04 · Forensic analysis

The DOCX is the primary source. The PDF is a derivative with manipulated metadata.

Six forensic disciplines converge on one conclusion: the document was assembled from multiple sources, and the PDF produced to the defense was not the original.

RSID reconstruction

RSIDs (Revision Save Identifiers) are 8-character hex values Word generates on each save. They create a fingerprint of Forensic how a document was assembled. The DOCX contains 61 unique RSIDs across 415 text-run occurrences, revealing 24 distinct writing sessions—far more than the 7 file saves recorded in metadata.

LayerRSIDParagraphsContent
1 (Foundation)0038001212Building target list & “Overall Goal”
2 (Title)00A71B6D4“Storm the Winter Palace” & timeline headers
3 (Ops core)00F01E999Covert Sleeper, manpower, team structure
4 (Roles)00FC348D10Recruiter, Covid instructions, preparation
5 (Distract)0056613C11Fire alarms, “we OWN!!” section
6 (Slogans)00CC59894“Free and fair elections” chants
7 (Demands)00B16F186Paper ballots, election demands
8 (Formatting)007864A817Section headers across all pages (rsidRPr=226)
9 (Logistics)00A777F721Patriot Plan logistics, building templates
10 (Title late)00C730B71“1776 Returns” — late insertion

Interactive RSID viewer

Three RSID layer visualizations showing the document’s RSID clusters at progressive stages, plus an animated reconstruction.

RSID layer visualization

Figure 1 — Early RSID layer (partial structure)

PDF vs. DOCX: a comparison

Native DOCX

  • Author metadata: Eryka Gemma
  • Created: Dec 30, 2020, 02:48 UTC
  • 24 RSID editing sessions preserved
  • Grammarly DocId and SessionId embedded
  • Three embedded PNG images + HD Photo
  • 125-minute editing window recorded

Rasterized PDF

  • No author, creator, or producer metadata
  • Created: Feb 8, 2022 (13 months later)
  • All RSID and construction history destroyed
  • No Grammarly artifacts survive
  • 9 JPEG page images at 200 ppi
  • ModDate identical to CreationDate (scrubbed)

Object-level PDF findings

Page 7 of the PDF is encoded differently from the other eight pagesForensic:

  • Pages 1–6, 8–9: JPEG (DCTDecode) at 70–152K each
  • Page 7: Lossless deflate (FlateDecode) at 289K, with Interpolate=false
  • Page widths vary: 1344–1346 px (batch 1), 1263 px (page 6), 1277 px (page 7), 1309 px (page 8)

This proves multi-source assembly: at least two different image production methods were used to build this PDF. Page 7 was inserted from a different source or tool.

Font & style analysis

The DOCX uses Forensic only system fonts (no embedded fonts): Arial (79.8% of 746 text runs), Times New Roman (10.2%). The document uses no custom heading styles—231 paragraphs use inline formatting. This is consistent with content pasted from multiple sources and rapidly assembled without document templating.

Image inventory

ImageDimensionsFormatContent
image1.png1280×777PNG RGB, 96 ppiLikely map or header graphic
image2.png750×1000PNG RGBA, 96 ppiTall portrait orientation
hdphoto1.wdp750×1000HD Photo (WDP)Compressed duplicate of image2.png
image3.png2113×1362PNG RGBA, 192 ppiRetina-class, likely map (page 9)

No EXIF/GPS data in any image. All are clean PNGs derived from screenshots, not camera originals.

61 unique RSIDs · 24 editing sessions · 3 image formats · 6 forensic passesNext: Authorship →