IT Forensics · Solicitors & Criminal Defence Lawyers

Kann eine virtuelle Maschine eine belastende Aktivität einem anderen Systemkontext zuordnen?

Virtuelle Maschinen besitzen eigene Benutzer, Anwendungen und Dateisysteme. Spuren im Gast- und Hostsystem dürfen nicht miteinander vermischt werden.

Enquire without obligation

Why this question is important for a criminal defence

During a criminal investigation, a digital trace that appears to be unequivocal can have a significant impact on the assessment of the suspicion of a crime. It is therefore crucial for the defence to determine whether the technical interpretation is in fact valid, or whether context, system architecture, incomplete data or alternative causes need to be taken into account.

Technical investigative approach

Wir prüfen virtuelle Datenträger, Hypervisor- und Gastspuren, Snapshots, Laufzeiten und Benutzerkontext.

Where the limits of what can be said lie

Ein Artefakt in einer virtuellen Maschine ist nicht automatisch dem Hostsystem oder dessen gerade angemeldetem Benutzer zuzurechnen.

Why LanCologne?

LanCologne supports the defence by providing an independent technical assessment, not by prescribing a specific outcome. A finding that exonerates the defendant is only valuable if its origin, the reasoning behind it and its limitations remain transparent to the Crown Prosecution Service, another expert witness and, subsequently, the court.

The starting point is therefore always the specific defence issue. We distinguish between device-related, account-related and session-related aspects, and between natural persons, just as consistently as we distinguish between technical feasibility, actual use and verifiable actions.

Data accessed lawfully is secured in a traceable manner, insofar as this is technically possible. Automated matches relevant to decision-making are not accepted without verification. Where necessary, checks are carried out at file system, database or raw data level, or using a second method appropriate to the subject matter.

The result may be conclusive, inconclusive or open-ended. This openness regarding the result safeguards the quality of the investigation and prevents an explanation that is merely technically possible from being presented as an established fact.

How we work

1Define the specific defence issue and the aim of the investigation.
2Clarify which data, devices or parts of the file are lawfully available for the technical inspection.
3Document source data and integrity information.
4Formulate an incriminating investigative hypothesis and technically plausible alternative hypotheses.
5Examine relevant primary data in a targeted manner.
6Validate critical parser or report findings independently where necessary.
7Keep device, account, session and user assignments strictly separate from one another.
8Assess incriminating and exonerating findings using the same professional criteria.
9Openly document missing data, inconsistencies and limitations in the findings.
10Present the findings in a way that is clear to the defence and technically verifiable by other forensic experts.

Incriminating, exculpatory and inconclusive findings

The defence does not benefit from a favourable expert report. If the data supports the allegation, this is stated just as clearly as any credible evidence to the contrary. If several explanations remain possible or if essential data required for a definitive conclusion is missing, this uncertainty is explicitly documented.

Understandable to the defence lawyer – verifiable technically by other forensic experts

The main finding is explained in clear language. The technical section documents the data sources, integrity information, time references, artefacts and investigation steps relevant to a review. This enables another qualified IT forensic expert to carry out a technical review of the reasoning.

LanCologne as an independent source of technical support for the defence

If a criminal defence lawyer wishes to have a digital factual issue independently examined during the pre-trial investigation, LanCologne provides support in the form of a transparent and unbiased IT forensic investigation. The aim is to establish a factually sound and technically robust basis – regardless of whether it confirms, qualifies or technically contradicts the allegation.

Legal framework

The defence may become involved as early as the pre-trial investigation stage. Under section 137(1) of the Code of Criminal Procedure (StPO), the accused may engage a defence counsel at any stage of the proceedings. Section 160(2) of the Code of Criminal Procedure (StPO) obliges the public prosecutor’s office to investigate both incriminating and exculpatory circumstances and to ensure the preservation of evidence which is at risk of being lost. Under Section 163a(2) of the Code of Criminal Procedure, evidence which the accused requests to be taken in his or her defence must be taken if it is relevant.

Under section 147 of the Code of Criminal Procedure (StPO), the defence counsel is entitled to inspect files and examine evidence. Pursuant to paragraph 2, restrictions may apply prior to the conclusion of the investigation; however, pursuant to paragraph 3, the defence counsel must not be denied access to expert reports at any stage of the proceedings. LanCologne does not have its own right of access to the case file under Section 147 of the Code of Criminal Procedure. A cross-check requires that the defence be able to lawfully make the relevant documents or data available for technical examination.

An IT forensic expert privately engaged by the defence does not, by virtue of that engagement alone, become a formally appointed expert witness under sections 72 et seq. of the Code of Criminal Procedure. These roles are explicitly distinguished in our statements and on our landing pages.

Where digitally stored evidence held in official custody or seized is at issue, the competent law enforcement agencies and courts shall decide on its seizure, confiscation, examination and access. In particular, sections 94, 98 and 110 of the Code of Criminal Procedure do not confer any sovereign powers on LanCologne.

When working confidentially with the defence, the legal requirements regarding the protection of professional secrecy must be observed in a nuanced manner. Sections 53 and 53a of the Code of Criminal Procedure (StPO) govern the rights to refuse to give evidence of persons bound by professional secrecy and, subject to certain conditions, of persons assisting in proceedings; Section 97 StPO contains prohibitions on seizure, with specific conditions and exceptions; Section 160a StPO sets out rules of protection for investigative measures. Section 203(3) and (4) of the Criminal Code (StGB) permits, subject to the conditions set out therein, the necessary involvement of other persons assisting in the proceedings and establishes obligations of confidentiality. This does not imply blanket, automatic protection for every file held by an external IT forensic expert.

Frequently Asked Questions

Does LanCologne work towards a desired outcome in terms of relief?+
No. The technical assessment is open-ended. Only a finding that can actually be derived from the data is useful for a robust defence.
Can LanCologne itself request access to files or to a seized device?+
No. These rights and decisions lie with the defence, the prosecution and the court. LanCologne only investigates data or evidence that has been lawfully provided.
Is a private report automatically an expert report within the meaning of sections 72 et seq. of the Code of Criminal Procedure?+
No. A privately commissioned technical consultation or expert report must be distinguished from the formal appointment of an expert in criminal proceedings.
Can a negative technical finding guarantee that proceedings will be discontinued?+
No. The decision on how to proceed with the case rests with the public prosecutor’s office or, at a later stage, the court. However, the findings may provide a relevant technical basis of fact.

LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now