IT Forensics · Solicitors & Criminal Defence Lawyers
How can the defence arrange for a technical verification of the hash values and integrity checks contained in the investigation file?
Hash values are often used as proof of the integrity of a digital dataset. It is important for the defence to understand which datasets have been compared with one another.
Why this question is important for a criminal defence
Having examined the case files, it is important to distinguish the technical facts from the summary assessments of the investigation. Digital evidence, in particular, can appear plausible in reports, even though the scope of data extraction, temporal context, attribution to individuals or data context may require a more nuanced assessment.
Technical investigative approach
We check the algorithm, the time at which the calculation was carried out, the source and destination of the comparison, and whether the documented values actually relate to the same dataset.
Where the limits of what can be said lie
A matching hash value confirms the identity of two sets of data within the framework of the method used, but not the accuracy or authorship of the information they contain.
Why LanCologne?
Having examined the case files, the added value of an independent IT forensic review does not lie in casting blanket doubt on the work carried out by the authorities. Rather, the key point is to trace the key digital findings back to their actual data sources.
LanCologne therefore checks which evidence, image or extraction was examined, which filters and parsers were used, and whether the conclusion drawn from this is technically supported by the primary data. Where an official finding is correct, it is confirmed. Where a statement goes beyond the scope of the data, this limitation is explained in a way that is easy to follow.
Particular attention is paid to the distinction between a device, an account, a session and a natural person, as well as between automated system behaviour and deliberate user action. Contradictory findings, incomplete data sources and technically plausible alternative explanations are also taken into account.
The aim is to establish a sound technical basis for the defence that will also stand up to subsequent scrutiny by the public prosecutor’s office, other experts and the court.
How we work
Incriminating, exculpatory and inconclusive findings
A technical review is not an attempt to find an error in the investigation file at all costs. Technically correct findings are confirmed. If contradictory findings, incomplete data or alternative technical explanations are identified, these are also documented in a clear and comprehensible manner. This provides the defence with a realistic and robust factual basis.
Understandable to the defence lawyer – reproducible for other forensic scientists
The main finding is formulated clearly and without unnecessary technical jargon. Data sources relevant to the investigation, hash values, IDs, time references, raw data locations and methodological steps are documented in such a way that another qualified IT forensic expert can technically verify the key findings.
LanCologne as an independent source of technical support for the defence
If a criminal defence lawyer wishes to have a digital key analysis independently verified after reviewing the case files, LanCologne provides support in the form of an objective and unbiased IT forensic re-examination. The aim is to provide a clear answer as to what the available technical data actually proves – and what it does not.
Legal framework
The defence counsel’s right to inspect files and examine exhibits is governed by section 147 of the Code of Criminal Procedure. Under paragraph 1, the defence counsel is authorised to inspect the files before the court or, in the case of an indictment, those to be submitted to the court, and to examine exhibits held in official custody. So long as the conclusion of the investigations has not yet been noted in the files, access or inspection may, pursuant to paragraph 2, be restricted subject to the conditions set out therein. Under Section 147(3), the defence counsel must not, in any stage of the proceedings, be denied access to expert reports. In the preliminary proceedings, the public prosecutor’s office generally decides on the granting of access to the files (Section 147(5)).
These rights are vested in the defence counsel, not in LanCologne. A technical cross-check therefore requires that the defence be able to lawfully make the relevant documents or data available. By being privately commissioned, LanCologne does not acquire any right of its own to inspect, examine files or access information held by the Crown Prosecution Service or the police.
Section 160(2) of the Code of Criminal Procedure (StPO) requires the public prosecutor’s office to investigate both incriminating and exculpatory circumstances. Under Section 163a(2) of the StPO, evidence requested by the accused in their defence must be obtained if it is relevant. An independent technical examination can therefore provide factual evidence which the defence counsel can assess with a view to suggesting further evidence or making applications; the procedural decision is taken by the defence counsel or the competent law enforcement authority.
Insofar as electronic evidence that has been officially seized, confiscated or examined is concerned, particular attention must be paid to sections 94, 98 and 110 of the Code of Criminal Procedure. Section 110(3) governs the examination of electronic storage media by authorised state authorities and, subject to certain conditions, also storage media located in separate premises. This does not confer any sovereign powers on a privately commissioned IT forensic expert.
An IT forensic expert privately engaged by the defence is not, by virtue of that engagement alone, a formally appointed expert witness within the meaning of Sections 72 et seq. of the Code of Criminal Procedure. These procedural roles are expressly distinguished from one another.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can connection and communication data be checked for technical inconsistencies?
- How are corporate accounts and domain registrations assessed from a criminal defence perspective?
- Could a scheduled task or automation explain a supposed user action?
- Could a background service explain file access that appears to be placing a strain on the system?