IT Forensics · Car

Warum LanCologne in der Car-Forensik auf generische Standardwerkzeuge setzt

LanCologne setzt für die Fahrzeug-Forensik bewusst keine dedizierte, herstellerspezifische Extraktionshardware wie proprietäre Infotainment- oder Steuergeräte-Ausleselösungen ein, sondern etablierte, breit einsetzbare forensische Standardwerkzeuge.

Enquire without obligation

This point is particularly important when it comes to vehicles, as manufacturers, model types, software versions and the storage and transmission formats used can vary considerably. A conventional petrol or diesel car, a modern electric vehicle and a commercial vehicle fitted with a tachograph cannot be treated according to the same technical approach. The storage location, data format, encryption and connectivity determine which data is accessible and which backup method causes the least disruption.

Dieser Ansatz ermöglicht eine einheitliche, nachvollziehbare Vorgehensweise über verschiedene Fahrzeughersteller hinweg, statt sich auf einzelne, teils nicht flächendeckend verfügbare Speziallösungen zu verlassen.

Why LanCologne?

LanCologne does not investigate digital traces relating to vehicles according to a blanket standard procedure, but rather on the basis of the specific vehicle type, the available data sources and the evidence at issue. Our staff have decades of experience in information technology and many years of practical experience in IT forensics. We assist companies, solicitors and private individuals, as well as regularly supporting courts and public authorities, in the technical investigation of digital matters.

The investigation is generally carried out on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence is either left unchanged or, where technically unavoidable alterations have been made, these are transparently documented and the evidence is stored in a manner that preserves its integrity.

Our working methods and the tools we use

Our investigation does not begin by launching an analysis programme, but by gathering evidence. The vehicle, its on-board systems, its visible condition and any connected mobile devices are documented. A decision is then made as to which data sources are accessible and in what order they are to be backed up.

The next step is to define the backup strategy. In doing so, we distinguish between whether data is accessible via removed storage media, via a standard diagnostic interface, or via a mobile device connected to the vehicle. The choice depends not on convenience, but on the vehicle type, data format, availability and the specific issue to be established. Where technically possible, we work in read-only mode; any unavoidable changes to the data’s state are explicitly logged.

The backup created is documented using hash values. The actual analysis is not carried out on the original, but on a working copy or a verified forensic image. This allows searches or specific analysis steps to be carried out without continuously altering the original evidence.

Wir werten Speichermedien, verbundene Mobilgeräte und gängige Datei- und Datenbankformate mit unseren etablierten forensischen Werkzeugen aus, insbesondere Belkasoft X und X-Ways Forensics, statt mit dedizierter Fahrzeug-Extraktionshardware.

For a reader unfamiliar with the subject, one point is particularly important: a forensic programme does not automatically „find" the truth. It reads data structures and interprets them according to known rules. If a new software or system version changes a data format, an automated analysis may produce incomplete or incorrect results. That is why, in the case of crucial findings, we check which file or data structure the result originates from and whether a second technical approach confirms the same findings.

We deliberately do not use any dedicated vehicle data extraction hardware, such as proprietary infotainment or ECU readers. Instead, we analyse storage media, connected mobile devices and common file and database formats using our established forensic tools, in particular Belkasoft X and X-Ways Forensics. Where manufacturer-specific, undocumented ECU or infotainment formats prevent a fully automated analysis, we manually examine the accessible raw data and transparently document any technical limitations, rather than claiming an unsubstantiated finding.

Typical areas of application

Judicial and non-judicial expert reports
Preservation of evidence from vehicles, storage media and connected mobile devices
Study of different vehicle types and manufacturer platforms
Investigating accidents, theft and allegations of tampering
Analysis of driving, media, app and system artefacts
Reconstruction of travel routes, usage times and access times
Cross-checking of automated analysis results
Analysis of deleted, historical or only indirectly visible traces
Documentation for courts, solicitors, insurance companies, public authorities and businesses

This is how the forensic investigation is carried out

1Collection of evidence and documentation of the condition

The vehicle, its systems and, where applicable, any connected mobile devices are first clearly identified and documented either photographically or in writing. We record the physical and electronic condition in which the vehicle was found. This information may prove crucial later on.

2Technical classification

The manufacturer, model, installed systems and their software versions are identified. Only then can it be determined which data is generally accessible and which backup method is appropriate.

3Secure storage that preserves evidence

The backup process is carried out in such a way that the original state is altered as little as possible. Depending on the circumstances, accessible storage media are read in write-protected mode, connected mobile devices are backed up separately, and available cloud data is captured with the authorised person’s consent. Every step is logged.

4Integrity check

Any images or copies created are given unique names, assigned hash values and verified. Analysis and searches are then carried out exclusively on working copies.

5Multi-stage evaluation

Existing data is analysed in a structured manner using our established forensic tools. Where standard software does not fully support a particular format, this is documented rather than being tacitly ignored.

6Manual validation

In the case of findings that are particularly relevant to the evidence or unusual, we manually check the raw data, file structures and metadata to rule out any automated misinterpretations.

7Report and reference to evidence

At the end, we do not merely list what could be gleaned from the data. We explain the technical source on which the findings are based, what conclusions can be drawn, and where the limitations lie.

Why is this area of investigation relevant to forensics?

LanCologne setzt für die Fahrzeug-Forensik bewusst keine dedizierte, herstellerspezifische Extraktionshardware wie proprietäre Infotainment- oder Steuergeräte-Ausleselösungen ein, sondern etablierte, breit einsetzbare forensische Standardwerkzeuge.

The forensic value lies not solely in the volume of data found, but in its origin and reliability. A file name, a timestamp or a log entry can be misleading without context. That is why we document how an artefact may have come into being, what alternative explanations exist and what further evidence supports the findings.

Dieser Ansatz ermöglicht eine einheitliche, nachvollziehbare Vorgehensweise über verschiedene Fahrzeughersteller hinweg, statt sich auf einzelne, teils nicht flächendeckend verfügbare Speziallösungen zu verlassen.

Particularly in the case of vehicles, attempts to carry out a comprehensive technical analysis may also reach their limits if manufacturers use proprietary, unpublished data formats. A lack of documentation, encrypted memory areas and manufacturer-specific cloud connections highlight why it is so important to carry out a professional backup and to communicate existing limitations transparently before the actual analysis begins. Errors made at this stage cannot always be rectified later on.

Frequently Asked Questions

Do you use specialist vehicle forensics hardware such as Berla iVe or Bosch CDR?+
No, we deliberately do not use dedicated vehicle data extraction hardware; instead, we analyse accessible storage media, connected mobile devices and file formats using our established forensic tools. Where proprietary, undocumented ECU formats prevent a complete analysis, we communicate this transparently.
Which tools do you actually use?+
For our analysis, we primarily use Belkasoft X and X-Ways Forensics, which offer extensive support for storage media, mobile devices and common file and database formats.
Can you carry out a full assessment of every vehicle model?+
No. The scope of the analysis depends on the manufacturer in question, the control unit and infotainment formats used, and the relevant documentation. Any existing technical limitations are clearly stated in the report.
Why don’t you analyse the original control unit directly?+
Because analysis software and data extraction processes can alter data. The actual analysis is therefore always carried out on a verified forensic copy or on the basis of a duly documented data extraction process.
Is it always possible to carry out a full analysis of the control unit’s data memory?+
No. Encryption, proprietary formats or a lack of access to certain control units may impose technical limitations. Such limitations are openly documented.
Do you also analyse data from smartphones paired with the vehicle?+
Yes, provided they are available and the necessary authorisation has been granted, as paired mobile devices often contain additional usage data that is not stored in the vehicle itself.
How do you deal with different manufacturer formats?+
We assess on a case-by-case basis which data formats are available and which of our tools can be used to analyse them. Unsupported, proprietary formats are documented as such.
How do you explain the results to non-technical people?+
We do not merely describe raw technical data; we also explain what an artefact signifies, how it may have arisen, and what conclusions can actually be drawn from it.

LanCologne – Vehicle IT Forensics, Cologne

Sie benötigen eine professionelle Untersuchung zu „Warum LanCologne in der Car-Forensik auf generische Standardwerkzeuge setzt"? LanCologne unterstützt Sie bei der beweissicheren Sicherung, mehrstufigen Auswertung und nachvollziehbaren Dokumentation digitaler Spuren im Zusammenhang mit Fahrzeugen. Entscheidend ist dabei nicht, möglichst viele automatische Treffer zu erzeugen, sondern technisch belastbare und überprüfbare Beweise zu sichern.

Get in touch now