SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThe FBI had already uncovered most of the browser history… What they didn't have was a way to tie any of it to the victims or a motive.

Now that Netflix has aired, the same questions keep coming in from media, family, friends, and strangers online:
Easy one first: Nobody paid us. Not Netflix, not the families, not the state of Idaho. We worked this case for free. "We" includes, my husband Jared, and our companies, SANS and Cellebrite. I list our companies because they supported our time, media requests, and all the chaos that came with the case.
In March 2023, I got a call asking if I could get to the FBI Regional Computer Forensics Laboratory (RCFL) in Philadelphia to look at evidence that seemed "off." Their tools weren't showing user activity, and they didn't know why.
A decade earlier, a few people from that same FBI RCFL had taken my SANS FOR585 Smartphone Forensics course in Dallas. We stayed in touch for years. That's how a village in this community gets built. When their tools hit a wall on Bryan Kohberger's phone and PC (I'll call him BK going forward), they wanted another expert opinion. The FBI had already uncovered most of the browser history, VPN activity, and disturbing searches. What they didn't have was a way to tie any of it to the victims or a motive. That's why they called me, in hopes that I would find something they hadn't yet or confirm what they were seeing was odd and help make sense of it.
Jared offered to join, too. Cellebrite backed us on hours. We signed a gag order, which made it hard to lean on other trusted examiners like Josh Hickman, Mattia Epifani, and Ovie Carroll, since we couldn't tell them what we were actually working on.
This case was hard because the data didn't paint an obvious story of motive. Limited conversations. No clear location trail. Minimal app activity. BK's mobile device was eerily quiet and void of normal user activity. That in itself spoke loudly to us.
FOR585 is built on Locard's Principle: Every contact leaves a trace, including digital cleanup. It's just harder to find because tools don't always parse it.
My Cellebrite CTF device (Sharon O'Neil) happened to be the exact same phone model, OS version, and carrier as BK's. That let me recreate the logs we were examining, line by line. That's the part that matters: going past what the tool shows you on the surface.
Jared and I would strategize what we thought happened on the phone, recreate it, extract the data, examine it, compare it, and do it again. Over and over. Josh Hickman did the same on a different device.
We linked his PC to his phone through Google Chrome sync. Most of his browsing was done in Incognito until he returned to Pennsylvania with his father, when he seemed to let his guard down. BK's mistakes helped us. Downloads from Incognito were cleared from his PC but not his Android. Cache files persisted.
Logs showed his phone was at 100% battery when he manually shut it down in the early morning of the murders. We could pinpoint exactly when Wi-Fi was disabled, when the phone was powered off, and when it came back on. The FBI handled cell tower data. We stayed focused on the devices themselves.
So, when you read other stories, keep in mind that many of us had assigned lanes, and we stayed in them.
We never found a motive in plain text. That still sits with me. We wanted to hand the families real answers. What we did find was intentional deletion: an entire missing month of laptop activity and phone gaps everywhere except searches about the case and calls to his parents.
Jared's key point was this: If your alibi is stargazing, your phone needs to be on. If it's at 100%, it didn't die. If you're driving from your apartment after 2 a.m. toward Moscow, you weren't asleep. If you power your phone back on after 4:40 a.m., right after your car is caught on camera fleeing the scene, you weren't out taking photos.
BK was awake. He tried to erase his footprint. He failed.
Multiple tools were used to see if anything was missed below the surface. My stance has always been “trust, but validate,” and that is what we did.
Every log we planned to testify to, we recreated ourselves so we could explain exactly how it was generated. We were ready.
Then BK pled guilty in July 2025.
I thought that was the end of it. Instead came the media frenzy, the "pro-Berger" attacks, and families who felt like answers had been left on the table.
Alivea found me online and reached out. I thought it was a sick prank, but it was really her. Jared and I flew to Idaho and spent nearly three and a half hours with the Goncalves family, one of the hardest conversations of my life.
Steve, Kristi, Alivea, and the rest of Kaylee's family are some of the strongest people I know. We stayed in touch through the media storm, careful not to reopen wounds, and we've honored the four kids murdered on November 13, 2022, every chance we've had since.
I've turned down every interview request about BK's appeal. My rule with media has always been simple: Does this help SANS, Cellebrite, the families, or the DFIR community? If not, I pass.
This case took a real toll, and I'm ready for BK to fade, so Kaylee, Maddie, Ethan, and Xana can be what's remembered. I hope the case holds up and that justice was served. Would I testify to our work? Without hesitation. Data is data, and the absence of it can say more about intent than the data itself ever could.
Everything from this case now lives in my SANS courses, which I co-author with brilliant examiners. FOR585 walks through every log and method we used on BK's Android device. FOR500 covers how his PC deletions and abnormal behavior can be detected.
Every contact leaves a trace, and a digital forensics expert will find it.
I am going to keynote the DFIR Summit and Training 2026 in Arlington, Virginia October 15-16 and will be diving into this case. Join me and other experts for two days of research, case sharing, and amazing hands-on experiences.
Want to read the full story and dive deeper into the digital forensics behind the case? Visit smarterforensics.com/blog to read the full blog.


Heather brings 24+ years of experience supporting government agencies, defense contractors, law enforcement, and Fortune 500 companies. Her extensive case experience spans fraud investigations, crimes against children, counterterrorism, and more.
Read more about Heather Barnhart