Diese Übersicht bündelt alle Fragen und Antworten rund um IT-Forensik für Gerichte bei LanCologne – von der Zuordnung von Nutzern und Konten über Dateien, Metadaten und Kommunikationsspuren bis hin zu Widersprüchen in digitalen Beweismitteln und der Rolle des IT-Sachverständigen im Gerichtsverfahren. Klicken Sie auf eine Kategorie, um die passenden Fragen zu sehen.
Nutzer- und Kontozuordnung
- Is it possible to establish who has used a computer or a smartphone?
- Can a specific user input be verified technically?
- Can the actual sending of a message be distinguished from its mere existence in the account?
- Is it possible to distinguish between a local user account, a domain account and a cloud account?
- Is it possible to reconstruct a user switch or a concurrent user session?
- How meaningful is an automatic registration?
- Can a digital artefact be linked to a specific user profile?
- How should artefacts from shared or technical accounts be assessed?
- Is it possible to distinguish whether digital data was generated automatically or as a result of a user action?
- Is it possible to determine whether a user account has been compromised or used by a third party?
- How are digital traces assessed when several devices use the same account?
- Can a digital action carried out on shared computers be attributed to a specific user?
- Is it possible to reliably distinguish between a local user account, a domain account and a cloud account?
- Is it possible to verify a change of user or a concurrent user session?
- How significant is automatic login in terms of user assignment?
- Can a digital artefact be assigned to a specific user profile within a multi-user system?
Kommunikation: Chat, E-Mail und Nachrichten
- Is it technically possible to verify the authenticity and completeness of a chat history?
- Is it technically possible to trace the origin and route of an email?
- How reliable are push notifications as digital evidence?
- What does a digital read receipt actually prove?
- How should differences in message status between the sender and recipient be assessed?
- Is it possible to distinguish between receiving, saving, opening and processing an email attachment?
- Is it possible to tell whether an email has been forwarded or whether its content has been copied manually?
- How reliable are email headers in indicating the origin and transmission path?
- Is it possible to determine whether an email has been deleted locally, on the server or via synchronisation?
Fotos, Videos und Multimedia
- Can one infer actual device usage from a screen lock?
- Is it possible to determine whether a photo or video was taken with a specific device?
- Is it possible to distinguish between the original recording, the edited file and the converted copy?
- How informative are preview images and thumbnail caches?
- How reliable is a screen recording as digital evidence?
- How reliable are photo and video metadata as evidence in court?
- Does a preview image or thumbnail show whether the associated file has been opened?
Geräte, Netzwerk und Systemartefakte
- Is it possible to determine whether a device was connected to a specific WLAN?
- What significance do identical files on multiple devices have?
- Is it possible to determine which device originally initiated a synchronised change?
- Can an alleged instance of remote access to a computer be technically substantiated?
- Is it possible to reconstruct the timing of a device’s network switch?
- Is it possible to determine whether a system update has altered or deleted digital traces?
- How does migrating to a new device affect the assessment of evidence?
- Is it possible to determine whether a particular external device was connected to a computer?
- Is it possible to determine whether a particular piece of software has been installed or has actually been run?
- Is it possible to determine retrospectively whether a piece of software that has since been uninstalled was previously installed?
- Is it possible to determine whether data has been transferred or accessed via a network share?
- What weight is given to volatile data from main memory in court?
- Can a remote desktop or remote access session be verified retrospectively?
- Is it possible to determine whether a device was locked or actively in use at the relevant time?
- Is it possible to determine which network a device was connected to at a specific point in time?
- How are time stamps from external Server devices compared with the local device time?
- How might system updates affect digital traces?
- Can a migration from an old device to a new one be detected through forensic analysis?
Löschung, Wiederherstellung und Backup
- Is it possible to prove whether data was deliberately deleted?
- What traces might a restore from a backup leave behind?
- What can still be reliably determined after a factory reset?
- What is the evidential value of backups, snapshots and historical backups?
- Is it possible to tell whether a storage device has been formatted or whether an operating system has been reinstalled?
- What weight do ‘Recycle Bin’ and ‘Trash’ artefacts carry in court?
- Is it possible to determine whether deleted data has subsequently been overwritten?
- How does restoring data from a backup affect the assessment of evidence?
- What information is still available after a factory reset?
Authentifizierung, Verschlüsselung und Zugriffsschutz
- Is it possible to distinguish between password-based, biometric and session-based authentication?
- What weight do stored passwords, tokens and login details carry in court?
- How secure are encrypted containers and virtual storage devices?
- What kind of evidence is admissible where evidence is encrypted or only partially accessible?
- How is a digital signature verified from a technical point of view?
Anonymisierung, VPN und Netzwerkspuren
- To what extent does the use of a VPN affect the attribution of digital activities?
- How are proxy, relay or anonymisation connections categorised in a forensic context?
- How reliable are DNS traces as evidence of internet activity?
- To what extent does the use of a VPN affect the attribution of internet activity?
Cloud, virtuelle Systeme und Container
- Is it possible to determine whether an archive has been extracted or whether its contents have been used?
- How are virtual machines examined as digital evidence?
- Is it possible to determine whether a virtual machine was running at a specific point in time?
- How much weight do cloud synchronisation logs carry in court?
- What weight do encrypted containers and virtual data carriers carry in court?
- How are virtual machines examined as digital evidence?
Dateien, Metadaten und Zeitstempel
- Is it possible to determine when a file was created or modified?
- Is it possible to determine whether a file has actually been opened or used?
- Is it possible to determine whether a file has merely been viewed or has actually been edited?
- How reliable are drafts, auto-save files and temporary documents?
- Can a file be associated with a specific programme used to create it?
- Is it possible to tell whether a document has been exported from another file?
- Can traces in the clipboard prove that a copy-and-paste operation took place?
- What weight do ZIP, RAR and other archive files carry in court?
- How reliable is a digital timeline in court?
- How reliable are search indexes and the contents of indexed files?
- Can an actual search be distinguished from mere indexing?
- Is it possible to determine whether a digital action was triggered by a scheduled task or by automation?
- Is it possible to determine whether authorisation was in place at a specific point in time?
- Can changes to user or group permissions be reconstructed?
- When, if at all, can a conclusion be drawn from the absence of a digital artefact?
- Is it possible to prove whether a digital document has been altered at a later date?
- Is it possible to determine which version of a document was in use at a specific point in time?
- Is it possible to tell whether a file has been downloaded from the internet?
- Is it possible to determine whether a computer was switched on or off at a specific time?
- Is it possible to tell whether files have been renamed or moved within a system?
- What weight do recovered files, or those preserved only in fragments, carry in court?
- Is it possible to tell whether a file or piece of information has been printed out?
- Is it possible to determine whether a file has actually been opened?
- Can it be proven that a person has actually taken note of the contents of a digital file?
- Is it possible to tell whether a file has been copied, moved or synchronised?
- Is it technically possible to specify the exact time of deletion?
- Can access to a file be proven even though the file remained unchanged?
- Is it possible to detect any tampering with file or system timestamps?
- Is it possible to distinguish between an original media file and a converted or re-saved version?
- How reliable are search indexes as indicators of a file’s existence or use?
Widersprüche, Plausibilität und Beweiswürdigung
- How does an IT expert verify an alleged sequence of events when digital evidence contradicts itself?
- How reliable is metadata that can be manually altered as evidence?
- Can malware be an alternative explanation for a digital action?
- How should we deal with conflicting digital traces?
- How is a claimed digital chain of events checked for technical plausibility?
- How does an IT expert assess two technically plausible explanations?
- How should a technical non-verification be clearly stated in the report?
- How should contradictory digital evidence be dealt with in an IT expert report?
Gutachten, Gerichtsverfahren und Sachverständige
- How are the independence and neutrality of an IT expert put into practice?
- Why does an IT report need to be understandable to non-forensic experts?
- Why is a technical appendix part of a comprehensive IT report?
- How should an IT report be structured in such a way as to allow for a potential counter-report to be produced?
- How can a legal question concerning IT evidence be answered conclusively and unambiguously?
- How are time zones, summer time and faulty system clocks taken into account in the report?
- How can an existing private IT report be technically reviewed?
- Expert or expert witness – what is the distinction when it comes to digital evidence?
- How is an IT expert report presented in court and examined in response to supplementary questions?
- What impact does an incomplete chain of custody have on the technical validity of the findings?
- What happens if, during the IT forensic investigation, new facts come to light that are not covered by the court order?
- Where does the IT expert’s technical conclusion end, and where does the court’s assessment of the evidence begin?
Sonstige Beweisfragen
- What is the evidential value of a screenshot or photograph of digital content?
- Is it possible to determine whether data has been copied to a USB storage device?
- How can digital evidence be secured in such a way that the investigation remains verifiable at a later date?
- How reliable is digital location data as evidence in court?
- Is it technically possible to reconstruct alleged internet or browser usage?
- Is it possible to trace the origin of a digital file or a data record?
- How is damaged or incomplete digital evidence handled?
- How are database entries and WAL/journal traces assessed in court?
- What evidence value do system and event logs have in court?
- Can an IP address be linked to a specific person?
- Is there any evidence of anti-forensics or deliberate evidence tampering?
- Which is more conclusive: original data, a forensic backup or an exported report?
- When might it be appropriate to commission a new IT forensic assessment under Section 412 of the German Code of Civil Procedure (ZPO)?
- Is it possible to prove whether digital evidence has been altered since it was seized?
- Is it possible to determine whether administrative or elevated privileges were used?
- How should digital evidence be assessed if it has been used further prior to forensic preservation?
- Can the sequence of several digital actions be reliably reconstructed?
- Is it technically possible to verify the authenticity and origin of a screenshot?
- Is it possible to determine when a ZIP, RAR or other archive was created or extracted?
- Is it possible to determine which source document a PDF file was created from?