IT Forensics · Solicitors & Criminal Defence Lawyers

How can the defence arrange for a technical verification of the hash values and integrity checks contained in the investigation file?

Hash values are often used as proof of the integrity of a digital dataset. It is important for the defence to understand which datasets have been compared with one another.

Enquire without obligation

Why this question is important for a criminal defence

Having examined the case files, it is important to distinguish the technical facts from the summary assessments of the investigation. Digital evidence, in particular, can appear plausible in reports, even though the scope of data extraction, temporal context, attribution to individuals or data context may require a more nuanced assessment.

Technical investigative approach

We check the algorithm, the time at which the calculation was carried out, the source and destination of the comparison, and whether the documented values actually relate to the same dataset.

Where the limits of what can be said lie

A matching hash value confirms the identity of two sets of data within the framework of the method used, but not the accuracy or authorship of the information they contain.

Why LanCologne?

Having examined the case files, the added value of an independent IT forensic review does not lie in casting blanket doubt on the work carried out by the authorities. Rather, the key point is to trace the key digital findings back to their actual data sources.

LanCologne therefore checks which evidence, image or extraction was examined, which filters and parsers were used, and whether the conclusion drawn from this is technically supported by the primary data. Where an official finding is correct, it is confirmed. Where a statement goes beyond the scope of the data, this limitation is explained in a way that is easy to follow.

Particular attention is paid to the distinction between a device, an account, a session and a natural person, as well as between automated system behaviour and deliberate user action. Contradictory findings, incomplete data sources and technically plausible alternative explanations are also taken into account.

The aim is to establish a sound technical basis for the defence that will also stand up to subsequent scrutiny by the public prosecutor’s office, other experts and the court.

How we work

1Systematically record the investigation file and technical exhibits to which the defence has access.
2Unambiguously link evidence identifiers, images, extractions and reports to one another.
3Examine which data sources actually formed the basis for the damning conclusions.
4Document the scope of the extraction, errors, filters, search terms and time constraints.
5Validate key parser and report findings against primary data and the system context.
6Assess device, account, session and user assignments separately.
7Take time zones, synchronisation and source dependencies into account when performing correlations.
8Look for contradictory findings and alternative explanations that have not yet been considered.
9Explicitly identify technical uncertainties and missing data.
10Document key findings and technical queries in a way that is clear to the defence and can be reproduced.

Incriminating, exculpatory and inconclusive findings

A technical review is not an attempt to find an error in the investigation file at all costs. Technically correct findings are confirmed. If contradictory findings, incomplete data or alternative technical explanations are identified, these are also documented in a clear and comprehensible manner. This provides the defence with a realistic and robust factual basis.

Understandable to the defence lawyer – reproducible for other forensic scientists

The main finding is formulated clearly and without unnecessary technical jargon. Data sources relevant to the investigation, hash values, IDs, time references, raw data locations and methodological steps are documented in such a way that another qualified IT forensic expert can technically verify the key findings.

LanCologne as an independent source of technical support for the defence

If a criminal defence lawyer wishes to have a digital key analysis independently verified after reviewing the case files, LanCologne provides support in the form of an objective and unbiased IT forensic re-examination. The aim is to provide a clear answer as to what the available technical data actually proves – and what it does not.

Legal framework

The defence counsel’s right to inspect files and examine exhibits is governed by section 147 of the Code of Criminal Procedure. Under paragraph 1, the defence counsel is authorised to inspect the files before the court or, in the case of an indictment, those to be submitted to the court, and to examine exhibits held in official custody. So long as the conclusion of the investigations has not yet been noted in the files, access or inspection may, pursuant to paragraph 2, be restricted subject to the conditions set out therein. Under Section 147(3), the defence counsel must not, in any stage of the proceedings, be denied access to expert reports. In the preliminary proceedings, the public prosecutor’s office generally decides on the granting of access to the files (Section 147(5)).

These rights are vested in the defence counsel, not in LanCologne. A technical cross-check therefore requires that the defence be able to lawfully make the relevant documents or data available. By being privately commissioned, LanCologne does not acquire any right of its own to inspect, examine files or access information held by the Crown Prosecution Service or the police.

Section 160(2) of the Code of Criminal Procedure (StPO) requires the public prosecutor’s office to investigate both incriminating and exculpatory circumstances. Under Section 163a(2) of the StPO, evidence requested by the accused in their defence must be obtained if it is relevant. An independent technical examination can therefore provide factual evidence which the defence counsel can assess with a view to suggesting further evidence or making applications; the procedural decision is taken by the defence counsel or the competent law enforcement authority.

Insofar as electronic evidence that has been officially seized, confiscated or examined is concerned, particular attention must be paid to sections 94, 98 and 110 of the Code of Criminal Procedure. Section 110(3) governs the examination of electronic storage media by authorised state authorities and, subject to certain conditions, also storage media located in separate premises. This does not confer any sovereign powers on a privately commissioned IT forensic expert.

An IT forensic expert privately engaged by the defence is not, by virtue of that engagement alone, a formally appointed expert witness within the meaning of Sections 72 et seq. of the Code of Criminal Procedure. These procedural roles are expressly distinguished from one another.

Frequently Asked Questions

Can LanCologne itself request access to the case files under section 147 of the Code of Criminal Procedure?+
No. This right is vested in the defence counsel or, subject to the statutory conditions, in the accused. LanCologne can only carry out technical checks on case files and data that have been lawfully made available.
Does the cross-check assume that the official assessment is incorrect?+
No. The assessment is open-ended. Key findings may be confirmed, qualified or technically refuted.
Does the entire forensic investigation have to be repeated for every report?+
Not necessarily. The scope depends on the specific defence argument and on which technical findings are actually crucial to the charge.
Can LanCologne assist the defence lawyer in referring technical queries to an expert?+
Yes. We can identify technical inconsistencies, gaps in the evidence and limitations in testimony, and use these to draw up a list of technical questions. It is up to the defence lawyer to decide how to use these in court.

LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now