IT Forensics · Solicitors & Criminal Defence Lawyers
How can an official timeline be independently verified?
A timeline can make the sequence of events appear very convincing. However, errors relating to time zones, the interpretation of time or synchronisation can alter the sequence.
Why this question is important for a criminal defence
Having examined the case files, it is important to distinguish the technical facts from the summary assessments of the investigation. Digital evidence, in particular, can appear plausible in reports, even though the scope of data extraction, temporal context, attribution to individuals or data context may require a more nuanced assessment.
Technical investigative approach
We examine every primary time source in terms of format, time zone, system clock, significance of the event and technical dependencies, and reconstruct the relevant sequence independently.
Where the limits of what can be said lie
Multiple timestamps from the same source do not automatically constitute independent confirmations of one another.
Why LanCologne?
Having examined the case files, the added value of an independent IT forensic review does not lie in casting blanket doubt on the work carried out by the authorities. Rather, the key point is to trace the key digital findings back to their actual data sources.
LanCologne therefore checks which evidence, image or extraction was examined, which filters and parsers were used, and whether the conclusion drawn from this is technically supported by the primary data. Where an official finding is correct, it is confirmed. Where a statement goes beyond the scope of the data, this limitation is explained in a way that is easy to follow.
Particular attention is paid to the distinction between a device, an account, a session and a natural person, as well as between automated system behaviour and deliberate user action. Contradictory findings, incomplete data sources and technically plausible alternative explanations are also taken into account.
The aim is to establish a sound technical basis for the defence that will also stand up to subsequent scrutiny by the public prosecutor’s office, other experts and the court.
How we work
Incriminating, exculpatory and inconclusive findings
A technical review is not an attempt to find an error in the investigation file at all costs. Technically correct findings are confirmed. If contradictory findings, incomplete data or alternative technical explanations are identified, these are also documented in a clear and comprehensible manner. This provides the defence with a realistic and robust factual basis.
Understandable to the defence lawyer – reproducible for other forensic scientists
The main finding is formulated clearly and without unnecessary technical jargon. Data sources relevant to the investigation, hash values, IDs, time references, raw data locations and methodological steps are documented in such a way that another qualified IT forensic expert can technically verify the key findings.
LanCologne as an independent source of technical support for the defence
If a criminal defence lawyer wishes to have a digital key analysis independently verified after reviewing the case files, LanCologne provides support in the form of an objective and unbiased IT forensic re-examination. The aim is to provide a clear answer as to what the available technical data actually proves – and what it does not.
Legal framework
The defence counsel’s right to inspect files and examine exhibits is governed by section 147 of the Code of Criminal Procedure. Under paragraph 1, the defence counsel is authorised to inspect the files before the court or, in the case of an indictment, those to be submitted to the court, and to examine exhibits held in official custody. So long as the conclusion of the investigations has not yet been noted in the files, access or inspection may, pursuant to paragraph 2, be restricted subject to the conditions set out therein. Under Section 147(3), the defence counsel must not, in any stage of the proceedings, be denied access to expert reports. In the preliminary proceedings, the public prosecutor’s office generally decides on the granting of access to the files (Section 147(5)).
These rights are vested in the defence counsel, not in LanCologne. A technical cross-check therefore requires that the defence be able to lawfully make the relevant documents or data available. By being privately commissioned, LanCologne does not acquire any right of its own to inspect, examine files or access information held by the Crown Prosecution Service or the police.
Section 160(2) of the Code of Criminal Procedure (StPO) requires the public prosecutor’s office to investigate both incriminating and exculpatory circumstances. Under Section 163a(2) of the StPO, evidence requested by the accused in their defence must be obtained if it is relevant. An independent technical examination can therefore provide factual evidence which the defence counsel can assess with a view to suggesting further evidence or making applications; the procedural decision is taken by the defence counsel or the competent law enforcement authority.
Insofar as electronic evidence that has been officially seized, confiscated or examined is concerned, particular attention must be paid to sections 94, 98 and 110 of the Code of Criminal Procedure. Section 110(3) governs the examination of electronic storage media by authorised state authorities and, subject to certain conditions, also storage media located in separate premises. This does not confer any sovereign powers on a privately commissioned IT forensic expert.
An IT forensic expert privately engaged by the defence is not, by virtue of that engagement alone, a formally appointed expert witness within the meaning of Sections 72 et seq. of the Code of Criminal Procedure. These procedural roles are expressly distinguished from one another.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How is it verified whether chat messages have been taken out of their technical context in the investigation report?
- How is the technical validity of an official account or personal assignment verified?
- How are local device data and cloud data synchronised within the investigation file?
- How is location data from various sources cross-checked in the investigation file?