IT Forensics · Courts

How can an existing private IT report be technically reviewed?

If a technical report is already available, we do not examine its author, but rather its data basis and methodology: Have the correct pieces of evidence been examined? Are key findings reproducible? Have alternative explanations been taken into account? Does the conclusion actually follow from the documented data?

Enquire without obligation

What exactly does the expert need to clarify?

It is not the number of artefacts found that is decisive. What matters is whether the relevant digital traces support the fact in question, contradict it, or do not allow for any conclusive conclusion. To this end, findings are examined in their technical context and alternative hypotheses are explicitly considered.

Where the limits of what can be said lie

A differing technical assessment is not correct simply because a different tool or terminology was used. What matters are the data basis, the method and the logical reasoning.

How LanCologne tackles the question requiring proof

In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.

The data set is clearly documented and, as far as technically possible, examined using verified forensic backups or working copies. Automated matches are not accepted without verification where they relate to matters relevant to the decision. The origin, the logic behind its creation and the context of an artefact are decisive. Where necessary, a finding is verified against the raw data or using an independent, second, technically appropriate method.

In the report, we distinguish between the findings of fact, the technical assessment and the conclusion. We also clearly state the limits of our findings: what has been proven, what is merely supported, what remains open to question, and what cannot be determined on the basis of the available data?

The main body of the report is written in a way that is accessible to judges and other non-forensic experts. Technical verifiability is ensured by a separate technical section. This section documents the data sources, integrity values, artefacts and investigative steps that are essential for an independent review.

How we work

1Distinguish between the scope of the court’s order and the issue of evidence from a technical perspective.
2Check the area of specialisation, the time limit and any potential doubts regarding impartiality.
3Clearly document the evidence and source data.
4Ensure integrity and avoid change wherever possible.
5Derive technical test hypotheses and counter-hypotheses from the question to be proven.
6Examine relevant data sources in a targeted manner.
7Validate key findings from a technical perspective and examine alternative explanations.
8Document any inconsistencies, missing data and technical limitations.
9Answer the research question clearly, without overstating the significance of the data.
10Document the technical basis for an independent review.

Methodological classification

There is no statutory list of prescribed software products for forensic IT investigations. The BSI Basic Protection module DER.2.2 contains useful guiding principles on precautionary measures, evidence preservation and the presentation of findings in a manner appropriate to the target audience in the event of IT security incidents. However, it expressly states that the actual forensic analysis is not covered by the module and that it does not relate to IT forensic investigations in criminal cases. We therefore do not present it as a standard for criminal proceedings.

Legal framework

ZPO Sections 403, 404a, 407a, 411, 412; Section 286 ZPO.

The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the terms of reference.

Frequently Asked Questions

How can an existing private IT report be technically reviewed?+
If a technical report is already available, we do not examine its author, but rather its data basis and methodology: Was the correct evidence analysed? Are key findings reproducible? Were alternative explanations taken into account?
How is such a technical investigation carried out in practice?+
In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.
Does the result of the investigation provide clear evidence for the court?+
A differing technical assessment is not correct simply because a different tool or terminology was used. What matters are the data basis, the method and the logical reasoning.
Is there a legal basis for this?+
ZPO §§ 403, 404a, 407a, 411, 412; § 286 ZPO. The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the remit.

LanCologne – IT Forensics for the Courts

Do you require an independent IT forensic investigation in relation to a specific issue of evidence in court? LanCologne examines the available digital evidence with an open mind and documents key findings, counter-findings and technical limitations in a transparent manner.

Get in touch now