Back to case studies

The video played at trial wasn't the video in discovery: PowerPoint, transcoding, and normalized audio

Criminal Defense
Updated Jul 27, 2026
7 min read

The situation

In a felony assault prosecution the State intended to prove the defendant threatened someone outside a nightclub. Rather than presenting the original exported surveillance file, the prosecutor embedded video in a PowerPoint containing selected segments, captions, enlarged stills, a shortened audio track, and a timeline. During trial preparation the defense noticed the PowerPoint audio sounded louder and clearer than the discovery copy, and the video looked shorter and smoother.

What the other side said the evidence showed

The State described the PowerPoint video as "the surveillance footage." That description was technically inaccurate — what the presentation contained was a processed derivative several generations removed from the original recording.

A courtroom exhibit can look like the original while being five generations away from it.

Video evidence arrives in generations, and each one can change the exhibit. Generation one is the recording on the surveillance system. Two is the export made by a business owner or officer. Three is the police working copy. Four is the file inserted into a presentation. Five is what actually plays in the courtroom. Nobody has to act in bad faith for the final generation to differ materially from the first — presentation software, conversion tools, and editing applications transform media automatically and silently.

Audio normalization is the change that matters most and gets noticed least. Normalization raises the signal level so quiet speech sounds louder. It also lifts background noise and can make an ambiguous word sound intelligible — which is precisely the problem when the disputed fact is what someone said. The jury hears a version of the audio that is acoustically different from the evidence, and nothing on screen tells them so.

Excerpting compounds it. An 18-minute recording reduced to 46 seconds may be a fair excerpt or may remove the approach, the other participant's statements, and the seconds immediately after the disputed remark. Both can be true at once: the clip is relevant, and the clip is not the context.

What the examination involved

1

Separated the files into generations

Original system recording, the export, the police working copy, the file embedded in the presentation, and the media extracted from playback — then determined which available file was closest to native.

2

Compared codecs and containers

The original export used a proprietary H.265 stream with low-bitrate audio. The embedded file had been converted to H.264 video with AAC audio, changing compression, frame timing, file structure, metadata, and perceived loudness. It was not a bit-for-bit copy of anything.

3

Analyzed the audio waveform

Increased average amplitude, reduced dynamic range, different peak levels, an altered noise floor, and minor clipping in several sections — the signature of normalization, whether applied deliberately or automatically by an intermediate tool.

4

Measured what the excerpt omitted

18 minutes of export against 46 seconds of presentation. The omitted material included the events leading to the confrontation, statements by other participants, the alleged victim approaching the defendant, and several seconds immediately following the disputed statement.

5

Calculated hashes across every version

Each version produced a different SHA-256 value because each is a different digital object. That mismatch proves the files are not identical; on its own it proves nothing about intent.

What the examination found

  • The file played in court was transcoded from the original codec, not copied from it
  • The audio had been normalized: louder, compressed in dynamic range, with a lifted noise floor and minor clipping
  • 46 seconds of an 18-minute recording were presented, with the approach and aftermath omitted
  • Captions had been added that were not part of any underlying recording
  • No version's hash matched any other, because every generation was a distinct digital object
  • The original export remained available and could still be produced

Outcome

An excerpt may still be usable as a demonstrative if the court permits it and the underlying evidence is properly authenticated. What should not survive is the characterization: the presentation version is not the surveillance footage, and the difference between a demonstrative aid and the original evidence is a distinction the record should reflect.

Takeaways for counsel

  • Ask what file is actually being played in the courtroom, and whether it is the same object produced in discovery. Frequently it isn't.
  • Request the native export and play it. If the audio sounds different, that difference is measurable and worth an expert.
  • Normalized audio makes ambiguous speech sound intelligible — dangerous when the disputed fact is what was said.
  • Captions on a video exhibit tell jurors what to hear. Ask who wrote them and on what basis.
  • A hash mismatch between versions is expected, not scandalous. The argument is about what changed and whether it was disclosed, not about the mismatch itself.

Related questions

Does embedding video in PowerPoint really change it?

It can, and often does. Presentation and conversion software re-encode media to formats they play reliably, which changes codec, compression, frame timing, metadata, and sometimes audio levels. The result looks like the source and is a different digital object. That is why the native file, not the presentation, is the thing to authenticate.

Have a case that turns on digital evidence?

Tell us the case, the device, and your deadline. The scoping call is free, and we'll tell you honestly whether an examination is worth it.

Appointed counsel: see our Colorado public defender program.

This case study is illustrative. It is written to show how digital evidence is examined, challenged, and presented in court; it is not an account of any client matter, and any resemblance to a specific case is unintended. The techniques and failure modes described are real. Nothing on this page is legal advice, and no result is a prediction or guarantee of the outcome of any other matter.