The Floppy Disk That Caught a Serial Killer
Why the Best Investigations Go Beyond Digital Forensics
Hey there, and welcome to Eye on the Case - our monthly brief where we take a closer look at how investigators work, what makes certain cases successful, and one interesting fact you’ll want to know to stay sharp.
Each month, we’ll pick one core topic and break it down through a wild fact, an educational deep dive, and a practical workflow.
For our very first edition, we are looking at Digital Forensics and why looking at a single device extraction is never enough.
📂 Case Spotlight
Long before modern smartphones became evidence goldmines, digital forensics experts were already tracing criminals through forgotten metadata and deleted files. Remember floppy disks? The original “save” icon.
For more than 30 years, the “BTK Killer” evaded law enforcement while taunting police and the media with letters, packages, and cryptic messages. Dennis Rader believed he was smarter than investigators — and his ego ultimately became his downfall.
In 2005, Rader mailed a purple floppy disk to a Wichita TV station.
Police found metadata embedded in a deleted Microsoft Word document that was, unknown to Rader, still stored on the floppy disk. It was a church meeting agenda written and edited by Rader himself. The metadata contained the words “Christ Lutheran Church” and the document was marked as last modified by “Dennis”.
Although the metadata provided the first real lead in decades, it was not enough to arrest Rader. Investigators used additional evidence — including a vehicle linked to the case and a familial DNA match from a relative — to build enough probable cause for his arrest.
💡 The Lesson:
Digital forensics has been around for decades. Long before smartphones and cloud data, investigators were already recovering hidden evidence from disks, deleted files, and metadata.But digital evidence alone rarely closes a case.
In the BTK investigation, the floppy disk metadata was only the beginning. Investigators combined it with old case evidence, field intelligence, surveillance, vehicle information, and DNA analysis.
That correlation is what solved the case.
The real power of forensics is not just extracting data — it’s connecting it to the bigger investigative picture.
👉 Continue reading the official historical case breakdown here
⚡Tradecraft
The Operational Blindspot: From Device Dumps to Investigation Engines
Sticking to our forensic theme:
Detective Ray finally gets the phone dump back.
Thousands of messages. Call logs. GPS points. Selfies.
The extraction worked perfectly.
But two hours later, he’s still stuck.
One screen has the forensic dump open.
Another is running Telegram searches.
And across the room, Diane is still tracing financial transactions line by line in a spreadsheet.
Now Detective Ray is trying to figure out whether a recovered contact matches an active target from another case.
This is where investigations slow down.
Not because of missing data.
Because the data lives in separate places.
A phone dump alone is just raw evidence.
The real breakthrough happens when forensic data connects with external intelligence sources, timelines, maps, and entity analysis—all in the same workflow.
That’s how isolated artifacts become actionable intelligence.
Just like peanut butter and jelly, some things just work better when they’re together.
We broke down this exact workflow in our latest guide.
👉 Read the full article: From Device Dump to Investigation Engine
⚙️ Falkor in Action
Inside the Lab: Introducing Falkor Forensic Studio
To fix this exact blindspot, we’re introducing a new capability within our platform: Forensic Studio.
Falkor is already your all-in-one investigation hub—where you launch OSINT queries, run deep analytics, and manage entire cases. Now, we are bringing digital forensics into that exact same ecosystem. No more hopping between fragmented software; you can now centralize your entire lifecycle in one place:
All-in-One Forensic Management: Centralize device extractions, manage chat flows, location data, and call durations seamlessly alongside your active cases.
Instant OSINT & Data Fusion: Automatically cross-reference extracted phone numbers, emails, or entities with external OSINT sources and legacy intelligence instantly.
From Lists to Link Analysis: Turn a massive dump of fragmented evidence into interactive entity graphs and weekly activity heatmaps on a single canvas.
From evidence to intelligence. Break down silos and keep your entire investigation workflow in one place.
🌍 Want to see the new Forensic Studio in action? If you are heading to Prague next week for ISS World Europe (June 2–4), come by Booth # G5. 👉 Book a live demo with us at the booth
Ari Ben-Am will speak on how digital forensics can be fused directly into the investigative workflow to help combat national security threats.
Join us at Lounge 16
Tuesday, 2 June · 9:30 AM
You might already know Ari from his newsletter, Memetic Warfare


