This overview brings together all the questions and answers relating to IT forensics for law enforcement agencies on LanCologne – from the seizure of digital evidence, through the assessment of evidence and the identification of perpetrators, to corporate IT systems, expert reports and the use of evidence in court. Click on a category to view the relevant questions.
Assessment of evidence, plausibility and investigative hypotheses
- How are incriminating and exculpatory digital traces examined in equal measure?
- How is a digital investigative question broken down into sub-questions that can be verified technically?
- How is a preliminary assumption transformed into technically verifiable hypotheses and counter-hypotheses?
- How is the evidential value of an individual digital artefact assessed?
- How can several pieces of weak evidence be combined to form a robust overall technical conclusion?
- How are incriminating findings weighed up against exonerating technical counter-findings?
- When can a negative technical result be considered reliable?
- When is a technical exclusion more serious than a mere failure to provide evidence?
- How can a technically plausible alternative explanation be documented in a way that stands up to scrutiny?
- How is it determined whether a statement made by a defendant is technically plausible?
- How is it determined whether it is technically possible to give evidence relating to a digital transaction?
- How are several devices seized from a suspect linked to one another?
- How are conflicting statements cross-checked against digital evidence?
- Can malware provide an incriminating or exculpatory alternative explanation?
- How is the distinction between technical analysis and investigative decisions maintained?
- How is it documented when two recognised methods produce different results?
- How are indications of anti-forensics or evidence tampering investigated?
- How is the plausibility of an alleged digital chain of events verified from a technical perspective?
- How is conflicting digital evidence dealt with during the preliminary investigation?
- When does the absence of a digital artefact provide meaningful information for an investigation?
- When is an independent second IT forensic investigation advisable for investigating authorities?
- How are existing forensic analyses independently validated?
- How are the digital traces of several suspects distinguished from one another?
- How are digital traces within a group of offenders technically distinguished?
- How are allegations of tampering with digital timestamps investigated?
- How can one distinguish between an alleged attempt to cover up evidence and a routine system clean-up?
- How can a technical alternative explanation that exonerates the accused be documented in a reliable manner?
- When can a hypothesis be technically ruled out?
Perpetrator identification, accounts and remote access
- Can a digital activity be linked to a user account or a natural person?
- How are multiple possible source devices for a piece of digital content assessed?
- How are shared accounts handled when attributing responsibility to perpetrators?
- How is the use of stolen or shared login details tested as a counter-hypothesis?
- How are MFA events assessed in user mapping?
- How are session tokens taken into account when reconstructing account usage?
- How is data from cloud providers synchronised with data on local devices?
- How is remote station data used in communication systems?
- How is an alleged instance of remote access investigated as an alternative theory regarding the perpetrator?
- How are server-side logs synchronised with local app data?
- How is an incomplete sequence of events reconstructed?
- How can we determine whether two digital events are causally linked?
- How are multiple devices linked to the same cloud account?
- How is a distinction made between automated system behaviour and deliberate user action?
Technical analysis methodology, timestamps and data quality
- How are the extraction limits of a forensic data set documented?
- How is it verified whether a forensic parser has interpreted a data structure correctly?
- When is a raw data check required?
- How are unknown or rare digital artefacts examined?
- How are new app versions and modified database structures assessed from a forensic perspective?
- How are App-Updates taken into account as a cause of seemingly contradictory data?
- How are different data states of the same app on multiple devices evaluated?
- How are timestamps with unknown or poorly documented semantics evaluated?
- How are time zone discrepancies between devices, Servern and cloud systems detected?
- How are synchronisation delays taken into account in an investigation timeline?
- How are file hashes used in larger criminal investigations?
- How can duplicate data be effectively reduced in investigations?
Seizure, securing and legal basis
- How is digital evidence that has been secured technically transferred and documented?
- How are electronic storage media technically analysed in accordance with section 110 of the Code of Criminal Procedure?
- How is the integrity of a forensic backup documented for the purposes of the investigation?
- When is it advisable to perform a live backup of a running system?
- How are encrypted computers assessed forensically during a criminal investigation?
- How are locked smartphones technically categorised in the course of a criminal investigation?
- How is a complex body of digital evidence collated for the prosecution and the subsequent trial?
- How is the impact of incomplete data on the assessment of the investigation quantified?
- How is a technical conclusion with a graded level of certainty formulated?
- What information is still available after a factory reset?
- How is the formatting or reinstallation of a computer assessed during a criminal investigation?
- How are backups and snapshots used as sources of evidence?
- How is damaged or incomplete evidence assessed by an expert?
System changes, migration and subsequent modifications
- How are traces assessed following an operating system Upgrade?
- How are traces assessed following a change of device or migration?
- How is data assessed after it has been restored from a backup?
- How are subsequent system changes documented as part of investigative or security measures?
- How are new technical findings dealt with when they fall outside the scope of the original line of enquiry?
- How is a technical incidental finding documented in professional terms?
Expert reports, court proceedings and the Crown Prosecution Service
- Why can a criminal investigation authority call in an external IT forensic expert?
- How is an existing forensic report assessed for technical validity?
- How can the findings of an IT forensic investigation be summarised in a way that is clear enough to inform a decision by the public prosecutor’s office?
- How is a complex IT forensic report prepared for the main hearing?
- How are technical findings documented for the purposes of enquiries from the court and the defence?
- How is a reproducible repeat study carried out using the same dataset?
- How is a final comprehensive IT forensic assessment prepared for criminal investigation authorities?
- How is an IT forensic investigation documented in a way that ensures it can be reproduced for the defence and subsequent court proceedings?
- How is an expert report drawn up during a public prosecutor’s preliminary investigation?
- How are IT forensic findings prepared in such a way that they can be explained later in court proceedings?
Enterprise IT, cloud and network systems
- Can the use of a shared service account be attributed to specific individuals?
- How are Active Directory logins assessed during a criminal investigation?
- How are Entra ID or cloud identity logins classified for forensic purposes?
- How are local computer logs and central directory service logs correlated with one another?
- Is it possible to trace which user accessed a file server?
- Can the use of a NAS be reconstructed during a criminal investigation?
- How are SharePoint files and version histories assessed during a preliminary investigation?
- How are OneDrive synchronisation logs analysed in investigations?
- How is Microsoft 365 audit data assessed during a criminal investigation?
- How are Exchange mailboxes and server-side email traces examined?
- How are Teams communications and meeting artefacts assessed from a forensic perspective?
- Is it possible to determine whether company data has been shared externally?
- How are changes to authorisations reconstructed in enterprise systems?
- Is it possible to determine who granted a user elevated privileges?
- How are Terminal Server and Remote Desktop sessions assigned to individual users?
- How are VDI environments examined for forensic purposes?
- How is MDM data categorised in smartphone investigations?
- Is it technically possible to recover data following a remote wipe?
- How are backup systems in corporate networks used as a source of evidence?
- How are centralised logging systems and SIEM data analysed forensically?
- How are firewall logs used as evidence in investigations?
- How are proxy and web gateway logs analysed within the corporate network?
- How are DHCP and network access details used for device assignment?
- How is WLAN controller data assessed in preliminary investigations?
- Is it possible to prove that a specific workstation was used on the company network?
- How are file servers, email and end devices correlated to form a single chain of events?
- Is it possible to determine whether company data has been leaked via private cloud storage?
- Is it technically possible to verify that a file has been uploaded to a web service?
- How is the origin of a downloaded company document verified?
Device, communication and location traces
- How are deleted files assessed in a criminal investigation?
- How is a sequence of digital events reconstructed for investigators?
- How is digital location data assessed during a criminal investigation?
- How are cloud synchronisation logs treated in investigations?
- How can messenger data be analysed reliably during a criminal investigation?
- How is the origin of an email verified during a criminal investigation?
- How are browser and search history records assessed for investigative purposes?
- How are SQLite databases, WALs and logs assessed in criminal investigations?
- How are photo and video metadata examined during a criminal investigation?
- How is the authenticity of a screenshot or screen capture verified?
- What role do archives and encrypted containers play in investigations?
- How are virtual machines assessed as standalone investigation environments?
Other questions
- How is an existing IT report from another organisation independently verified?
- How are automated follow-up events distinguished from manual actions?
- How are background processes examined as an alternative explanation for file accesses?
- How are system maintenance and log rotation taken into account as causes of missing traces?
- Is it technically possible to trace data leakage via USB devices?
- Can data leaks via network shares be traced?
- How is VPN usage taken into account when categorising internet activity?
- How are proxy, relay or Tor connections classified from a technical point of view?
- What is the evidential value of an IP address in a criminal investigation?
- How much weight do DNA traces carry in criminal investigations?
- How are system and security logs assessed as evidence in an investigation?
- Is it possible to trace the use of administrative rights during a criminal investigation?
- Can account compromise be considered as an alternative theory regarding the perpetrator?
- How are shared computers taken into account when identifying the perpetrator?
- How can large volumes of data be analysed in a targeted manner to address a specific investigative question?
- How are search terms and results lists validated forensically?
- How is deleted data from unallocated areas assessed?
- How are carving findings assessed during the preliminary investigation?
- Can a file be assigned to a specific storage medium as its original source?
- How is the provenance of a piece of digital evidence documented?
- How is evidence that has been technically altered dealt with?
- How are missing or incomplete chains of evidence assessed from a technical perspective?
- How are discrepancies between the initial and second analyses resolved?
- How are parser errors and misinterpretations detected in existing reports?
- How are different time sources from the cloud, Server and end devices synchronised?
- How are device clocks synchronised with external reference times?