IT Forensics · Solicitors & Criminal Defence Lawyers
Welche Bedeutung hat eine Formatierung oder Neuinstallation für die Verteidigung?
Eine Neuinstallation oder Formatierung wird mitunter als bewusste Spurenbeseitigung interpretiert, kann aber auch reguläre Ursachen haben.
Why this question is important for a criminal defence
During a criminal investigation, a digital trace that appears to be unequivocal can have a significant impact on the assessment of the suspicion of a crime. It is therefore crucial for the defence to determine whether the technical interpretation is in fact valid, or whether context, system architecture, incomplete data or alternative causes need to be taken into account.
Technical investigative approach
Wir prüfen Installations-, Partitions-, Dateisystem- und Wiederherstellungsspuren sowie zeitliche Zusammenhänge mit Wartung, Defekten oder Gerätewechsel.
Where the limits of what can be said lie
Die technische Feststellung einer Formatierung erlaubt ohne zusätzliche Spuren keine Aussage über Motiv oder Vorsatz.
Why LanCologne?
LanCologne supports the defence by providing an independent technical assessment, not by prescribing a specific outcome. A finding that exonerates the defendant is only valuable if its origin, the reasoning behind it and its limitations remain transparent to the Crown Prosecution Service, another expert witness and, subsequently, the court.
The starting point is therefore always the specific defence issue. We distinguish between device-related, account-related and session-related aspects, and between natural persons, just as consistently as we distinguish between technical feasibility, actual use and verifiable actions.
Data accessed lawfully is secured in a traceable manner, insofar as this is technically possible. Automated matches relevant to decision-making are not accepted without verification. Where necessary, checks are carried out at file system, database or raw data level, or using a second method appropriate to the subject matter.
The result may be conclusive, inconclusive or open-ended. This openness regarding the result safeguards the quality of the investigation and prevents an explanation that is merely technically possible from being presented as an established fact.
How we work
Incriminating, exculpatory and inconclusive findings
The defence does not benefit from a favourable expert report. If the data supports the allegation, this is stated just as clearly as any credible evidence to the contrary. If several explanations remain possible or if essential data required for a definitive conclusion is missing, this uncertainty is explicitly documented.
Understandable to the defence lawyer – verifiable technically by other forensic experts
The main finding is explained in clear language. The technical section documents the data sources, integrity information, time references, artefacts and investigation steps relevant to a review. This enables another qualified IT forensic expert to carry out a technical review of the reasoning.
LanCologne as an independent source of technical support for the defence
If a criminal defence lawyer wishes to have a digital factual issue independently examined during the pre-trial investigation, LanCologne provides support in the form of a transparent and unbiased IT forensic investigation. The aim is to establish a factually sound and technically robust basis – regardless of whether it confirms, qualifies or technically contradicts the allegation.
Legal framework
The defence may become involved as early as the pre-trial investigation stage. Under section 137(1) of the Code of Criminal Procedure (StPO), the accused may engage a defence counsel at any stage of the proceedings. Section 160(2) of the Code of Criminal Procedure (StPO) obliges the public prosecutor’s office to investigate both incriminating and exculpatory circumstances and to ensure the preservation of evidence which is at risk of being lost. Under Section 163a(2) of the Code of Criminal Procedure, evidence which the accused requests to be taken in his or her defence must be taken if it is relevant.
Under section 147 of the Code of Criminal Procedure (StPO), the defence counsel is entitled to inspect files and examine evidence. Pursuant to paragraph 2, restrictions may apply prior to the conclusion of the investigation; however, pursuant to paragraph 3, the defence counsel must not be denied access to expert reports at any stage of the proceedings. LanCologne does not have its own right of access to the case file under Section 147 of the Code of Criminal Procedure. A cross-check requires that the defence be able to lawfully make the relevant documents or data available for technical examination.
An IT forensic expert privately engaged by the defence does not, by virtue of that engagement alone, become a formally appointed expert witness under sections 72 et seq. of the Code of Criminal Procedure. These roles are explicitly distinguished in our statements and on our landing pages.
Where digitally stored evidence held in official custody or seized is at issue, the competent law enforcement agencies and courts shall decide on its seizure, confiscation, examination and access. In particular, sections 94, 98 and 110 of the Code of Criminal Procedure do not confer any sovereign powers on LanCologne.
When working confidentially with the defence, the legal requirements regarding the protection of professional secrecy must be observed in a nuanced manner. Sections 53 and 53a of the Code of Criminal Procedure (StPO) govern the rights to refuse to give evidence of persons bound by professional secrecy and, subject to certain conditions, of persons assisting in proceedings; Section 97 StPO contains prohibitions on seizure, with specific conditions and exceptions; Section 160a StPO sets out rules of protection for investigative measures. Section 203(3) and (4) of the Criminal Code (StGB) permits, subject to the conditions set out therein, the necessary involvement of other persons assisting in the proceedings and establishes obligations of confidentiality. This does not imply blanket, automatic protection for every file held by an external IT forensic expert.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- Wie belastbar sind wiederhergestellte oder fragmentierte Dateien als Beweis gegen den Mandanten?
- Kann eine Provider- oder Gegenstellenauskunft eine lokale Geräteauswertung zugunsten des Mandanten korrigieren?
- Wie werden mehrere Geräte mit demselben Account aus Verteidigersicht unterschieden?
- Welche Aussagekraft haben MFA-Ereignisse und Session-Tokens für die Personenfrage?