IT Forensics · Courts

Can access to a file be proven even though the file remained unchanged?

A file can be read or viewed without its contents being altered.

Enquire without obligation

For the court, it is not a question of how many analysis programmes were used. What matters is which specific technical fact can be reliably established from the available data, how this finding is reached, and what its limitations are.

The specific question of evidence

We analyse usage, application, file system and cache artefacts, taking into account the system’s specific logging logic.

Why a single digital trail is rarely enough

Digital artefacts are generated in systems with their own storage, synchronisation and logging mechanisms. A single timestamp, log entry or database value is therefore not treated as conclusive evidence without context. Where the question of evidence requires it, several independent traces are correlated and technically plausible counter-hypotheses are examined.

Where the limits of what can be said lie

An unchanged hash value proves that the content is identical, but on its own does not indicate whether the file has been opened or read in the meantime.

How LanCologne tackles the question requiring proof

At LanCologne, a forensic IT investigation begins by addressing the question of evidence, rather than by selecting a specific analysis programme. The first step is to clarify which technical facts are to be established, which data sources are actually relevant for this purpose, and which alternative hypotheses need to be taken into account.

The evidence and source data are clearly documented. Where technically feasible, the analysis is carried out on verified forensic backups or suitable working copies. Matches relevant to the decision are not accepted solely because they are displayed by software. The origin, logic behind its creation and context of the artefact are examined; key findings are verified, where necessary, against the underlying data or using a second, technically appropriate method.

In the expert report, the findings of fact, technical interpretation and conclusions are kept distinct from one another. The limits of what can be stated are described just as clearly: What can be proven? What is merely supported? What contrary findings exist? What remains unresolved? A lack of evidence is not reinterpreted as a seemingly certain statement.

The main body is written in such a way that a judge without specialist knowledge of IT forensics can understand the reasoning behind the findings. Technical verifiability is maintained. Data sources relevant to the investigation, integrity information, artefacts and investigative steps are documented in such a way that an independent IT forensic expert can verify the key findings as part of a potential counter-assessment.

From a court order to a reliable statement

1Distinguish between the scope of the court’s order and the issue of evidence from a technical perspective.
2Check whether the matter falls within your own area of expertise and whether it is necessary to seek clarification from the court.
3Document the evidence, the initial situation and the available data.
4Verify the integrity of the study data to the extent that this is technically feasible.
5Derive technical test hypotheses and counter-hypotheses from the question to be proven.
6Examine only the data sources relevant to this, in a targeted manner.
7Validate findings relevant to decision-making in a technical context.
8Take into account contradictions, missing data and alternative explanations.
9Explicitly state the limits of the statement.
10Provide a clear answer to the question of proof and enable a technical review.

Positive results, negative results and no evidence found

An expert finding must be open-ended. If the data confirm the hypothesis under investigation, an explanation is provided as to what underpins it. If reliable evidence contradicts this hypothesis, this is also presented. If the data set is insufficient to reach a definitive conclusion, this is described as a lack of evidence or as an open technical question. It is precisely this distinction that prevents a data gap from giving rise to a seemingly definitive statement.

Understandable to the court – technically verifiable by a counter-expert

The core technical content is explained in clear, accessible language. Technical terms are used only where necessary and are subsequently defined. At the same time, the key technical fundamentals are retained: the data sources examined, relevant artefacts, integrity information, temporal references and methodological steps. An IT forensic expert unfamiliar with the procedure should be able to verify the reasoning without the main text becoming a collection of raw technical data for the court.

Methodological classification

There is no statutory list of prescribed analysis programmes for forensic IT investigations. From a technical perspective, the key factors are a controlled database, data integrity, documented investigative steps, verifiable conclusions and the possibility of independent verification.

The BSI Basic Protection Module DER.2.2, „Preparations for IT Forensics“, contains useful guiding principles on how to prepare for subsequent forensic investigations and on securing evidence in the event of IT security incidents. However, it is not a standard for forensic investigations in criminal proceedings; the module expressly states that the actual forensic analysis is not its subject matter and that it does not relate to IT forensic investigations in connection with criminal offences.

LanCologne as an independent IT expert

Where a court needs to have a specific issue relating to digital evidence clarified from a technical perspective, we examine the available data independently and without preconceptions. The aim is not to compile the most extensive collection of technical results possible, but to provide a technically sound answer: one that is comprehensible to the court, transparent in its reasoning and technically verifiable.

Legal framework

With regard to expert evidence in civil proceedings, Sections 402 et seq. of the Code of Civil Procedure (ZPO) are particularly relevant. Section 403 of the ZPO links the presentation of evidence to the specification of the points to be assessed. Under Section 404a of the ZPO, the court directs the expert’s work; where the facts are in dispute, it determines the facts on which the expert opinion is to be based. Section 407a of the ZPO requires the expert, amongst other things, to assess whether the assignment falls within their field of expertise, to disclose any grounds that might justify mistrust of their impartiality, and, in the event of doubt regarding the content and scope of the assignment, to seek immediate clarification from the court. Section 411 of the ZPO governs the written expert report and any explanations or additions thereto. The assessment of the expert report, together with the rest of the evidence, remains the responsibility of the court (Section 286 of the ZPO).

Where an expert assessment is carried out in criminal proceedings, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. The specific procedural classification depends on the particular remit and proceedings. Our role is to provide a technical response to the technical question of evidence; this does not replace either the legal assessment or the court’s evaluation of the evidence.

Frequently Asked Questions

Can access to a file be proven even though the file remained unchanged?+
A file can be read or displayed without its contents being altered. We examine usage, application, file system and cache artefacts, taking into account the system’s specific logging logic.
How is such a technical investigation carried out in practice?+
At LanCologne, a forensic IT investigation begins by identifying the issues in the case, rather than by selecting a specific analysis programme.
Does the result of the investigation provide clear evidence for the court?+
An unchanged hash value proves that the content is identical, but on its own does not indicate whether the file has been opened or read in the meantime.
Is there a legal basis for this?+
Sections 402 et seq. of the Code of Civil Procedure (ZPO) are particularly relevant to expert evidence in civil proceedings. Section 403 of the ZPO stipulates that evidence must be adduced in relation to the specific points to be assessed.

LanCologne – IT Forensics for the Courts

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now