IT Forensics · Courts

IT Forensics for the Courts – the focus is on the question of evidence

A court does not need a technical report that is as long as possible, nor a list of the programmes used. It needs a sound answer to the question of evidence raised.

Enquire without obligation

This is precisely what we base our investigation on. First, we clarify what questions need to be answered from a technical perspective. We then determine which data sources are suitable for this purpose, which investigative steps are required, and which alternative explanations need to be taken into account. Only then does the actual analysis begin.

The result may be a positive finding, a ruling of non-guilt, or a reasoned conclusion that „it cannot be determined with certainty on the basis of the available data“. All three outcomes may be technically correct. What is crucial is that the court is able to understand how the finding was reached and what its limitations are.

The actual question of evidence

How does a legal question of evidence become a technically sound investigation?

We break down the legal question into sub-questions that can be technically verified. If, for example, it needs to be established whether a file was modified on a specific date, a single timestamp is not sufficient. Among other things, file system metadata, application traces, backups, logs and, where applicable, synchronisation processes must be examined.

The investigation remains bound by the court’s instructions. Where the facts are in dispute, the court determines, in accordance with Section 404a(3) of the Code of Civil Procedure (ZPO), which facts are to form the basis of the expert assessment. We do not substitute these instructions with our own assumptions.

Where the limits of what can be said lie

An expert witness must not, of their own accord, reinterpret an unclear issue of evidence as a different issue. If there is any doubt as to the content or scope of the terms of reference, section 407a(4) of the Code of Civil Procedure (ZPO) requires the court to clarify the matter.

Why LanCologne?

In the case of court-ordered investigations, it is not a matter of which analysis programme displays a match first. What matters is whether the question of evidence can be answered on a technical basis and whether that answer stands up to independent scrutiny.

We adopt an open-minded approach, document the origin of key findings and examine alternative technical explanations. The actual analysis is always carried out on a forensic copy or a dataset that has been securely preserved as evidence. Originals are not examined directly unless absolutely necessary. Where live procedures are technically necessary, any changes that may result from them are explicitly documented.

Depending on the research question, key findings are verified either using a second method appropriate to the subject matter or directly on the basis of the underlying raw data. The tools used for this purpose depend on the evidence and the research question. The key factors are the suitability, professional recognition and traceability of the method – not a product name.

Our report distinguishes between factual findings, technical assessments and remaining uncertainties. A negative finding is justified just as carefully as a positive one.

How we handle court-ordered assignments

How we work – from the court order to the response

1Check the terms of reference and the question of proof

We first check whether the matter falls within our area of expertise, what facts the court is basing its decision on, and whether the content or scope of the assignment is clear. If there is any doubt, the court will seek clarification. This is in accordance with Sections 404a and 407a of the Code of Civil Procedure (ZPO).

2Check for independence

Any reasons that might give rise to doubts as to impartiality are examined before the substantive investigation begins and, where appropriate, disclosed to the court.

3Record evidence clearly

Devices, data storage media, backups and files provided are identified and documented. The status at the time of the investigation is recorded.

4Ensuring data integrity

Where technically feasible, a forensic copy or image is created. Hash values and other integrity checks are used to ensure unambiguous identification. The original is retained for future verification.

5Derive test hypotheses from the question to be proven

We determine which evidence would support the alleged event, what contradictory findings are conceivable, and which alternative technical explanations need to be examined.

6Examine relevant data sources

Only those artefacts which have professional evidential value in relation to the issue in question are examined. Automatic matches are not accepted without verification.

7Independently validate findings

Findings relevant to the decision are – where necessary – cross-checked using a second recognised method, a different technical approach or directly against the raw data.

8Determining the limits of what can be stated

We explicitly examine what conclusions must not be drawn from the data. We identify missing data, possible deletions, technical limitations, incomplete extracts or contradictory evidence.

9Answer the question of proof clearly

The final conclusion is drawn from the documented findings. It is not stated in stronger terms than the data permit.

10Please attach the technical appendix

The main text remains accessible even to those without a background in digital forensics. The technical appendix contains the information required by an independent IT forensic expert to carry out a technical review or prepare a counter-report.

Legal framework

Sections 403, 404a, 407a, 411 and 412 of the Code of Civil Procedure (ZPO); see also Section 286 of the ZPO regarding the court’s assessment of evidence. In criminal cases, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to expert witnesses.

The expert provides the factual basis for the case. The legal assessment and the final evaluation of the evidence remain the responsibility of the court.

Frequently Asked Questions

Why is the question of evidence central to a forensic IT investigation in court?+
A court does not need a technical report that is as long as possible, nor does it need a list of the programmes used. It needs a robust answer to the question of evidence put before it. How does a question of evidence before the court become a technically sound investigation?
How is such a technical investigation carried out in practice?+
How we work – from the court’s instruction to the response We first check whether the question falls within our area of expertise, what facts the court has taken as a basis, and whether the content or scope of the instruction is clear.
Does the result of the investigation provide clear evidence for the court?+
An expert witness must not, of their own accord, reinterpret an unclear issue of evidence as a different issue. If there is any doubt as to the content or scope of the terms of reference, section 407a(4) of the Code of Civil Procedure (ZPO) requires the court to clarify the matter.
Is there a legal basis for this?+
Sections 403, 404a, 407a, 411 and 412 of the Code of Civil Procedure (ZPO); supplemented by Section 286 of the ZPO on the judicial assessment of evidence. In criminal cases, sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to expert witnesses. The expert witness provides the technical factual basis.

LanCologne – IT Forensics for the Courts

Do you require an independent technical investigation into a matter of evidence for court proceedings? LanCologne examines digital evidence objectively, transparently and in a reproducible manner. We document both positive findings and the absence of evidence, as well as technical limitations, in such a way that the conclusions remain comprehensible to the court and verifiable by an independent IT forensic expert.

Get in touch now