This overview brings together all the questions and answers relating to IT forensics for solicitors and criminal defence lawyers at LanCologne – from the preliminary investigation through interim proceedings and the main hearing to appeals, cassation appeals, retrials and the technical review of expert reports. Click on a category to view the relevant questions.
Interim proceedings and the indictment
- How can a comprehensive, independent IT forensic investigation support the defence strategy in the face of criminal charges?
- How can an IT forensic examination, following the service of the indictment, assist the defence in the preliminary proceedings?
- How can the defence make the necessary technical preparations for raising digital objections to the commencement of the main hearing?
- How can individual supplementary investigations be prepared from a technical perspective prior to the decision to open proceedings?
- How can it be verified whether the indictment sets out the findings of a digital investigation in greater detail than the investigation file?
- How can the digital allocation of individuals be reviewed again before the decision to open proceedings is taken?
- How can the defence verify whether the digital timeframe alleged in the indictment is technically accurate?
- How can an alleged sequence of digital events be examined for internal inconsistencies prior to the main hearing?
- How can it be determined whether a piece of digital evidence is even relevant to the specific charge?
- How can the defence identify incomplete digital chains of evidence once charges have been brought?
- How can a client’s computer be examined independently prior to any charges being brought?
- How can an expert report commissioned by the authorities be subjected to a technical review during interim proceedings?
- How can the absence of technical evidence be objectively assessed in interim proceedings?
- How can the defence ensure that exculpatory digital evidence remains available after the indictment has been issued?
- How can the defence arrange for technical findings used as a pretext to be examined before the decision on whether to open proceedings is made?
- How can it be ascertained whether digital communications have been included in the indictment in their entirety or only selectively?
- How can the defence arrange for a check to be carried out to ensure that deleted messages were correctly interpreted during the preliminary proceedings?
- How can an alleged data leak be technically verified prior to the decision to open an investigation?
- How can the defence arrange for an investigation into whether remote access may have influenced the digital sequence of events alleged in the indictment?
- How can malware be investigated as an alternative cause of an alleged digital incident?
- How can the defence draw up a list of technical questions for the taking of further evidence during the interim proceedings?
- How should a defence counsel’s IT forensic report be structured for the preliminary proceedings?
- How can the defence present technical findings in such a way that a court without specialist IT knowledge can understand them?
- How can the defence organise the IT forensic preparations for the trial following a decision on the opening proceedings?
Trial
- How can an IT forensic defence dossier be prepared to serve as the technical basis for the trial?
- How can the defence prepare, from an IT forensics perspective, for the taking of digital evidence during the trial?
- How can the methodological limitations of an IT forensic report be clearly explained for the trial?
- How can the defence highlight a technical inconsistency between the expert report and the primary data during the trial?
- How can an expert’s incorrect or unclear interpretation of a time be examined during the trial?
- How can an expert’s alleged identification of a person be critically examined from a professional perspective?
- How can the defence ascertain whether an expert has sufficiently ruled out alternative technical causes?
- How can digital evidence, such as photographs, tables and screenshots, be correctly categorised from a technical perspective during the trial?
- How can a digital timeline be presented and examined in a way that is easy to follow during the main hearing?
- How can the defence arrange for technical checks to be carried out on discrepancies between a witness’s testimony and digital evidence?
- How can one check whether several digital traces are in fact independent of one another?
- How can the defence provide a technical explanation for a negative digital finding during the trial?
- How can an IT forensic expert acting on behalf of the defence provide technical support during the trial without assuming the role of the defence lawyer or a court-appointed expert?
- How can a motion to introduce evidence relating to a digital object be prepared with technical precision?
- How can the defence respond professionally to new digital evidence during the trial?
- How can the defence arrange for an assessment to be carried out to determine whether a technical term mentioned during the trial actually proves the alleged event?
- How can the defence verify whether a demonstration of forensic software at the trial fully reflects the underlying findings?
- How can the defence respond professionally and promptly following a single digital evidence collection?
- How can a criminal defence lawyer technically prepare a statement under Section 257 of the Code of Criminal Procedure (StPO) regarding the findings of a digital forensics investigation?
- How can it be verified whether an electronic document read out during the main hearing is technically identical to the original?
- How can the defence technically prepare and check electronic documents for the self-reading procedure?
- How can an electronic export of chat messages be technically verified before it is used in the main hearing?
- How can the defence verify whether a search query shown during the trial can be reproduced?
- How can the defence check whether a filtered view in the main hearing is concealing relevant counter-evidence?
- How can a technical finding from forensic software be explained without reference to the manufacturer?
- How can the defence deal with a parser error that only becomes apparent during the trial?
- How can it be verified whether a digital source of evidence still contains the same data at the time of the trial as it did when it was secured?
- How can the defence check whether a digital evidence file is complete or merely a fragment?
- How can the defence have an alleged anti-forensics finding examined during the trial?
- How can the defence verify whether evidence relating to a VPN, proxy or Tor connection is in fact linked to the alleged activity?
- How can the defence check whether an IP address is being attributed to a particular person to an excessive extent during the trial?
- How can a final IT forensic evidence matrix support the defence towards the end of the trial?
- How can the defence reorganise digital evidence for a main appeal hearing?
Appeals, reviews and legal remedies
- How can a digital forensics investigation assist in preparing an appeal in technically complex criminal cases?
- How can a digital finding that remained unclear at first instance be re-examined on appeal?
- How can the defence arrange for new digital evidence to be examined by experts during an appeal?
- How can the defence prepare technical questions for an expert witness at the main appeal hearing?
- How can an IT forensic investigation support the preparation for an audit without replacing legal advice?
- How can the defence clearly distinguish between technical facts and points of law relevant to an appeal?
- How can a technical issue be documented accurately for a defence counsel in an appeal?
- How can one check whether a digital finding is described differently in the judgement, hearing documents and expert reports?
- How can the defence ensure that any potential shortcomings in the technical documentation are addressed for the purposes of the appeal review?
Retrial
- How can the defence verify whether a piece of digital evidence discovered at a later date is in fact new?
- How can newly discovered digital evidence be forensically preserved once a judgement has become final?
- How can the defence arrange for an assessment to be carried out to determine whether new insights into software or parsers might alter a previous digital finding?
- How can a device or data archive that is decrypted at a later date be technically classified as part of a closed case?
- How can a backup that has been restored at a later date be examined as potential new counter-evidence?
- How can the defence arrange for a technical assessment of new cloud or provider data once the proceedings have concluded?
- How can one check whether a new digital finding actually refutes an earlier key finding?
- How can the defence arrange for a technical preliminary review of a potential recommendation for a retrial without overestimating its significance?
Review and cross-checking of the report
- How can the defence address technical inconsistencies between several expert reports or investigation reports?
- How can an alternative digital version of events be technically verified in such a way that it represents more than just a possibility?
- How can a criminal defence lawyer prepare, from a technical perspective, for the cross-examination of a digital forensics expert?
- What questions should be put to an expert if their report is based predominantly on automated forensic reports?
- How can the defence check whether an expert witness has in fact answered the specific question of evidence?
- Can an email technically prove that the client was not the actual sender?
- How can the defence verify the completeness of the data set used by the expert?
- How can the defence assess, from a technical perspective, whether there are objective grounds for calling a further expert witness?
- How can the defence assess whether existing digital evidence is technically suitable for further evidence-gathering?
- How can the defence ensure that technical uncertainty is quantified or described in a clear and comprehensible manner in an expert report?
- How can an IT forensic report be updated following the taking of evidence?
- How does a comprehensive, independent IT forensic assessment support the defence in cases involving the gathering of complex digital evidence?
- How can the defence check whether a PDF forensic report has been altered or abridged compared with the original analysis?
- Can a digital timeline technically disprove an alleged sequence of events?
- How can the defence check whether different forensic programmes interpret the same digital evidence differently?
- How can the defence check whether digital data collected at a later date is comparable to an earlier forensic image?
- How can the defence assess technical discrepancies between an original device and its forensic extract?
- How can the defence verify whether a deleted data record was in fact deleted intentionally?
- How can the defence check whether encryption is being over-interpreted as incriminating behaviour?
- How are time zones and faulty device clocks taken into account when findings are exculpatory?
- How can the defence respond to a change in the technical facts presented during the trial?
- How can a criminal defence lawyer arrange for a technical review of an expert report that has already been submitted?
- How are SQLite WAL and journal data categorised in a forensic analysis?
- How can an official IT forensic report be technically reviewed following access to the case file?
- How does the defence determine whether data extracted from a smartphone or computer is incomplete?
- How is a seizure or extraction report interpreted from a defence lawyer’s perspective?
- How can the defence determine whether any relevant data has been excluded by filters during the analysis?
- How are search terms and keyword matches from an official forensic report verified?
- How is a parser output checked against the underlying raw data?
- How can the defence arrange for a check to be carried out to ascertain whether relevant data sources were overlooked in the authorities’ analysis?
- How is a distinction made between an investigation report and primary technical findings?
- How can an official timeline be independently verified?
- How is it verified whether chat messages have been taken out of their technical context in the investigation report?
- How is the technical validity of an official account or personal assignment verified?
- How are local device data and cloud data synchronised within the investigation file?
- How is location data from various sources cross-checked in the investigation file?
- How are IP and provider data from the investigation file subjected to a technical review?
- How is photo and video metadata from an investigation file validated independently?
- How is the version history and creation history of a document in the investigation file checked?
- How are deleted and recovered data cross-checked in an official report?
- How are SQLite, WAL and journal findings from an official investigation validated?
- How are time zones and time conversions assessed in an official report?
- How does the defence identify technical error messages or gaps in the analysis within the investigation file?
- How are key findings from the investigation file independently validated?
- How can the defence identify exculpatory digital evidence that was not addressed in the investigation report?
- How can LanCologne draw up a list of technical questions to inform the defence strategy going forward?
- How can the defence arrange for a review to be carried out to determine whether a preliminary investigation report draws technical conclusions that are too strong?
- How can it be verified whether alternative technical explanations have been given sufficient consideration in the investigation file?
- How can the defence arrange for audio or video files to be examined to determine whether they have been re-encoded or edited?
- How is a defence-led IT forensic report structured from a technical perspective?
- How should a private expert report commissioned by the defence be documented in such a way that it remains technically verifiable at a later date?
- How can a defence team present a counter-argument to the public prosecutor’s office or the investigating authority in an objective manner?
Technical system logs, devices and data integrity
- How are corporate accounts and domain registrations assessed from a criminal defence perspective?
- Could a scheduled task or automation explain a supposed user action?
- Could a background service explain file access that appears to be placing a strain on the system?
- Can a print job be reliably attributed to the client?
- What is the significance of connecting an external storage device without any evidence of a copying process having taken place?
- Can a virtual machine assign a resource-intensive activity to a different system context?
- How are encrypted containers or inaccessible data areas classified to ensure a fair assessment?
- What significance does formatting or reinstalling have for the defence?
- How reliable are recovered or fragmented files as evidence against the client?
- Can information provided by a service provider or a remote site correct a local device analysis?
- From a security perspective, how are multiple devices using the same account distinguished from one another?
- How relevant are MFA events and session tokens to the issue of identity?
- How are missing logs or gaps in the log records assessed from a defence perspective?
- From a defence lawyer’s perspective, how can the integrity of officially secured digital evidence be called into question?
- Once the defence lawyer has been granted access to the case file, how can they verify which pieces of digital evidence have actually been analysed?
- How is it verified that a forensic image actually corresponds to the seized data carrier?
- How can the defence arrange for a technical verification of the hash values and integrity checks contained in the investigation file?
- How can connection and communication data be checked for technical inconsistencies?
Preliminary investigations and before indictment
- Can an early IT forensic investigation reveal exculpatory evidence whilst the preliminary investigation is still ongoing?
- How can a criminal defence lawyer ensure that digital exculpatory evidence at risk of being lost is secured at an early stage?
- Is it possible to carry out a technical review of the client’s statement prior to giving evidence?
- Can a digital activity be linked to the client personally, or only to a device or account?
- How are shared computers or smartphones assessed from a criminal defence perspective?
- Could a compromised account be an alternative explanation for the alleged offence?
- Can remote access account for an action attributed to the client?
- Can malware provide an alternative technical explanation for a criminal charge?
- How can the client’s smartphone be examined at an early stage to exonerate them?
- Can a chat history exonerate the client or put an allegation into perspective?
- Can a browser or search history refute an allegation or put it into a different perspective?
- How can location data be assessed as a potential means of reducing the burden?
- How can backups reveal previous states to the benefit of the defence?
- How is deleted data assessed from a criminal defence perspective?
- Why might independent IT forensic support be useful for a criminal defence, from the preliminary investigation right through to the end of the trial?
- When can the absence of a digital artefact exonerate the client?
- From the defence’s perspective, can an alleged data leak via USB be investigated?
- How can a technically sound exculpatory finding be presented before the investigation has been concluded?
Other questions
- How can digital evidence to the contrary, which has only recently come to light, be technically verified at short notice?
- How can the defence present the key digital findings for the closing statement in a way that is academically sound?
- How can the defence prevent technical possibilities from being treated as proven facts at the conclusion of the taking of evidence?
- How can the defence, following a judgement, check whether a key piece of digital evidence has been accurately reproduced in the judgement from a technical point of view?
- How can a criminal defence lawyer arrange for a technical expert to examine technical inconsistencies in the written grounds for the judgement?
- How can one verify whether a digital timeline assumed in the judgement is technically feasible?
- How can one verify whether the attribution of a device, account or person, as assumed in the judgement, is technically feasible?
- Could cloud synchronisation offer a different explanation for a user’s apparent action?
- How can the defence arrange for a review to be carried out to establish whether a technical possibility was treated as an established sequence of events in the judgement?
- How can a comprehensive IT forensic case timeline support the defence across multiple courts?
- How much weight does an IP address carry from a criminal defence perspective?
- Can the use of a VPN or proxy alter the attribution of internet activity?
- How can a screenshot be independently verified as incriminating evidence?
- From a criminal defence perspective, how can the authenticity of an audio recording be verified using technical methods?
- How can photographs or videos be technically categorised as incriminating evidence?
- Can the history of a digital document’s creation influence the charge?
- How can an alleged subsequent alteration to a PDF or document be verified?
- Is it possible to determine whether a file was actually downloaded from the internet?
- Can access via a network share be distinguished from a local file transfer?
- From the defence’s perspective, can an alleged upload to a private cloud be investigated?
- How can one verify whether an official report has incorrectly treated several interrelated lines of evidence as multiple pieces of independent evidence?
- How can the defence arrange for a check to be carried out to determine whether an incriminating finding is based solely on a single artefact?
- How is it determined whether incriminating files were in fact accessible to the client?
- How can one check whether inappropriate content has been automatically downloaded onto the device?
- How is it determined whether a file found in a backup originates from a backup rather than from active use?
- How can the defence arrange for a check to be carried out to see whether thumbnail or cache files have been over-interpreted?
- How are search indexes from the investigation file assessed from the defence counsel’s perspective?
- How can you check whether a file has simply been opened automatically or has been processed by a programme?
- How can the defence arrange for an investigation to be carried out to determine whether several users were active on the same system at the same time?
- How are automatic login and automatic session recovery taken into account in the investigation file?
- How can one check whether a piece of software was actually run, rather than simply installed?
- How can the defence arrange for an investigation to determine whether a piece of software that has since been uninstalled was in fact relevant?
- How are administrative rights and their actual use assessed from a defence lawyer’s perspective?
- How can one check whether a file move has been mistakenly interpreted as a copy operation?
- How can the defence arrange for a check to be carried out to see whether a file has simply been renamed?
- How are file timestamps correctly interpreted after copying, moving or restoring?
- How can the defence arrange for a check to be carried out to determine whether cloud versions show an older or different version of a document?
- How can you check whether a screenshot comes from another source or another device?