IT Forensics · Courts
Is it possible to establish who has used a computer or a smartphone?
Die Frage „Wer hat das Gerät benutzt?“ gehört zu den häufigsten und zugleich schwierigsten Beweisfragen der IT-Forensik. Ein angemeldetes Benutzerkonto ist nicht automatisch der Nachweis, dass die namensgebende Person selbst vor dem Gerät saß. Gleiches gilt für ein Smartphone, das einer Person gehört, aber möglicherweise von Dritten benutzt wurde.
Eine belastbare Zuordnung entsteht deshalb nicht aus einem einzelnen Artefakt. Sie ergibt sich – wenn überhaupt – aus einer Kette miteinander vereinbarer Spuren: Anmeldung, Gerätezustand, Benutzerprofil, Kommunikationsdaten, Dateiaktivitäten, lokale oder cloudbasierte Konten, gegebenenfalls biometrische oder gerätespezifische Hinweise und der zeitliche Zusammenhang mit weiteren Ereignissen.
Unsere Aufgabe ist nicht, aus einem Benutzerkonto eine Person zu machen, sondern dem Gericht zu erklären, welche Zuordnung technisch gesichert, wahrscheinlich, nur möglich oder nicht belegbar ist.
The actual question of evidence
Welche Spuren können eine Benutzerzuordnung tragen?
Je nach Gerät und Fragestellung können Anmeldeereignisse, Benutzerkonten, Session-Daten, Gerätebindungen, App-Accounts, Kommunikationsspuren, Standort- oder Netzwerkbezüge und Dateisystemaktivitäten relevant sein. Entscheidend ist die Korrelation.
Ein Beispiel: Ein Windows-Login um 10:02 Uhr, ein geöffnetes Dokument um 10:05 Uhr und eine unmittelbar danach versendete Nachricht aus einem auf demselben Profil angemeldeten Account können gemeinsam aussagekräftiger sein als jedes einzelne Artefakt. Trotzdem muss geprüft werden, ob automatisierte Prozesse, Fernzugriff oder eine Nutzung durch Dritte als alternative Erklärung in Betracht kommen.
Where the limits of what can be said lie
Technische Artefakte belegen häufig zunächst ein Konto, eine Sitzung oder ein Gerät – nicht zwangsläufig die dahinterstehende natürliche Person. Diese Grenze muss im Gutachten sichtbar bleiben.
Why LanCologne?
In the case of court-ordered investigations, it is not a matter of which analysis programme displays a match first. What matters is whether the question of evidence can be answered on a technical basis and whether that answer stands up to independent scrutiny.
We adopt an open-minded approach, document the origin of key findings and examine alternative technical explanations. The actual analysis is always carried out on a forensic copy or a dataset that has been securely preserved as evidence. Originals are not examined directly unless absolutely necessary. Where live procedures are technically necessary, any changes that may result from them are explicitly documented.
Depending on the research question, key findings are verified either using a second method appropriate to the subject matter or directly on the basis of the underlying raw data. The tools used for this purpose depend on the evidence and the research question. The key factors are the suitability, professional recognition and traceability of the method – not a product name.
Our report distinguishes between factual findings, technical assessments and remaining uncertainties. A negative finding is justified just as carefully as a positive one.
How we handle court-ordered assignments
How we work – from the court order to the response
We first check whether the matter falls within our area of expertise, what facts the court is basing its decision on, and whether the content or scope of the assignment is clear. If there is any doubt, the court will seek clarification. This is in accordance with Sections 404a and 407a of the Code of Civil Procedure (ZPO).
Any reasons that might give rise to doubts as to impartiality are examined before the substantive investigation begins and, where appropriate, disclosed to the court.
Devices, data storage media, backups and files provided are identified and documented. The status at the time of the investigation is recorded.
Where technically feasible, a forensic copy or image is created. Hash values and other integrity checks are used to ensure unambiguous identification. The original is retained for future verification.
We determine which evidence would support the alleged event, what contradictory findings are conceivable, and which alternative technical explanations need to be examined.
Only those artefacts which have professional evidential value in relation to the issue in question are examined. Automatic matches are not accepted without verification.
Findings relevant to the decision are – where necessary – cross-checked using a second recognised method, a different technical approach or directly against the raw data.
We explicitly examine what conclusions must not be drawn from the data. We identify missing data, possible deletions, technical limitations, incomplete extracts or contradictory evidence.
The final conclusion is drawn from the documented findings. It is not stated in stronger terms than the data permit.
The main text remains accessible even to those without a background in digital forensics. The technical appendix contains the information required by an independent IT forensic expert to carry out a technical review or prepare a counter-report.
Legal framework
ZPO §§ 403, 404a, 407a und 411; § 286 ZPO für die abschließende richterliche Würdigung. In Strafverfahren §§ 72 ff. StPO.
The expert provides the factual basis for the case. The legal assessment and the final evaluation of the evidence remain the responsibility of the court.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you require an independent technical investigation into a matter of evidence for court proceedings? LanCologne examines digital evidence objectively, transparently and in a reproducible manner. We document both positive findings and the absence of evidence, as well as technical limitations, in such a way that the conclusions remain comprehensible to the court and verifiable by an independent IT forensic expert.
Related to this topic
- Kann eine konkrete Benutzereingabe technisch nachgewiesen werden?
- Kann der tatsächliche Versand einer Nachricht vom bloßen Vorhandensein im Konto unterschieden werden?
- Kann zwischen lokalem Benutzerkonto, Domänenkonto und Cloudkonto unterschieden werden?
- Kann ein Benutzerwechsel oder eine parallele Benutzersitzung rekonstruiert werden?