EXPERT ASSESSMENT OFFICE & FORENSIC LABORATORY

IT Forensics & Digital Evidence Preservation

Independent forensic investigations and expert reports for the judiciary, solicitors, businesses and private individuals.

LANCologne: Certified assessor of the DGuSV
LANCologne: Certified assessor of the DGuSV
LANCologne: Alliance for cyber security participants
LANCologne: Certified assessor of the DGuSV

Identify digital traces. Secure evidence. Clarify the facts in a transparent manner.

LanCologne is on IT forensics, mobile forensics, digital evidence preservation, forensic data analysis and professional data recovery specialises in. We assist courts, law enforcement agencies, solicitors and defence lawyers, businesses, insurance companies and private individuals with the technical investigation and transparent clarification of digital matters.

Digital evidence now plays just as significant a role in civil and criminal proceedings as it does in internal investigations, cyber incidents, commercial disputes or cases involving suspected data manipulation and data loss. Smartphones, computers, data storage media, cloud services and digital communications may contain crucial information in such cases.

Our role is not to confirm a desired outcome. IT forensic investigations are conducted in an unbiased and transparent manner, based on the digital evidence actually available.

Qualifications and working methods

TÜV Rheinland-certified qualification

The technical basis is a qualification in mobile device and Windows forensics, certified by TÜV Rheinland. Both certifications are listed in TÜV Rheinland’s Certipedia certificate database under the certification mark number 0000067863 available for public viewing.

Since 2015, for courts and public authorities

LanCologne has been providing forensic services throughout Germany since 2015 and has carried out investigations in the fields of criminal and civil law during this time. References are available on request.

Transparent methodology

Original data is protected from alteration, forensic images are created and the processing steps are documented. This ensures that the investigation process and findings remain verifiable by experts – including third parties.

In-house forensic laboratory

Cleanrooms, chip-off and JTAG workstations, Faraday cages and write-blocker stations are available on-site. Mobile devices are secured by being shielded from the mobile network, and data storage media are read in write-protected mode only. Test material is not passed on to third parties.

Neutral and impartial

LanCologne is commissioned by law enforcement agencies and courts, as well as by defence teams, companies and private individuals. Every case and every device requires a bespoke approach – but the standard is non-negotiable: The artefacts relevant to the issue at hand are analysed, regardless of whether they confirm or refute a working hypothesis. The scope and limitations of the analysis are documented. The report also specifies what cannot be determined on the basis of the available evidence.

In-house seminars on mobile forensics

LanCologne shares its expertise through seminars, with a focus on mobile forensics. The seminars are based on practical experience gained from handling forensic cases and teach the methods used in the company’s own laboratory.

Forensic backup of data storage media at the LanCologne laboratory

Investigation and Preservation of evidence

Research into various issues

Depending on the assignment, we examine and secure, amongst other things, smartphones, tablets, computers, hard drives, SSDs, USB storage devices, memory cards, Server, cloud data and other digital systems.

This may involve, for example, the recovery of deleted data, the examination of digital communications, timestamps and metadata, the identification of user activities, the analysis of file systems, or the reconstruction of specific events.

Particular emphasis is placed on the Mobile forensics for iOS and Android devices as well as the forensic examination of Windows, macOS and other IT systems. The investigative methods employed depend on the evidence in question, its technical condition and the specific issue at hand.

Preservation of evidence and transparent documentation

A professional IT forensic investigation begins with the preservation of digital evidence. Where technically feasible and necessary for the investigation in question, the following are carried out: Original data protected from changes and create forensic working copies or images.

Integrity and processing steps are documented so that the origin, security and examination of digital data can be traced. In doing so, we take into account both existing findings and technical limitations, as well as circumstances that cannot be reliably established on the basis of the available data.

Depending on the nature of the assignment, the findings may be set out in technical documentation, a forensic investigation report or an IT forensic expert’s report.

Evidence is stored in a separate, restricted-access area. The handover, storage and return of evidence are documented to ensure that the chain of custody remains traceable. Investigation material is not passed on to third parties. References will be provided on request.

IT Forensics for Your section

Courts

Expert analysis of digital evidence and transparent expert reports on issues of evidence in court proceedings.

Lawyers and criminal defence lawyers

Technical examination of digital evidence, independent expert reports and assessment of the available investigation findings.

The judiciary and public authorities

Forensic data acquisition and analysis for law enforcement and investigative authorities.

The company

Internal investigations, potential data breaches, cyber incidents and the reconstruction of specific sequences of events.

Insurance

Technical investigation of claims, verification of digital evidence and identification of data loss.

Private individuals

Examination of personal devices, securing digital evidence and providing a clear explanation of the findings.

IT forensics seminars

As companies and authorities are increasingly becoming victims of attacks, espionage and manipulation through the exploitation of security vulnerabilities, there is an urgent need to clarify such incidents. Our IT forensics seminars present methods and tools for identifying and extracting traces securely and reliably.

The field of IT forensics offers a wide range of tools. Topics covered include, amongst others, the targeted search for content on large data storage media and in online storage services, live forensics, and the analysis of mobile devices such as smartphones and smartwatches. The specific scope is set out in the seminar programme.

Data recovery specialist in Cologne
Close up of touch pad of a keyboard with only some of the keys in focus. Action. Symbols on a touch pad of a computer, concept of modern technologies.
Team of developers working with computers at office

Our range of services