IT Forensics · Courts
Is it possible to determine whether deleted data has subsequently been overwritten?
Once data has been deleted, storage areas can be reused. This affects which previous contents can still be recovered.
For the court, it is not a question of how many analysis programmes were used. What matters is which specific technical fact can be reliably established from the available data, how this finding is reached, and what its limitations are.
The specific question of evidence
We assess the state of the file system, storage usage and existing fragments, and document which areas can still be analysed.
Why a single digital trail is rarely enough
Digital artefacts are generated in systems with their own storage, synchronisation and logging mechanisms. A single timestamp, log entry or database value is therefore not treated as conclusive evidence without context. Where the question of evidence requires it, several independent traces are correlated and technically plausible counter-hypotheses are examined.
Where the limits of what can be said lie
The fact that a file cannot be recovered does not automatically mean that it was deliberately overwritten; normal system use can cause the same result.
How LanCologne tackles the question requiring proof
At LanCologne, a forensic IT investigation begins by addressing the question of evidence, rather than by selecting a specific analysis programme. The first step is to clarify which technical facts are to be established, which data sources are actually relevant for this purpose, and which alternative hypotheses need to be taken into account.
The evidence and source data are clearly documented. Where technically feasible, the analysis is carried out on verified forensic backups or suitable working copies. Matches relevant to the decision are not accepted solely because they are displayed by software. The origin, logic behind its creation and context of the artefact are examined; key findings are verified, where necessary, against the underlying data or using a second, technically appropriate method.
In the expert report, the findings of fact, technical interpretation and conclusions are kept distinct from one another. The limits of what can be stated are described just as clearly: What can be proven? What is merely supported? What contrary findings exist? What remains unresolved? A lack of evidence is not reinterpreted as a seemingly certain statement.
The main body is written in such a way that a judge without specialist knowledge of IT forensics can understand the reasoning behind the findings. Technical verifiability is maintained. Data sources relevant to the investigation, integrity information, artefacts and investigative steps are documented in such a way that an independent IT forensic expert can verify the key findings as part of a potential counter-assessment.
From a court order to a reliable statement
Positive results, negative results and no evidence found
An expert finding must be open-ended. If the data confirm the hypothesis under investigation, an explanation is provided as to what underpins it. If reliable evidence contradicts this hypothesis, this is also presented. If the data set is insufficient to reach a definitive conclusion, this is described as a lack of evidence or as an open technical question. It is precisely this distinction that prevents a data gap from giving rise to a seemingly definitive statement.
Understandable to the court – technically verifiable by a counter-expert
The core technical content is explained in clear, accessible language. Technical terms are used only where necessary and are subsequently defined. At the same time, the key technical fundamentals are retained: the data sources examined, relevant artefacts, integrity information, temporal references and methodological steps. An IT forensic expert unfamiliar with the procedure should be able to verify the reasoning without the main text becoming a collection of raw technical data for the court.
Methodological classification
There is no statutory list of prescribed analysis programmes for forensic IT investigations. From a technical perspective, the key factors are a controlled database, data integrity, documented investigative steps, verifiable conclusions and the possibility of independent verification.
The BSI Basic Protection Module DER.2.2, „Preparations for IT Forensics“, contains useful guiding principles on how to prepare for subsequent forensic investigations and on securing evidence in the event of IT security incidents. However, it is not a standard for forensic investigations in criminal proceedings; the module expressly states that the actual forensic analysis is not its subject matter and that it does not relate to IT forensic investigations in connection with criminal offences.
LanCologne as an independent IT expert
Where a court needs to have a specific issue relating to digital evidence clarified from a technical perspective, we examine the available data independently and without preconceptions. The aim is not to compile the most extensive collection of technical results possible, but to provide a technically sound answer: one that is comprehensible to the court, transparent in its reasoning and technically verifiable.
Legal framework
With regard to expert evidence in civil proceedings, Sections 402 et seq. of the Code of Civil Procedure (ZPO) are particularly relevant. Section 403 of the ZPO links the presentation of evidence to the specification of the points to be assessed. Under Section 404a of the ZPO, the court directs the expert’s work; where the facts are in dispute, it determines the facts on which the expert opinion is to be based. Section 407a of the ZPO requires the expert, amongst other things, to assess whether the assignment falls within their field of expertise, to disclose any grounds that might justify mistrust of their impartiality, and, in the event of doubt regarding the content and scope of the assignment, to seek immediate clarification from the court. Section 411 of the ZPO governs the written expert report and any explanations or additions thereto. The assessment of the expert report, together with the rest of the evidence, remains the responsibility of the court (Section 286 of the ZPO).
Where an expert assessment is carried out in criminal proceedings, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. The specific procedural classification depends on the particular remit and proceedings. Our role is to provide a technical response to the technical question of evidence; this does not replace either the legal assessment or the court’s evaluation of the evidence.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.