IT Forensics · Courts
Is it technically possible to reconstruct alleged internet or browser usage?
Browser data may include search terms, visited URLs, downloads, cookies, cache, sessions and other traces of usage. However, what matters is which action the respective data item actually records. Automatic background processes and synchronisation must not be equated with deliberate user navigation.
What exactly does the expert need to clarify?
It is not the number of artefacts found that is decisive. What matters is whether the relevant digital traces support the fact in question, contradict it, or do not allow for any conclusive conclusion. To this end, findings are examined in their technical context and alternative hypotheses are explicitly considered.
Where the limits of what can be said lie
A URL entry does not necessarily prove that a person deliberately viewed the page in question. Conversely, the absence of a browsing history does not prove that the site was not used.
How LanCologne tackles the question requiring proof
In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.
The data set is clearly documented and, as far as technically possible, examined using verified forensic backups or working copies. Automated matches are not accepted without verification where they relate to matters relevant to the decision. The origin, the logic behind its creation and the context of an artefact are decisive. Where necessary, a finding is verified against the raw data or using an independent, second, technically appropriate method.
In the report, we distinguish between the findings of fact, the technical assessment and the conclusion. We also clearly state the limits of our findings: what has been proven, what is merely supported, what remains open to question, and what cannot be determined on the basis of the available data?
The main body of the report is written in a way that is accessible to judges and other non-forensic experts. Technical verifiability is ensured by a separate technical section. This section documents the data sources, integrity values, artefacts and investigative steps that are essential for an independent review.
How we work
Methodological classification
There is no statutory list of prescribed software products for forensic IT investigations. The BSI Basic Protection module DER.2.2 contains useful guiding principles on precautionary measures, evidence preservation and the presentation of findings in a manner appropriate to the target audience in the event of IT security incidents. However, it expressly states that the actual forensic analysis is not covered by the module and that it does not relate to IT forensic investigations in criminal cases. We therefore do not present it as a standard for criminal proceedings.
Legal framework
ZPO Sections 403, 404a, 407a, 411; Section 286 ZPO.
The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the terms of reference.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you require an independent IT forensic investigation in relation to a specific issue of evidence in court? LanCologne examines the available digital evidence with an open mind and documents key findings, counter-findings and technical limitations in a transparent manner.