IT forensics · Investigative authorities
Wie werden Hintergrundprozesse als alternative Erklärung für Dateizugriffe geprüft?
Indexierung, Antivirus, Backup oder Synchronisation können Dateien lesen, ohne dass ein Benutzer sie öffnet.
Why this question is important to the investigating authorities
In advanced investigative questions, the issue is rarely simply whether a particular artefact exists. What is crucial is whether the technical interpretation is robust, what alternative hypotheses exist, and which conclusions must not be drawn from the available data.
Technical investigative approach
Wir prüfen Prozesskontext, Systemdienste, Zeitbezüge und weitere Nutzungsspuren.
Where the limits of what can be said lie
Ein Dateizugriff allein beweist nicht bewusste Kenntnisnahme durch einen Benutzer.
Why LanCologne?
LanCologne is not used in complex criminal investigations to confirm an existing line of inquiry as effectively as possible. Its purpose is to examine a specific technical issue independently and to assess both incriminating and exculpatory findings using the same professional standards.
The data set is clearly documented. Where technically feasible, the analysis is carried out on verified backups or suitable working copies. In the case of findings relevant to decision-making, we do not rely solely on automatically generated reports. The origin, the logic behind the data generation and the system context are checked; where necessary, validation is carried out using the primary data or a second, technically appropriate method.
Particularly in complex cases, it is crucial to distinguish between device-related, account-related and session-related factors, user actions and natural persons. A distinction is also made between positive identification, mere compatibility, lack of evidence and technical exclusion.
The results are documented in such a way that investigators and prosecutors can understand the key findings without requiring specialist forensic knowledge. At the same time, the technical basis is documented in a way that allows it to be reproduced for subsequent review by other forensic experts, the defence and the court.
From the investigation brief to a reliable statement
Incriminating, exculpatory and inconclusive findings
The investigation remains open-ended. If several reliable sources support a hypothesis put forward during the investigation, the technical relationship between them is explained. If there are contradictory findings or a technically plausible alternative explanation, these are documented on an equal footing. If the data available is insufficient, the fact that no evidence has been found is explicitly stated.
Reproducibility and subsequent judicial review
The key findings are presented in a way that is clear to investigators and prosecutors. At the same time, the technical principles relevant to the investigation are documented in such a way that another qualified IT forensic expert can verify the key findings using the same data set. This facilitates subsequent enquiries, cross-checks and any potential court proceedings.
LanCologne as an independent external IT forensics expert
When a criminal investigation authority needs to have a complex digital issue examined in depth, independently or in a way that can be replicated, LanCologne provides support through an objective and unbiased investigation. The focus is on providing a robust answer to the specific investigative question – including counter-findings, limitations on conclusions and technical verifiability.
Legal framework
The responsibility for conducting the investigation and making legal assessments remains with the competent law enforcement authorities. Under Section 160 of the Code of Criminal Procedure (StPO), the public prosecutor’s office investigates the facts of the case and is required to establish both incriminating and exonerating circumstances. Section 161 of the Code of Criminal Procedure (StPO) governs the public prosecutor’s office’s general investigative powers; Section 163 of the Code of Criminal Procedure (StPO) sets out the police’s duties during the preliminary investigation.
In principle, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. Under Section 161a(1) of the StPO, experts are required to appear before the public prosecutor’s office when summoned and to deliver their expert report. Section 82 of the Code of Criminal Procedure (StPO) governs the form in which expert reports are to be submitted during the preliminary proceedings. Section 78 of the Code of Criminal Procedure (StPO) concerns the judicial supervision of the expert’s work, insofar as such supervision is applicable.
Seizure and confiscation are governed in particular by sections 94 and 98 of the Code of Criminal Procedure. Section 110(3) of the Code of Criminal Procedure concerns the examination of electronic storage media and the securing of data that may be relevant to the investigation. Decisions on the admissibility, scope and ordering of official measures are taken exclusively by the competent law enforcement authorities and courts.
Under Section 1(3) of the JVEG, engagement by the police or other law enforcement authorities on behalf of, or with the prior approval of, the public prosecutor’s office is treated as equivalent to engagement by the public prosecutor’s office for the purposes of remuneration.
Frequently Asked Questions
LanCologne – IT Forensics for Criminal Investigation Authorities
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.