IT Forensics · Courts
Wie sind Proxy-, Relay- und Anonymisierungsverbindungen technisch zu bewerten?
Zwischengeschaltete Dienste können die direkte Beziehung zwischen Endgerät und Zielsystem verdecken.
For the court, the number of programmes used is not the decisive factor. What is decisive is which technical facts can be reliably established from the available data, how this finding is reached, and what limitations apply to its interpretation.
The specific question of evidence
Wir prüfen lokale Konfigurationen, Verbindungsdaten, Zertifikats- und DNS-Spuren sowie vorhandene Serverlogs und unterscheiden direkte von vermittelten Verbindungen.
Why the technical context is crucial
Digital traces do not arise in isolation. The operating system, application, cloud service, network and user context can all produce the same visible evidence in different ways. For this reason, a single timestamp, log entry or database value is not treated as conclusive evidence without examining the logic behind its creation. Where necessary, several independent traces are correlated with one another.
Where the limits of what can be said lie
Die sichtbare Adresse eines Relays oder Proxys ist nicht mit der Identität des ursprünglichen Nutzers gleichzusetzen.
How LanCologne tackles the question requiring proof
At LanCologne, forensic IT investigations begin by addressing the question of evidence, rather than by selecting a specific analysis programme. The first step is to determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations must be seriously examined.
The source data and evidence are documented. Where technically feasible, analysis is carried out on verified forensic backups or suitable working copies. Automatically generated matches are not accepted without verification where they are relevant to the decision. The origin, logic behind their creation and context of the respective artefact are decisive. Key findings are verified, where necessary, against the underlying data or using a second, technically appropriate method.
In the expert report, the findings of fact, the technical interpretation and the conclusion are kept separate. Equally important is the scope of the findings: What has been technically proven? What is merely supported? What counter-findings exist? What alternative explanations remain possible? What cannot be established on the basis of the available data?
The main body of the report is written in a way that is understandable to judges and other parties to the proceedings who do not possess specialist knowledge of IT forensics. Technical verifiability is maintained. The data sources, integrity information, artefacts and investigative steps essential for an independent review are documented in a transparent manner in a technical section.
From the brief to a robust conclusion
Positive result, negative result and no detection
A court-appointed expert report must remain open-ended. If the data supports a hypothesis, the report explains why. If reliable evidence contradicts the hypothesis, this is also presented. If the data set is insufficient, the lack of evidence is explicitly stated. No seemingly certain conclusion is drawn from a gap in the data.
Comprehensible to the court – verifiable by the opposing expert
The core technical content is explained in clear, accessible language. Technical terms are used only where necessary and are subsequently defined. At the same time, the key technical principles are documented in such a way that an independent IT forensic expert can follow the reasoning using the same data set and, if necessary, reproduce the results.
Methodological classification
There is no statutory list of prescribed analysis programmes for forensic IT investigations. From a technical perspective, the key requirements are a controlled database, data integrity, documented investigative steps, verifiable conclusions and the possibility of independent verification.
The BSI Basic Protection module DER.2.2, „Preparations for IT Forensics“, contains helpful guiding principles on how to prepare for subsequent IT forensic investigations and on securing evidence in the event of IT security incidents. However, it is expressly not a set of rules for IT forensic investigations in criminal cases; nor is the actual forensic analysis the subject of this module. It is therefore not presented as a forensic standard for criminal proceedings.
LanCologne as an independent IT expert
Where a court needs to have a specific issue relating to digital evidence clarified from a technical perspective, we examine the available data independently and without preconceptions. The aim is not to generate as many technical hits as possible, but to provide a technically sound answer: one that is comprehensible to the court, transparent in its reasoning and technically verifiable.
Legal framework
Sections 402 et seq. of the Code of Civil Procedure (ZPO) are particularly relevant to expert evidence in civil proceedings. Under Section 404a of the ZPO, the court directs the expert’s work and may determine the nature and scope of their work. Where the facts are in dispute, the court determines which facts are to form the basis of the expert opinion. Section 407a of the ZPO requires the expert, amongst other things, to check without delay whether the assignment falls within their area of expertise; any doubts regarding the content and scope of the assignment must be clarified by the court. The written expert report and any explanatory notes or additions are governed by Section 411 of the ZPO. The final assessment of the expert report, together with the overall outcome of the taking of evidence, remains the responsibility of the court (Section 286 of the ZPO).
In the case of expert reports in criminal proceedings, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts; Section 78 of the StPO concerns the judicial supervision of the expert’s work. Which provisions are relevant in a specific case depends on the type of proceedings and the terms of reference. An IT forensic assessment does not replace a legal assessment.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.