LanCologne’s laboratory in Cologne, equipped with an electronics workbench, a digital microscope and a soldering fume extraction system

About us · Laboratory

Our IT forensics laboratory in Cologne

LanCologne operates its own laboratory in Cologne specialising in IT forensics, mobile forensics and data recovery. The photographs on this page were taken in this laboratory. They show the work areas where we secure digital evidence, examine devices and recover data from damaged storage media.

Request a survey

The laboratory at a glance

  • Location: Horbeller Str. 31, 50858 Cologne
  • Areas of work: Forensic backup of data storage media, mobile forensics, examination of electronic components and hardware, data recovery at the cleanroom workbench
  • Services provided on this basis: IT forensics, mobile forensics, data recovery, scanning smartphones for malware, expert reports
  • Responsible: Risto Popovski, IT forensics expert with TÜV Rheinland certifications (IT Forensic Windows Expert, IT Forensic Mobile Expert, valid until 02/2027) – Reference on Certipedia

Forensic backup of data storage media

As a rule, a forensic investigation begins with the creation of a backup. Where technically feasible, the original data carrier is protected against write access and a forensic backup is first created. Further analysis is then generally carried out on the basis of this backup or a working copy created from it.

Why write protection is important for original data media

Simply connecting a storage device to a standard computer can alter data. For example, the operating system creates files or updates timestamps. We therefore use hardware write blockers for supported storage media. These allow read access whilst preventing unintentional write access to the original medium that is connected. This makes it possible to verify later which version of the data the investigation is based on.

Controlled backup and integrity checking using hash values

Specialised forensic imaging systems are available for the backup process. We calculate hash values for each backup. This is a kind of digital fingerprint: even the slightest change to the data results in a different value. If the hash values match, this proves that the copy under examination corresponds to the backed-up data.

Find out more: Windows Forensics · Writeblockers in Linux forensics

OpenText Forensic Bridge hardware write blocker and Logicube Falcon NEO imaging system on the lab bench
Hardware write blocker and imaging system for read-only backups of supported storage media.

Mobile Forensics Workstation

We examine smartphones and tablets at a dedicated workstation in the laboratory.

Two monitors running Cellebrite Inseyets: on the left, the platform selection screen for extraction; on the right, the analysis view
Workstation with data extraction and analysis software for mobile devices. Screen content has been obscured.
MEFF M3 Pro for scanning smartphones for malware, alongside a tablet with the MEFF interface
A workstation for testing Android and iOS devices for malware.

Why there isn’t a single method that works for all smartphones

The data that can be recovered depends on several factors: the manufacturer and model, the operating system version, the security status (locked or unlocked, encrypted) and the specific issue at hand. Depending on the initial situation, different extraction and analysis methods may therefore be considered. For each investigation, we document which method we use and what its limitations are.

Malware scanning and monitoring

If spyware, stalkerware or other malware is suspected, we scan Android and iOS devices using specialised analysis systems. A clean result does not mean that a compromise can be ruled out. That is why we explain the significance of each result.

Find out more: Mobile forensics · Have your smartphone checked for malware · Mobile Malware Analysis

Electronics and hardware testing

If a device can no longer be read normally

Water damage, breakage, faulty components or a device that no longer starts up: in such cases, it is often not possible to back up data via the standard ports. In such instances, work must first be carried out on the hardware to make it possible to retrieve the data at all.

Microscopy, soldering and rework techniques

Many components on modern circuit boards can only be reliably assessed and worked on under magnification. The electronics workstation is equipped with a digital microscope, soldering and rework equipment with solder fume extraction, and ESD-protected work surfaces. The ESD surfaces protect sensitive electronics from electrostatic discharge.

Electronics workstation with a digital microscope, soldering station, soldering fume extraction system and ESD mats
Electronics workstation for testing circuit boards and memory modules.
A digital microscope positioned above an ESD work mat, alongside tweezers, a multimeter and a precision tool
Components, solder joints and damage become visible under the microscope.
A dismantled smartphone and a removed circuit board in a dust-proof workstation
Damaged smartphones are opened in a dust-proof workstation.

Hardware-based access methods: JTAG and chip-off

If a device cannot be accessed via its normal connections even after hardware modification, hardware-based methods may be considered. With JTAG, the memory is accessed via test and inspection connectors on the circuit board; with chip-off, the memory chip is desoldered and read out using a programmer. We carry out both procedures at our electronics workstation. Whether they are appropriate depends on the device, the memory architecture and the security mechanisms in place. In many modern smartphones, the data is encrypted and tied to the device’s hardware. Memory read directly in this way may provide raw data, but not necessarily usable user data. We will discuss with you beforehand whether such a method is likely to be successful in your specific case.

Workbench with ultrasonic cleaner, XELTEK SuperPro chip programmer, multimeter and SATA adaptors
Tools for working on memory modules and storage device electronics.

Data recovery at the cleanroom workbench

Some work on data storage media must be carried out in a dust-free environment. A cleanroom workbench is available in the laboratory for this purpose. It supplies the work area with air that has been purified by a Class H14 HEPA filter. According to EN 1822, filters of this class remove at least 99.995% of the particles in the size range that is most difficult to filter out. This is a controlled workstation for open data storage media and sensitive electronic components, not a classified cleanroom.

We then examine damaged storage media at our analysis workstation using specialised data recovery software.

Find out more: Data recovery in Cologne

Cleanroom workbench with filter unit and ESD work surface for data recovery
Cleanroom workbench for tasks where data storage media must be protected from dust.
Analysis workstation with an ultrawide monitor: data recovery software displaying a sector map of a storage medium
Analysis of a data carrier at the analysis workstation. Screen content has been obscured.

Handling of investigation material and evidence

In investigations relevant to evidence, it is not only the result that counts, but also the process leading up to it. Depending on the brief, we document, amongst other things:

  • Receipt and condition of the test samples
  • Handover and processing stages (chain of custody)
  • the security procedures used
  • Hash values or integrity checksums of the backups

The material under investigation remains under our control throughout the entire process. We do not pass it on to third parties. We provide every client with a written non-disclosure agreement (NDA), regardless of whether they are a private individual, a company, a law firm or a public authority.

Find out more: Expert report on smartphones

What this means for your examination

  • Private individuals: Equipment and data are processed in our own laboratory, not by various service providers. IT Forensics for Private Individuals
  • Solicitors and criminal defence lawyers: Backups with write protection and hash values, together with documented procedures, ensure that findings can be verified. IT Forensics for Lawyers
  • Company: Data storage media, computers and mobile devices involved in an incident can be secured and examined in one place. IT Forensics for Businesses
  • Public authorities and courts: Documentation, transparent procedures and the integrity of the evidence are of paramount importance. Services for public authorities

Frequently asked questions about the laboratory

Will my devices be passed on to external laboratories?

No. We do not pass on test samples to third parties. They remain in our laboratory in Cologne throughout the entire processing period.

Will I be given a confidentiality agreement?

Yes. We provide every client with a written confidentiality agreement (NDA).

Can I hand in equipment in person at the laboratory?

Yes, by prior appointment. Alternatively, we can post the items.

Can data be read from any device?

No. Whether and to what extent a backup can be made depends on the device, its condition and its security status. We will clarify this before the examination begins.

Why are you showcasing your laboratory?

So that you can see, before placing your order, where and how your test samples will be processed.

Request a survey

Please give us a brief description of the device and the issue. We’ll let you know what steps make sense and where the technical limitations lie.

Request a survey