IT Forensics · Solicitors & Criminal Defence Lawyers

How can one check whether a file move has been mistakenly interpreted as a copy operation?

Copying and moving can result in different traces and are not synonymous when it comes to allegations of data leakage.

Enquire without obligation

Why this question is important for a criminal defence

Particularly in the case of digital evidence, even minor differences in the data source, system context or temporal semantics can significantly alter the interpretation of a finding. It is therefore crucial for the defence to determine whether the incriminating conclusion actually follows from the primary data, or whether a more detailed technical assessment is required.

Technical investigative approach

We check the file system journal, paths, object identifiers, timestamps and source/destination context.

Where the limits of what can be said lie

Not every file system allows for unambiguous reconstruction. In the absence of suitable evidence, no definitive method of transfer can be claimed.

Why LanCologne?

Once the case files have been examined, or as soon as the defence has lawfully obtained the relevant technical documents, an independent cross-check can reveal the actual evidential value of digital findings. LanCologne does not work with the aim of necessarily finding an error in the investigation file.

We examine what technical information the primary data actually contains. Where an official finding is correct, it is confirmed. Where a report derived from device or account data implies a more detailed personal identification, we examine the additional connecting facts required for this. We also take into account automated system processes, synchronisation, migration, backups and alternative technical causes.

Parser or report findings that are relevant to the decision are validated, where necessary, on the basis of the underlying data or a second, technically appropriate method. Data gaps, conflicting sources and alternative explanations that cannot be resolved are clearly identified.

The results are presented in such a way that the defence lawyer can recognise their technical significance for his defence strategy and that another qualified IT forensic expert can subsequently verify the key findings.

How we work

1Compile a list of technical documentation and data sources available to the defence.
2Identify the key investigative assumptions and key digital findings.
3Map primary data, reports, extractions and evidence identifiers to one another.
4Check the scope of extraction, filters, time references and technical limitations.
5Validate parser and report results at the raw data or database level, where necessary.
6Keep device, account, session and user assignments strictly separate from one another.
7Check whether automated processes, synchronisation, migration and backups could be alternative explanations.
8Assess incriminating, exculpatory and inconclusive findings using the same professional criteria.
9Explicitly document technical limitations and any data that is not available.
10Summarise the results and technical queries for the defence in a clear and reproducible manner.

Incriminating, exculpatory and inconclusive findings

An independent review is only credible if incriminating findings are confirmed as soon as the data supports them. Similarly, exonerating counter-findings or unresolvable uncertainties are clearly stated. A procedure that is merely technically possible is not presented as an established fact.

Understandable to the defence lawyer – verifiable technically by other forensic experts

The main finding is explained in clear language. Data sources relevant to the investigation, integrity information, time references, IDs, raw data locations and methodological steps are documented in such a way that another qualified IT forensic expert can technically verify the key findings.

LanCologne as an independent source of technical support for the defence

If a criminal defence lawyer wishes to have a digital forensic report or a technical conclusion drawn from the investigation file independently verified, LanCologne provides support in the form of an objective and unbiased second opinion. The aim is to arrive at a reliable answer as to what the available data actually proves – and where its evidence ends.

Legal framework

The defence counsel’s right to inspect files and examine exhibits is governed by section 147 of the Code of Criminal Procedure. Under paragraph 1, the defence counsel is authorised to inspect the files held by the court or to be submitted in the event of an indictment, and to examine exhibits held in official custody. Prior to the conclusion of the investigation, access under paragraph 2 may be restricted subject to the conditions set out therein. Under paragraph 3, the defence counsel may not be denied access to expert reports at any stage of the proceedings.

These rights are vested in the defence counsel, not LanCologne. A technical cross-check carried out by a privately commissioned IT forensic expert requires that the defence be able to lawfully provide the relevant documents or data. Commissioning such an expert does not confer on LanCologne any right of its own to inspect files, examine evidence or access data held by the Crown Prosecution Service or the police.

Section 160(2) of the Code of Criminal Procedure (StPO) expressly obliges the public prosecutor’s office to investigate both incriminating and exculpatory circumstances. Under Section 163a(2) of the Code of Criminal Procedure, evidence requested by the accused in their defence must be taken if it is relevant. An independent technical examination may therefore yield facts and counter-findings, the admissibility of which in court proceedings is assessed by the defence counsel.

Where electronic evidence that has been officially seized, confiscated or examined is concerned, particular attention must be paid to sections 94, 98 and 110 of the Code of Criminal Procedure. These provisions do not confer any public authority powers on a privately commissioned IT forensic expert.

An IT forensic expert privately engaged by the defence is not, by virtue of this engagement alone, a formally appointed expert witness within the meaning of sections 72 et seq. of the Code of Criminal Procedure. Private expert reports, technical advice and formal appointment as an expert witness must be distinguished from one another in legal proceedings.

If the investigations do not provide sufficient grounds for bringing a public prosecution, the Public Prosecutor’s Office will discontinue the proceedings in accordance with section 170(2) of the Code of Criminal Procedure. A technical finding by the defence does not guarantee such a decision, but may form a relevant part of the factual basis.

Frequently Asked Questions

Does a technical review have to reach a different conclusion to that of the investigating authority?+
No. A proper follow-up examination may confirm, qualify or refute the initial findings. It is the data that counts, not the desired outcome.
Can LanCologne itself request access to case files under Section 147 of the Code of Criminal Procedure?+
No. That right lies with the defence counsel. LanCologne may only examine documents and data that have been lawfully provided for technical examination.
Is a statement submitted by the defence automatically an expert opinion under sections 72 et seq. of the Code of Criminal Procedure?+
No. A privately commissioned statement or expert report must be distinguished from the formal appointment of an expert in criminal proceedings.
Can a negative technical finding guarantee that proceedings will be discontinued?+
No. The decision is taken by the public prosecutor’s office or, subsequently, by the court. However, the counter-finding may provide a sound technical basis of fact.

LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now