IT forensics · Investigative authorities

How are SQLite databases, WALs and logs assessed in criminal investigations?

Many apps store messages, contacts and usage data in SQLite databases.

Enquire without obligation

Why this question is important to the investigating authorities

Digital investigations must yield reliable facts, but must not over-interpret technical evidence. It is therefore not only important for the investigation to establish whether a piece of evidence exists, but also what it actually proves, what alternative hypotheses exist, and which further conclusions are specifically not permissible.

Technical investigative approach

We distinguish between active records, transaction remnants, deleted or reconstructed content, and check their database context.

Where the limits of what can be said lie

A reconstructed fragment does not automatically carry the same weight as a fully active data set.

Why LanCologne?

In the case of investigative assignments, LanCologne does not operate on the principle of technically confirming a pre-determined hypothesis of suspicion. The starting point is the specific investigative question. To this end, both incriminating and exculpatory technical possibilities are examined equally.

The evidence or data sets provided are clearly documented. Where technically feasible, analysis is carried out on verified backups or suitable working copies. Automatically generated matches shall not be accepted without verification where they are relevant to the decision. The origin, generation logic and context of the artefact shall be checked; where necessary, an independent cross-check shall be carried out using the underlying data or a second method appropriate to the subject matter.

For a criminal investigation authority, it is crucial that no conclusion is drawn from technical evidence that goes beyond what the data actually supports. That is why we distinguish between device-related, account-related and user-related information, and the identification of individuals, as well as between possibility, actual use and provable action.

A negative finding is equally important. If a hypothesis put forward during the investigation cannot be confirmed on the basis of the available data, or if there are technically plausible alternative explanations, this is explicitly documented. This is in line with an open-minded, expert approach and supports the obligation to take into account both incriminating and exonerating circumstances.

From the investigation brief to a reliable statement

1Clearly distinguish between the subject of the investigation and the technical remit.
2Check whether the question falls within your own area of expertise and whether further information is required.
3Document the evidence, the initial situation and the available data.
4Verify the integrity of the study data to the extent that this is technically feasible.
5Derive specific test hypotheses and counter-hypotheses from the research assumption.
6Examine relevant data sources in a targeted manner.
7Examine the findings relevant to the decision in terms of their origin, the reasoning behind them and their context.
8Assess incriminating and exculpatory findings using the same professional standard.
9Document any inconsistencies, missing data and alternative technical explanations.
10Provide a clear answer to the question under investigation and facilitate the technical review.

Findings that support or refute the case

An expert investigation must remain open-ended. If the evidence supports the hypothesis under investigation, an explanation is provided as to why. If reliable evidence contradicts it, or if an alternative technical explanation remains valid, this is also documented. If the available evidence is insufficient to support a definitive conclusion, the absence of evidence is stated as such.

Understandable to the Crown Prosecution Service, the police, the defence and the court

The main findings are set out in plain language. At the same time, the technical principles relevant to the investigation are documented in such a way that another qualified IT forensic expert can verify the key conclusions using the same data. This ensures that the investigation remains transparent for any subsequent cross-checks or court proceedings.

LanCologne as an external IT forensic expert

When an investigating authority needs to have a specific digital issue clarified in an independent and technically sound manner, LanCologne provides support through a transparent, open-ended investigation. The aim is not to achieve the highest possible number of hits, but to provide a sound, expert answer to the specific investigative question.

Legal framework

The responsibility for conducting the investigation and making legal assessments remains with the competent law enforcement authorities. Under Section 160 of the Code of Criminal Procedure, the public prosecutor’s office investigates the facts of the case and is required to establish both incriminating and exonerating circumstances. Section 161 of the Code of Criminal Procedure (StPO) governs the Public Prosecutor’s general powers of investigation and the possibility of having investigations carried out by police authorities and officers. The duties of the police during the investigation are set out in Section 163 of the Code of Criminal Procedure (StPO).

As a general rule, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. Section 161a(1) StPO requires experts to appear before the public prosecutor’s office when summoned and to submit their expert report; the provisions relating to experts in Section 7 apply mutatis mutandis, unless otherwise specified. Section 82 of the Code of Criminal Procedure (StPO) concerns the form in which expert reports are to be submitted during the preliminary proceedings.

The seizure and confiscation of items that may constitute evidence are governed in particular by sections 94 and 98 of the Code of Criminal Procedure (StPO). Section 110(3) of the StPO governs the examination of electronic storage media and, subject to the conditions set out therein, also permits the securing of data relevant to the investigation. The decision on the admissibility, scope and ordering of such measures rests with the competent state authorities, not with LanCologne.

Under Section 1(3) of the JVEG, engagement by the police or other law enforcement authorities on behalf of, or with the prior approval of, the public prosecutor’s office is treated as equivalent to engagement by the public prosecutor’s office for the purposes of remuneration.

Frequently Asked Questions

How are SQLite databases, WALs and logs assessed in criminal investigations?+
Many apps store messages, contacts and usage data in SQLite databases. Digital investigations must provide reliable facts, but must not over-interpret technical evidence.
How is such a technical investigation carried out in practice?+
We distinguish between active records, transaction remnants, deleted or reconstructed content, and check their database context.
Does the investigation always yield a clear result that either incriminates or exonerates the person concerned?+
A reconstructed fragment does not automatically carry the same weight as a fully active data set.
Is there a legal basis for this?+
The responsibility for conducting the investigation and making a legal assessment remains with the relevant law enforcement authorities. Under Section 160 of the Code of Criminal Procedure, the public prosecutor’s office investigates the facts of the case and is required to establish both incriminating and exonerating circumstances.

LanCologne – IT Forensics for Criminal Investigation Authorities

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now