IT forensics · Investigative authorities
Wie werden Firewall-Logs als Beweismittel in Ermittlungen genutzt?
Firewalls können Netzwerkverbindungen, Blockierungen und NAT-Zuordnungen dokumentieren.
Why this question is important to the investigating authorities
In complex criminal investigations, a single technical match is rarely sufficient. The crucial factor is whether references to devices, accounts, users, Server and the cloud are technically and clearly separated from one another and are subsequently linked only where the data actually supports such a connection.
Technical investigative approach
Wir prüfen Zeitbasis, Regelwerk, Quell-/Zieladressen, Ports, NAT und Aufbewahrung und korrelieren mit Endgeräten.
Where the limits of what can be said lie
Eine erlaubte Verbindung beweist nicht den übertragenen Inhalt oder die Identität der handelnden Person.
Why LanCologne?
LanCologne complements the in-house capabilities of an investigating authority where a complex, specialised technical issue, independent validation or further in-depth analysis is required. The specific investigative question always remains the starting point.
We do not work with the aim of confirming a pre-existing hypothesis. Technical findings that point to guilt or innocence are assessed using the same criteria. This is particularly important in complex corporate, cloud and multi-device environments, as identical content, accounts or network traces can often have several technically plausible causes.
The source data is clearly documented. Where technically feasible, the analysis is carried out on verified backups or suitable working copies. Critical results are not accepted solely on the basis of an automated report. Their origin, the logic behind their generation and the system context are checked; where necessary, a key finding is validated using the primary data or an independent secondary method.
The findings are formulated in such a way that investigators and prosecutors can identify what has been technically proven, what is merely supported by evidence, what contradictory findings exist, and which points remain unresolved. The key technical basis remains clearly documented for subsequent judicial review.
From the investigation brief to a reliable statement
Findings that support or refute the case
The investigation remains open-ended. If several reliable sources confirm a line of inquiry, their technical relationship is presented in a way that can be verified. If other sources contradict this, or if an alternative technical explanation remains possible, this is also documented. It is not the expert’s role to resolve contradictions in favour of a desired narrative.
Understandable to the investigating authorities, the defence and the court
The main finding is formulated in clear language. The technical section documents the sources, time references, identities, integrity information and correlations that are essential for the review. This enables another qualified IT forensic expert to verify the key findings at a later date using the same dataset.
LanCologne as an independent external IT forensics expert
When a law enforcement agency needs to have a complex digital case examined in depth or independently, LanCologne provides support in the form of a transparent, unbiased investigation. The focus is not on the number of technical hits, but on providing a reliable answer to the specific question under investigation.
Legal framework
The responsibility for conducting the investigation and making legal assessments remains with the competent law enforcement authorities. Section 160 of the Code of Criminal Procedure (StPO) obliges the public prosecutor’s office to establish the facts of the case and expressly requires it to investigate both incriminating and exonerating circumstances. Under Section 161 of the Code of Criminal Procedure, it may conduct investigations itself or have them carried out by authorities and police officers; Section 163 of the Code of Criminal Procedure sets out the duties of the police in preliminary investigations.
In principle, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. Section 161a(1) of the StPO requires experts to appear before the Public Prosecutor’s Office when summoned and to submit their expert report; unless otherwise provided, the provisions of Section 7 of Book I apply mutatis mutandis. Section 82 of the Code of Criminal Procedure (StPO) concerns the form in which expert reports are to be submitted during the pre-trial proceedings.
Seizure and confiscation are governed in particular by Sections 94 and 98 of the Code of Criminal Procedure. Section 110(3) of the Code of Criminal Procedure governs the examination of electronic storage media and, subject to the conditions set out therein, also permits the securing of data relevant to the investigation. Decisions on the lawfulness, scope and ordering of such measures are taken by the competent state authorities, not LanCologne.
Under Section 1(3) of the JVEG, engagement by the police or another law enforcement authority on behalf of, or with the prior approval of, the public prosecutor’s office is treated as equivalent to engagement by the public prosecutor’s office for the purposes of remuneration.
Frequently Asked Questions
LanCologne – IT Forensics for Criminal Investigation Authorities
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- Wie werden Proxy- und Web-Gateway-Logs im Unternehmensnetz bewertet?
- Wie werden DHCP- und Netzwerkzugangsdaten zur Gerätezuordnung verwendet?
- Wie werden WLAN-Controllerdaten in Ermittlungsverfahren bewertet?
- Kann die Nutzung eines bestimmten Arbeitsplatzrechners im Unternehmensnetz nachgewiesen werden?