IT Forensics · Solicitors & Criminal Defence Lawyers
How can the defence arrange for an investigation to be carried out to determine whether several users were active on the same system at the same time?
On terminal servers, multi-user systems or shared computers, several sessions may be active at the same time.
Why this question is important for a criminal defence
Particularly in the case of digital evidence, even minor differences in the data source, system context or temporal semantics can significantly alter the interpretation of a finding. It is therefore crucial for the defence to determine whether the incriminating conclusion actually follows from the primary data, or whether a more detailed technical assessment is required.
Technical investigative approach
We monitor session IDs, login and logout events, user processes, remote access and activity over time.
Where the limits of what can be said lie
The existence of a session does not automatically prove that it was actively in use at a specific point in time.
Why LanCologne?
Once the case files have been examined, or as soon as the defence has lawfully obtained the relevant technical documents, an independent cross-check can reveal the actual evidential value of digital findings. LanCologne does not work with the aim of necessarily finding an error in the investigation file.
We examine what technical information the primary data actually contains. Where an official finding is correct, it is confirmed. Where a report derived from device or account data implies a more detailed personal identification, we examine the additional connecting facts required for this. We also take into account automated system processes, synchronisation, migration, backups and alternative technical causes.
Parser or report findings that are relevant to the decision are validated, where necessary, on the basis of the underlying data or a second, technically appropriate method. Data gaps, conflicting sources and alternative explanations that cannot be resolved are clearly identified.
The results are presented in such a way that the defence lawyer can recognise their technical significance for his defence strategy and that another qualified IT forensic expert can subsequently verify the key findings.
How we work
Incriminating, exculpatory and inconclusive findings
An independent review is only credible if incriminating findings are confirmed as soon as the data supports them. Similarly, exonerating counter-findings or unresolvable uncertainties are clearly stated. A procedure that is merely technically possible is not presented as an established fact.
Understandable to the defence lawyer – verifiable technically by other forensic experts
The main finding is explained in clear language. Data sources relevant to the investigation, integrity information, time references, IDs, raw data locations and methodological steps are documented in such a way that another qualified IT forensic expert can technically verify the key findings.
LanCologne as an independent source of technical support for the defence
If a criminal defence lawyer wishes to have a digital forensic report or a technical conclusion drawn from the investigation file independently verified, LanCologne provides support in the form of an objective and unbiased second opinion. The aim is to arrive at a reliable answer as to what the available data actually proves – and where its evidence ends.
Legal framework
The defence counsel’s right to inspect files and examine exhibits is governed by section 147 of the Code of Criminal Procedure. Under paragraph 1, the defence counsel is authorised to inspect the files held by the court or to be submitted in the event of an indictment, and to examine exhibits held in official custody. Prior to the conclusion of the investigation, access under paragraph 2 may be restricted subject to the conditions set out therein. Under paragraph 3, the defence counsel may not be denied access to expert reports at any stage of the proceedings.
These rights are vested in the defence counsel, not LanCologne. A technical cross-check carried out by a privately commissioned IT forensic expert requires that the defence be able to lawfully provide the relevant documents or data. Commissioning such an expert does not confer on LanCologne any right of its own to inspect files, examine evidence or access data held by the Crown Prosecution Service or the police.
Section 160(2) of the Code of Criminal Procedure (StPO) expressly obliges the public prosecutor’s office to investigate both incriminating and exculpatory circumstances. Under Section 163a(2) of the Code of Criminal Procedure, evidence requested by the accused in their defence must be taken if it is relevant. An independent technical examination may therefore yield facts and counter-findings, the admissibility of which in court proceedings is assessed by the defence counsel.
Where electronic evidence that has been officially seized, confiscated or examined is concerned, particular attention must be paid to sections 94, 98 and 110 of the Code of Criminal Procedure. These provisions do not confer any public authority powers on a privately commissioned IT forensic expert.
An IT forensic expert privately engaged by the defence is not, by virtue of this engagement alone, a formally appointed expert witness within the meaning of sections 72 et seq. of the Code of Criminal Procedure. Private expert reports, technical advice and formal appointment as an expert witness must be distinguished from one another in legal proceedings.
If the investigations do not provide sufficient grounds for bringing a public prosecution, the Public Prosecutor’s Office will discontinue the proceedings in accordance with section 170(2) of the Code of Criminal Procedure. A technical finding by the defence does not guarantee such a decision, but may form a relevant part of the factual basis.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How are automatic login and automatic session recovery taken into account in the investigation file?
- How can one check whether a piece of software was actually run, rather than simply installed?
- How can the defence arrange for an investigation to determine whether a piece of software that has since been uninstalled was in fact relevant?
- How are administrative rights and their actual use assessed from a defence lawyer’s perspective?