IT forensics · Investigative authorities

Wie werden WLAN-Controllerdaten in Ermittlungsverfahren bewertet?

Zentrale WLAN-Systeme können Verbindungen zu Access Points, Authentifizierungen und Roaming protokollieren.

Enquire without obligation

Why this question is important to the investigating authorities

In complex criminal investigations, a single technical match is rarely sufficient. The crucial factor is whether references to devices, accounts, users, Server and the cloud are technically and clearly separated from one another and are subsequently linked only where the data actually supports such a connection.

Technical investigative approach

Wir prüfen Gerätekennungen, Access Points, Zeitbezüge und Authentifizierung und korrelieren sie mit Endgeräten.

Where the limits of what can be said lie

Eine WLAN-Verbindung stützt einen Gerätebezug zum Netzwerk, nicht automatisch die Anwesenheit einer bestimmten Person.

Why LanCologne?

LanCologne complements the in-house capabilities of an investigating authority where a complex, specialised technical issue, independent validation or further in-depth analysis is required. The specific investigative question always remains the starting point.

We do not work with the aim of confirming a pre-existing hypothesis. Technical findings that point to guilt or innocence are assessed using the same criteria. This is particularly important in complex corporate, cloud and multi-device environments, as identical content, accounts or network traces can often have several technically plausible causes.

The source data is clearly documented. Where technically feasible, the analysis is carried out on verified backups or suitable working copies. Critical results are not accepted solely on the basis of an automated report. Their origin, the logic behind their generation and the system context are checked; where necessary, a key finding is validated using the primary data or an independent secondary method.

The findings are formulated in such a way that investigators and prosecutors can identify what has been technically proven, what is merely supported by evidence, what contradictory findings exist, and which points remain unresolved. The key technical basis remains clearly documented for subsequent judicial review.

From the investigation brief to a reliable statement

1Define the scope of the investigation, the extent of the enquiry and the technical system landscape.
2Check whether additional data sources or contextual information are required to make a reliable statement.
3Clearly document evidence and data sources and verify their integrity as far as possible.
4Separate device, account, session, Server and cloud references from one another.
5Define the test hypothesis to be tested and technically plausible alternative hypotheses.
6Systematically analyse relevant primary sources and evaluate key logs or artefacts within the system context.
7Correlate findings from different sources in terms of timing and methodology.
8Independently validate automated matches relating to points relevant to the evidence.
9Openly document inconsistencies, gaps in retention and technical limitations.
10Answer the research question clearly and enable subsequent academic scrutiny.

Findings that support or refute the case

The investigation remains open-ended. If several reliable sources confirm a line of inquiry, their technical relationship is presented in a way that can be verified. If other sources contradict this, or if an alternative technical explanation remains possible, this is also documented. It is not the expert’s role to resolve contradictions in favour of a desired narrative.

Understandable to the investigating authorities, the defence and the court

The main finding is formulated in clear language. The technical section documents the sources, time references, identities, integrity information and correlations that are essential for the review. This enables another qualified IT forensic expert to verify the key findings at a later date using the same dataset.

LanCologne as an independent external IT forensics expert

When a law enforcement agency needs to have a complex digital case examined in depth or independently, LanCologne provides support in the form of a transparent, unbiased investigation. The focus is not on the number of technical hits, but on providing a reliable answer to the specific question under investigation.

Legal framework

The responsibility for conducting the investigation and making legal assessments remains with the competent law enforcement authorities. Section 160 of the Code of Criminal Procedure (StPO) obliges the public prosecutor’s office to establish the facts of the case and expressly requires it to investigate both incriminating and exonerating circumstances. Under Section 161 of the Code of Criminal Procedure, it may conduct investigations itself or have them carried out by authorities and police officers; Section 163 of the Code of Criminal Procedure sets out the duties of the police in preliminary investigations.

In principle, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. Section 161a(1) of the StPO requires experts to appear before the Public Prosecutor’s Office when summoned and to submit their expert report; unless otherwise provided, the provisions of Section 7 of Book I apply mutatis mutandis. Section 82 of the Code of Criminal Procedure (StPO) concerns the form in which expert reports are to be submitted during the pre-trial proceedings.

Seizure and confiscation are governed in particular by Sections 94 and 98 of the Code of Criminal Procedure. Section 110(3) of the Code of Criminal Procedure governs the examination of electronic storage media and, subject to the conditions set out therein, also permits the securing of data relevant to the investigation. Decisions on the lawfulness, scope and ordering of such measures are taken by the competent state authorities, not LanCologne.

Under Section 1(3) of the JVEG, engagement by the police or another law enforcement authority on behalf of, or with the prior approval of, the public prosecutor’s office is treated as equivalent to engagement by the public prosecutor’s office for the purposes of remuneration.

Frequently Asked Questions

Wie werden WLAN-Controllerdaten in Ermittlungsverfahren bewertet?+
Zentrale WLAN-Systeme können Verbindungen zu Access Points, Authentifizierungen und Roaming protokollieren. In komplexen Ermittlungsverfahren reicht ein einzelner technischer Treffer selten aus.
How is such a technical investigation carried out in practice?+
Wir prüfen Gerätekennungen, Access Points, Zeitbezüge und Authentifizierung und korrelieren sie mit Endgeräten.
Does the investigation always yield a clear result that either incriminates or exonerates the person concerned?+
Eine WLAN-Verbindung stützt einen Gerätebezug zum Netzwerk, nicht automatisch die Anwesenheit einer bestimmten Person.
Is there a legal basis for this?+
The responsibility for conducting the investigation and making a legal assessment remains with the relevant law enforcement authorities. Section 160 of the Code of Criminal Procedure requires the public prosecutor’s office to establish the facts of the case and expressly obliges it to investigate both incriminating and exonerating circumstances.

LanCologne – IT Forensics for Criminal Investigation Authorities

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now