IT Forensics · Courts
How are database entries and WAL/journal traces assessed in court?
Many apps store information in databases. However, active tables do not always reflect the entire historical record. Transaction and journal structures may contain additional data records. It is crucial to clearly distinguish between active, deleted, reconstructed and only fragmentarily preserved data.
What exactly does the expert need to clarify?
It is not the number of artefacts found that is decisive. What matters is whether the relevant digital traces support the fact in question, contradict it, or do not allow for any conclusive conclusion. To this end, findings are examined in their technical context and alternative hypotheses are explicitly considered.
Where the limits of what can be said lie
A reconstructed dataset does not automatically have the same level of reliability as an active dataset. Its origin, structure and degree of reconstruction must be specified.
How LanCologne tackles the question requiring proof
In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.
The data set is clearly documented and, as far as technically possible, examined using verified forensic backups or working copies. Automated matches are not accepted without verification where they relate to matters relevant to the decision. The origin, the logic behind its creation and the context of an artefact are decisive. Where necessary, a finding is verified against the raw data or using an independent, second, technically appropriate method.
In the report, we distinguish between the findings of fact, the technical assessment and the conclusion. We also clearly state the limits of our findings: what has been proven, what is merely supported, what remains open to question, and what cannot be determined on the basis of the available data?
The main body of the report is written in a way that is accessible to judges and other non-forensic experts. Technical verifiability is ensured by a separate technical section. This section documents the data sources, integrity values, artefacts and investigative steps that are essential for an independent review.
How we work
Methodological classification
There is no statutory list of prescribed software products for forensic IT investigations. The BSI Basic Protection module DER.2.2 contains useful guiding principles on precautionary measures, evidence preservation and the presentation of findings in a manner appropriate to the target audience in the event of IT security incidents. However, it expressly states that the actual forensic analysis is not covered by the module and that it does not relate to IT forensic investigations in criminal cases. We therefore do not present it as a standard for criminal proceedings.
Legal framework
ZPO Sections 403, 404a, 407a, 411; Section 286 ZPO.
The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the terms of reference.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you require an independent IT forensic investigation in relation to a specific issue of evidence in court? LanCologne examines the available digital evidence with an open mind and documents key findings, counter-findings and technical limitations in a transparent manner.