
MR. CHAKRAVARTY: I'd ask for the witness, 1153. Excuse me. Sorry. 1557. Excuse me.
MR. CHAKRAVARTY: Agent Swindon, do you recognize this?
KEVIN SWINDON: I do.
MR. CHAKRAVARTY: What is it?
KEVIN SWINDON: That is the spreadsheet that we made when we were first asked to start to validate and verify this process. It was a spreadsheet that we put together to be able to track what pieces of evidence we were using, and it gave us a snapshot of a quick reference.
MR. CHAKRAVARTY: Would this be helpful in presenting your testimony today?
KEVIN SWINDON: Tremendously, yes.
MR. CHAKRAVARTY: Your Honor, I'd ask that 1557 be marked as a chalk.
MR. FICK: No objection to the chalk except that I'd like him to clarify when he says "we" prepared this exhibit. Who's "we"?
MR. CHAKRAVARTY: Who did you work with to prepare this exhibit?
KEVIN SWINDON: No one. I created it.
THE COURT: I'll expose it.
MR. CHAKRAVARTY: Thank you, your Honor.
MR. CHAKRAVARTY: Agent Swindon, can you read that?
KEVIN SWINDON: I can, yes.
MR. CHAKRAVARTY: How did you select these particular devices to make this chart about?
KEVIN SWINDON: I didn't actually select the devices. These devices corresponded to the files that I was asked to validate and verify.
MR. CHAKRAVARTY: And so this is the universe of the devices that you looked at?
KEVIN SWINDON: Yes, sir.
MR. CHAKRAVARTY: Now, with the exception of a couple of these devices, did you actually go in and check file by file whether files that are going to be presented to the jury were, in fact, on these devices?
KEVIN SWINDON: I was provided these CDs for the exhibit numbers and verified that the files existed on the pieces of evidence that are listed on the sheet here.
MR. CHAKRAVARTY: If I may approach, your Honor?
THE COURT: All right.
MR. CHAKRAVARTY: Handing you a binder, Agent Swindon, do you recognize that?
KEVIN SWINDON: I do.
MR. CHAKRAVARTY: What is it?
KEVIN SWINDON: It's a two-inch, three-ring binder, with two CD placeholders in it.
MR. CHAKRAVARTY: Are there several CDs in there?
KEVIN SWINDON: There are. There are 13 total CDs.
MR. CHAKRAVARTY: Do you know what those CDs are?
KEVIN SWINDON: I do. These are the CDs I was provided with to be able to check the files to make sure that these files that are on these CDs existed on these pieces of evidence.
MR. CHAKRAVARTY: Did you, in fact, verify that?
KEVIN SWINDON: I did.
THE COURT: What was the number of CDs?
KEVIN SWINDON: Sorry. There are 13, sir.
MR. CHAKRAVARTY: And, specifically, if I may, Agent Swindon, I'm going to read off a list of numbers on the CDs, exhibit numbers, and ask if you can verify that those CDs are in there.
KEVIN SWINDON: Okay.
MR. CHAKRAVARTY: 1141?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1142?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1143?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1144?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1145?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1146?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1147?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1148?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1149?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: 1150?
KEVIN SWINDON: Yup.
MR. CHAKRAVARTY: And 1151?
KEVIN SWINDON: Yes.
MR. CHAKRAVARTY: Is there also an 1152 in there?
KEVIN SWINDON: Yes, sir.
MR. CHAKRAVARTY: Sorry. There's one more. 1457?
MR. CHAKRAVARTY: 1457 is not in there?
KEVIN SWINDON: No, it is not.
MR. CHAKRAVARTY: Okay. I'll have to get that. With regards to 1141 through 1151, do those contain documents that were on each of the devices that they correspond to?
THE COURT: All right.
(SIDEBAR CONFERENCE AS FOLLOWS:
MR. FICK: The objection is he's asking the question based on a false premise. These CDs contain not only files from the various devices but various analytic spreadsheets of the -- either the FBI's or the U.S. Attorney's Office's own making. So it's, like, to ask the question in that form is itself misleading. And it sort of raises again the notice problem we had because these are the new disks we got yesterday that now have different contents than what we thought they had before.
MR. CHAKRAVARTY: I'll certainly clarify that there are analytical files or metadata that's also put on there that he will explain, and he will go through each of the CDs explaining which ones correspond to which devices.
MS. CONRAD: But are you offering the entire disks?
MR. CHAKRAVARTY: I am going to offer the entire disks, not at this time.
. . . END OF SIDEBAR CONFERENCE.)
MR. CHAKRAVARTY: Agent Swindon, do these CDs have the data extracted from the -- each of the devices that they correspond to?
KEVIN SWINDON: Do the numbered CDs have the data extracted from the numbers of the -- corresponding to the pieces of evidence on the spreadsheet?
MR. CHAKRAVARTY: Correct.
KEVIN SWINDON: Yes, they do.
MR. CHAKRAVARTY: Does it have all of the data for each of the devices?
KEVIN SWINDON: It does not have all of the data for each of the devices. The data for each of the devices would be too voluminous to fit on this many CDs or DVDs, so it was -- a sample or particular files were identified by the team and then extracted and put onto these CDs or DVDs.
MR. CHAKRAVARTY: Is it fair to say there are thousands and thousands of files on those computers?
KEVIN SWINDON: There are.
MR. CHAKRAVARTY: So can you explain what this -- sorry. In addition to the files that were actually extracted and put onto these computers -- excuse me, the CDs, were there any other types of metadata or other files that were also put onto these CDs?
KEVIN SWINDON: There are other files on the CDs. The other files would include a directory file listing for each of the devices when they could -- when they're appropriate or could be made. And then there are some derivative reports or derivative spreadsheets made from the data on that also.
MR. CHAKRAVARTY: Okay. So what is a directory file listing?
KEVIN SWINDON: A directory file listing would be a listing of all of the files that would exist on that computer.
MR. CHAKRAVARTY: And what are the derivative spreadsheets?
KEVIN SWINDON: A derivative spreadsheet would be a spreadsheet that would be created by someone that maybe aggregated information from several different places, maybe from the directory listing or maybe from other files on the computer for the ease of understanding.
MR. CHAKRAVARTY: Can you give an example of a derivative file listing?
KEVIN SWINDON: If -- for example, if you had a file listing for your whole computer or your whole computer at home, most of it would be useless because you've got your Windows directory there with files that you don't need to see. But if you wanted a directory listing of just your documents and settings, you could do a full directory listing for your whole hard drive and then only select what you may want to see in your documents and settings. Gives you a snapshot of a smaller subset of what was on that computer.
MR. CHAKRAVARTY: Are you familiar with internet history?
KEVIN SWINDON: I am familiar with internet history.
MR. CHAKRAVARTY: How is internet history exported from a computer?
KEVIN SWINDON: Internet history resides on your computer, typically your browser, whether you're using either Mozilla or Internet Explorer or Chrome, would track a history of you being online or an internet history file where that history would reside. You can do a couple things. You could export that file individually to look inside of it, or there are other applications that we would use post processing to assist us in trying to look at that file and make it understandable and usable.
MR. CHAKRAVARTY: Can you pare that down so you're only exporting some of the internet history?
KEVIN SWINDON: Once you have access to that internet history file, you can either select a range of dates or you can select maybe a particular type of web page or URL that you were looking for and filter it by that.
MR. CHAKRAVARTY: Were those derivative spreadsheets that you described, were those the result of that kind of a process?
KEVIN SWINDON: In some cases on these CDs, yes.
MR. CHAKRAVARTY: What other types of information were put on these CDs?
KEVIN SWINDON: These represent several different types of media. So, for example, there are -- one of the CDs is from a couple of -- from iPhones that were collected as a part of the investigation. And they contain data on them that would -- from the SIM card on the cell phone. So a typical directory structure, as we were discussing with a computer or a piece of media -- digital media, it would look differently on the disk.
MR. CHAKRAVARTY: And what's a SIM card?
KEVIN SWINDON: A SIM card is a card that would go into your cell phone that has a unique ID number which would allow you access to -- cellular networks would use it to authenticate your phone onto their networks.
MR. CHAKRAVARTY: Let's go through the spreadsheet now and explain what each of the columns are.
KEVIN SWINDON: The media was a description of the type of media that piece of evidence was. The ID number was the ID number that was assigned typically by the Evidence Response Team appropriate to a search scene. A media description was a simple, short as we could keep it, description of what it was; the location where it came from. The "I" would be where it was imaged. The "P" would be where it was processed. And then we did sort of a synopsis of the file types in that last column there.
MR. CHAKRAVARTY: Let's start with the file types. Can you describe what those file types are?
KEVIN SWINDON: Some of them are abbreviations. But the file type we'd -- the dir would be a directory listing. IH would be internet history. In the first line, iTunes would be -- or iTunes are a backup associated with an iTunes account. Audio or visual files; Adobe files; Word documents; or pictures.
MR. CHAKRAVARTY: For the first one, it says over 500,000 total files. Is that how many --
KEVIN SWINDON: We were trying to get the scope of how voluminous things were, and for particularly 1R6, it was over half a million files associated with that drive.
MR. CHAKRAVARTY: The "P," is that what you said where the item was processed?
KEVIN SWINDON: I'm sorry?
MR. CHAKRAVARTY: What does the "P" stand for?
KEVIN SWINDON: The "P" is where the items were processed.
MR. CHAKRAVARTY: What does the "CP" --
KEVIN SWINDON: "CP" would designate Center Plaza, which is where one of the forensics labs was located; and then "BF" was Black Falcon. And there were some items that actually went directly down to Quantico for processing, and that would be the -- designate the "QT."
MR. CHAKRAVARTY: That appears down here where I'm circling?
KEVIN SWINDON: Yes, sir.
MR. CHAKRAVARTY: Center Plaza, incidentally, is that where the FBI headquarter office is in Boston?
KEVIN SWINDON: One Center Plaza, Suite 600, in Boston, Mass.
MR. CHAKRAVARTY: And the media, it says "C." What does that stand for?
KEVIN SWINDON: "C" would stand for computer.
MR. CHAKRAVARTY: What does "TD" stand for?
KEVIN SWINDON: Would be thumb drive.
MR. CHAKRAVARTY: What does "HD" stand for?
KEVIN SWINDON: Hard drive.
MR. CHAKRAVARTY: And CD?
KEVIN SWINDON: CD-ROM.
MR. CHAKRAVARTY: And "IPOD"?
KEVIN SWINDON: IPods.
MR. CHAKRAVARTY: And "cell"?
KEVIN SWINDON: Would be cell phones or cellular telephones.
MR. CHAKRAVARTY: And "GPS"?
KEVIN SWINDON: GPS devices.
MR. CHAKRAVARTY: With regards to the data that you got for this spreadsheet, was this data that was collected by the -- during the Boston Marathon investigation?
KEVIN SWINDON: Yes. This was from -- what originated from a number of different locations. A chain-of-custody form would contain some of the pieces of information such as the description, the location. The imaging and the processing information would have come from our CART reports. And the file types would have come from a review or a cursory view of what types of files were on that piece of media.
MR. CHAKRAVARTY: Are you familiar with what a log file is?
KEVIN SWINDON: I am.
MR. CHAKRAVARTY: What is that?
KEVIN SWINDON: A log file can be a number of different things, but typically a log file would be a clear text file that would have information in it that would provide a log of activity.
MR. CHAKRAVARTY: Were log files maintained for these -- the devices as well or for some of them?
KEVIN SWINDON: For some of them, yes.
MR. CHAKRAVARTY: Were those put onto the CDs as well?
KEVIN SWINDON: If they were available, they were put onto the CDs, yes.
MR. CHAKRAVARTY: How familiar are you with each of these devices?
KEVIN SWINDON: I'm -- most of the devices, I'm very familiar with because they correspond to a CD with files that were verified. There are several -- one was a -- done a cursory look, and there were several that were actually physically unable to be -- you know, to be processed. So it was just the SIM cards that were processed.
MR. CHAKRAVARTY: Now, does computer forensics allow you to know whose computer some -- a computer device is?
THE COURT: Overruled. You may answer it.
KEVIN SWINDON: There are certain limitations to computer forensics. As we've moved into -- computer forensics has moved into more of a forensic science, we rely on the data that we're able to collect to make determinations of access, determinations of files where they may reside. We also rely on the information that we get from the computer knowing, as we all know, our home computers aren't sometimes the most reliable. They don't always collect all pieces of information that we need. Some of the things can be deleted either through user intervention or deleted automatically through program files or even wiped through applications that you could download on the internet. So we can only rely on what we have, you know, what we collect at the time when we collect it.
MR. CHAKRAVARTY: So in your computer investigations, how do you know who owns a computer?
KEVIN SWINDON: Typically, we would look at a number -- we'd start with a number of areas to look in the computer. When you first turn on your computer and register that computer, your name would be captured, or if you did enter your user name, would be captured in the Window's registry file which is the file within Windows that stores all of the information about that computer, would be one way of identifying who potentially may be using or accessing that computer. In general, internet activity, you may be able to tell who is logging onto your email or an email, who may be using social media or who may be using certain applications to do certain things.
MR. CHAKRAVARTY: So you look at the content of what's on the computer to help figure that out?
KEVIN SWINDON: We need to review the content to determine who would be utilizing it.
MR. CHAKRAVARTY: In addition to the materials on the computer, do you do other investigations outside of the computer forensics in order to make those determinations?
KEVIN SWINDON: Of course. The forensic examiner would provide as much information as he can to the investigative team who then may do additional interviews to determine usage.
MR. CHAKRAVARTY: Is there any limit to how you can determine who was using a computer on a specific day?
KEVIN SWINDON: I guess, barring having a computer over somebody's shoulder and filming them on the keyboard, there are limitations. We sometimes have to make assumptions, or based on internet activity we put together facts based on internet information and the technology.
MR. CHAKRAVARTY: Is it true that sometimes you cannot say, to a degree of certainty, that you feel comfortable as to who was using a computer?
KEVIN SWINDON: That's true, yes.
MR. CHAKRAVARTY: Now, with regards to the devices in this case, can you testify regarding the content of those devices that you did not examine or verify?
KEVIN SWINDON: That are on this list?
MR. CHAKRAVARTY: Yes, on this list or not.
KEVIN SWINDON: Okay. The ones on the list -- the ones that we have CDs for, yes. The ones we do not have CDs for, where several of them there was a cursory look or check done and -- but as far as the scope of the media collected, the over 600, absolutely not.
MR. CHAKRAVARTY: So on this spreadsheet, which of those that you did not do that verification process for?
KEVIN SWINDON: On D385, which is the third "C" down on the computer, the Samsung laptop from -- there was just a cursory look done of the directory structure.
MR. CHAKRAVARTY: Are you aware whose computer that was associated with?
KEVIN SWINDON: I believe, based on the location and other investigative information, that it was Tamerlan's computer.
MR. CHAKRAVARTY: Was there another device that you did not do an in-depth look at?
KEVIN SWINDON: It was the two cell phones that belonged to Azamat and Dias were processed as a different investigation.
MR. CHAKRAVARTY: Okay. Now --
KEVIN SWINDON: I'm sorry. There's just one more. 1V1, the GPS 1V1, I did not process or look at that.
MR. CHAKRAVARTY: Despite the fact that you didn't process or look at those devices, were those examined by the FBI?
KEVIN SWINDON: All pieces of digital media were imaged, processed, and reviewed by somebody on the investigative team for the FBI.
MR. CHAKRAVARTY: In fact, was there an army of analysts who were looking through these things?
KEVIN SWINDON: You could define an army, but, yeah, it was a large team of investigators that looked at or culled through the evidence.
MR. CHAKRAVARTY: Let's start with the 1R6. Does that correspond to the CD labeled Government's Exhibit 1142?
KEVIN SWINDON: Yup, it does. 1142, yes.
MR. CHAKRAVARTY: What computer does that CD contain data from?
KEVIN SWINDON: That contains data from a Sony Vaio laptop that was collected at 69 Carriage Street that investigative, we believe, belonged to Jahar.
MR. CHAKRAVARTY: The computer did?
KEVIN SWINDON: The computer did, yes.
MR. CHAKRAVARTY: Was that processed -- was that imaged at Black Falcon and processed at Center Plaza?
KEVIN SWINDON: It was imaged at Black Falcon, yes, and processed at Center Plaza.
MR. CHAKRAVARTY: And the CD that you have in front of you, does that contain files that were actually on that computer that were imaged near the time that they were seized and then exported onto that CD?
KEVIN SWINDON: It contains files that were identified on that computer by the investigative team, written to the CD, and then verified that they existed on 1R6 along with the other spreadsheets that we had discussed earlier.
MR. CHAKRAVARTY: At this time, your Honor, I'd move into evidence Exhibit 1142.
THE COURT: Let me see you at the side.