The Idaho Murders: Remembering Kaylee, Xana, Maddie, and Ethan

Now that Netflix has aired, the questions and media requests are flowing in. Here are the ones I hear most:

1. Why did we get this case?
2. Did we find his motive?
3. Will we be called back again if he gets a trial?
4. Did Netflix pay us, and how much did we make on the case over 1.5 years?

Let me start with the easy ones. Netflix did not pay us, nor did the families or the state of Idaho. We worked the case for free. “We” includes me, my husband Jared, and our companies, SANS and Cellebrite. Sometimes it’s important to offer help on investigations where digital evidence matters. That’s what we did with Idaho, and it’s why building a village of people around you matters. We should be doing digital forensics for the right reasons: to uncover the truth.


Why did we get this case?

I will never forget the call I got in March 2023, asking if I could come to the FBI RCFL in Philly to look at some evidence that seemed “off.” They didn’t understand why the tools weren’t showing them much user activity. Where was it? Was it the right device and computer? And was I available? Yes. If you know me, I say yes to far too many things. I’m grateful I said yes to Mike A. and Jeff T. that day.

You may be asking again, why me? A decade before the Idaho murders of Kaylee, Maddie, Ethan, and Xana, a few people from the FBI RCFL took my SANS FOR585 Smartphone Forensic Analysis course, taught by me and Lee Crognale, in Dallas. I exchanged information with them that day, visited their office for SANS and my day job at ManTech, and built real professional friendships over the years. That’s how you start building your village. Mike A. knew he could call me because I wrote the course on smartphones. I remember him saying something like, “if you can’t find it, maybe it’s not there.”

They also had a PC belonging to Bryan Kohberger (I’ll refer to him as BK going forward). The FBI had already found most of what you’ve heard about in the news: the browser searches before his arrest, the VPN activity, the selfies, the fascination with serial killers. They referenced both our FOR500 and FOR585 books and did their due diligence, but they couldn’t tie any of it to the victims or a motive. That’s why they called me.

Jared was driving up to see me and said he’d help if I wanted him to. I said yes, and the FBI agreed. Two experts for the price of zero is hard to turn away. Cellebrite was fantastic about supporting us on hours while we worked the case. We immediately signed a gag order stating we couldn’t discuss the case with the media or anyone outside the investigation. This made it hard to lean on other trusted examiners like Josh Hickman, Mattia Epifani, and Ovie Carroll, since we couldn’t tell them what we were actually working on.

Not to give BK any credit, because anyone can Google how to clear their digital forensic footprint, but this case was tricky. When the data doesn’t clearly paint the story through conversations, locations, and app usage, our job gets a lot harder. The core foundation of FOR585 is Locard’s Principle: every contact leaves a trace. That includes digital cleanup. It’s just harder to find because most tools don’t parse it. The logs track everything. We just had to find them.

Unlucky for BK, my Cellebrite Capture The Flag (CTF) device using the alias, Sharon O’Neil, was the exact model, Android OS version, and carrier (AT&T) as his phone. That meant I could attempt to recreate the logs Jared and I were examining, and I did. This is what matters: going beyond what the tools show you on the surface. It’s why the RCFL called me. They know how my brain works, and they knew I’d put in every effort to piece together what happened on BK’s phone and PC the day the four students were murdered in Idaho. Jared and I did that with the FBI.

We were able to link his PC to the phone through Google Chrome sync. Most of the browsing activity was done in Incognito mode until after BK returned to Pennsylvania with his father. He seemed to let his guard down after that. Netflix covered this, as did 20/20 and other outlets. Where he made mistakes that helped us: downloads from Incognito browsing were cleared from his PC but not from his Android device. We found those. Cache files persisted. And the logs showed his phone was at 100% battery when he manually powered it down in the early morning hours before the murders. We could pinpoint when WiFi was disabled, when the phone was manually shut down, and when it was powered back on. The FBI handled all of the cell tower logs and tower location data. Jared and I didn’t touch that side. We focused on what existed on the phone and laptop themselves with guidance from the investigative team. Everyone had their role. We all stayed in our lanes.

Motive

We never found BK’s motive in plain text on his phone or laptop. That still haunts me. I was hoping to give the victims’ families real answers. Why their kids? Why that house? Why that night? Jared was a huge source of support for me through this case. I tell him often that I love working with him, and that I’m grateful he understands the weight we carry mentally on cases like this. I can’t imagine getting through the trial prep and stress of this case without him beside me. He’s a key pillar in my village.

While we didn’t find the motive, we did find intentional deletion and masking of a digital footprint. The laptop was missing an entire month of user activity leading up to the murders. The phone had gaps from a few days before to a few days after, aside from searching news about the murders and contacting his parents.

When your alibi is that you were out stargazing and taking photos, your phone needs to be on. When your phone is at 100% charge, you can’t claim the battery died and that’s why it was off. You can’t say you were asleep when you were wide awake and driving from your apartment after 2 a.m., headed toward Moscow. You can’t say you were off stargazing when you suddenly power your phone back on after 4:40 a.m., after your car was caught on camera fleeing the victims’ home, and you take the long way back to your apartment. BK was awake. He was trying to erase his digital footprint. And he failed.

Validation is everything

Some call it verification, some call it validation. For us, it was both. If one tool showed something, what did another tool show? If a log showed something, how was it created? We recreated every single log we were prepared to testify to. We were ready to explain, in detail, what those logs meant and how they came to exist. We were ready. Then BK pled guilty in July 2025. Yes, almost a year and a half after we joined the case.

When BK took the plea, I thought our job was done. I had no idea the media frenzy that was about to follow. I didn’t expect the “pro-Berger” crowd to come after us, and I didn’t expect how much the families would feel like answers had been left on the table. Jared and I flew out to Idaho to meet with any of the families who wanted to talk. We sat with the Goncalves family for almost three and a half hours, answering their questions and learning who the victims really were. It was one of the toughest conversations of my life. Steve, Kristi, Alivea and their entire family are lovely people. I cherish the relationship we’ve built with them, and I think about them every day as they face life without Kaylee.

Jared and I stayed in touch with them throughout the media frenzy, careful never to reopen wounds. They asked us to honor the kids murdered that morning of November 13th, and we did, and still do, every chance we get.

The July 2026 appeal to remove the guilty plea

I’ve been asked to appear on the news about BK’s appeal, and I’ve turned it down. What else is there to say? I promised myself I’d do media only if it would educate other DFIR practitioners, parents sending their kids off to school, teens learning about online safety, or add real value to the case. Every time an opportunity comes up, I ask myself one question: is this helping SANS, Cellebrite, the families, or the DFIR community? If the answer is no, I pass. Someone else will take it.

This case was mentally exhausting, and I’m ready to let BK fade and let the memory of Kaylee, Maddie, Ethan, and Xana be what prevails. The courts will decide what happens with the appeal, not much I can do. I hope the case is as airtight, and that justice was served. Would I testify to my own work? One hundred percent. Data is data, and the absence of it can be the loudest signal of intent there is. Sit with that for a second: why was the data deleted? When was it deleted? And why did a suspect go to such lengths to keep digital evidence off his device in the first place?

What’s next

I’m retiring. Kidding. Everything I learned from this case now lives in my SANS courses that I co-author with other brilliant examiners. We walk through every log and every methodology we used on his Android in FOR585. Josh Hickman and I purposely write CTF questions for Cellebrite focusing on key details like battery percentage, how devices, were powered down, when data was cleared. In FOR500 Windows Forensic Analysis, we break down how his deletions and abnormal behavior on the PC can be detected.

I am going to keynote the DFIR Summit in Arlington, VA Oct 15-16th and will be diving into this case. Join me and other experts for two days of research, case sharing, and amazing hands-on experiences. https://go.sans.org/y3DazG

Remember: every contact leaves a trace, and a digital forensics expert will find it.


Leave a Reply

Your email address will not be published. Required fields are marked *