IT Forensics · Courts

How are database entries and WAL/journal traces assessed in court?

Many apps store information in databases. However, active tables do not always reflect the entire historical record. Transaction and journal structures may contain additional data records. It is crucial to clearly distinguish between active, deleted, reconstructed and only fragmentarily preserved data.

Enquire without obligation

What exactly does the expert need to clarify?

It is not the number of artefacts found that is decisive. What matters is whether the relevant digital traces support the fact in question, contradict it, or do not allow for any conclusive conclusion. To this end, findings are examined in their technical context and alternative hypotheses are explicitly considered.

Where the limits of what can be said lie

A reconstructed dataset does not automatically have the same level of reliability as an active dataset. Its origin, structure and degree of reconstruction must be specified.

How LanCologne tackles the question requiring proof

In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.

The data set is clearly documented and, as far as technically possible, examined using verified forensic backups or working copies. Automated matches are not accepted without verification where they relate to matters relevant to the decision. The origin, the logic behind its creation and the context of an artefact are decisive. Where necessary, a finding is verified against the raw data or using an independent, second, technically appropriate method.

In the report, we distinguish between the findings of fact, the technical assessment and the conclusion. We also clearly state the limits of our findings: what has been proven, what is merely supported, what remains open to question, and what cannot be determined on the basis of the available data?

The main body of the report is written in a way that is accessible to judges and other non-forensic experts. Technical verifiability is ensured by a separate technical section. This section documents the data sources, integrity values, artefacts and investigative steps that are essential for an independent review.

How we work

1Distinguish between the scope of the court’s order and the issue of evidence from a technical perspective.
2Check the area of specialisation, the time limit and any potential doubts regarding impartiality.
3Clearly document the evidence and source data.
4Ensure integrity and avoid change wherever possible.
5Derive technical test hypotheses and counter-hypotheses from the question to be proven.
6Examine relevant data sources in a targeted manner.
7Validate key findings from a technical perspective and examine alternative explanations.
8Document any inconsistencies, missing data and technical limitations.
9Answer the research question clearly, without overstating the significance of the data.
10Document the technical basis for an independent review.

Methodological classification

There is no statutory list of prescribed software products for forensic IT investigations. The BSI Basic Protection module DER.2.2 contains useful guiding principles on precautionary measures, evidence preservation and the presentation of findings in a manner appropriate to the target audience in the event of IT security incidents. However, it expressly states that the actual forensic analysis is not covered by the module and that it does not relate to IT forensic investigations in criminal cases. We therefore do not present it as a standard for criminal proceedings.

Legal framework

ZPO Sections 403, 404a, 407a, 411; Section 286 ZPO.

The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the terms of reference.

Frequently Asked Questions

How are database entries and WAL/journal traces assessed in court?+
Many apps store information in databases. However, active tables do not always show the full historical record. Transaction and journal structures may contain additional records.
How is such a technical investigation carried out in practice?+
In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.
Does the result of the investigation provide clear evidence for the court?+
A reconstructed dataset does not automatically have the same level of reliability as an active dataset. Its origin, structure and degree of reconstruction must be specified.
Is there a legal basis for this?+
Sections 403, 404a, 407a and 411 of the Code of Civil Procedure (ZPO); Section 286 ZPO. The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the remit.

LanCologne – IT Forensics for the Courts

Do you require an independent IT forensic investigation in relation to a specific issue of evidence in court? LanCologne examines the available digital evidence with an open mind and documents key findings, counter-findings and technical limitations in a transparent manner.

Get in touch now