Skip to main content
AI-generated

Knowledge and methods

Forensics, hash values, devices and examination methods explained

This knowledge section answers recurring technical questions about digital forensics: what a hash value proves, which examination systems AQON INTELLIGENCE uses, how a forensic examination proceeds and what matters in a suspected incident. All technical statements rest on the cited primary sources.

How to read this section

Each section opens with a short, independently quotable answer. The following paragraphs put it into context and state its limits. The sources supporting each statement are listed at the end of every section. The registered office and examination rooms of AQON INTELLIGENCE are in Krefeld, Germany; every other city named is a service area, not a branch office.

Topic 1 of 5

What is digital forensics?

Digital forensics is the secured capture, examination and documentation of digital traces on computers, mobile devices and storage media. Its aim is a verifiable answer to a clearly defined question. Work is carried out on verified copies, never on the original. What cannot be proven technically is stated as a limitation rather than replaced by assumptions.

A forensic examination starts with the question, not the tool. Only once it is clear what needs to be established – an access time, a copied file, a suspicious sign-in – is it decided which data sources matter and in which order they are secured. Volatile data such as memory contents and active connections are lost on shutdown and are therefore captured first wherever possible.

The analysis itself is performed on a secured working copy. The original remains stored unchanged so that an independent review stays possible. Findings are documented so that a qualified third party can retrace every step from the source material to the conclusion.

The levels must stay separate: a technical finding describes what a system recorded. The assessment explains what that finding may mean – and under which conditions. Whether a result is used in proceedings is decided solely by courts or investigating authorities.

Sources

Topic 2 of 5

What does a hash value prove?

A hash value is a checksum computed from a data set. If the hash before and after an acquisition matches, this proves the data set did not change between the two points in time. A hash value therefore proves the integrity of data – not its content, origin or accuracy.

In practice, a hash of the original medium is computed before acquisition and a hash of the copy afterwards. If both are identical, the copy matched the original bit for bit. If even a single bit changes later, a fresh computation returns a different value – the alteration would be demonstrable.

Cryptographic algorithms such as SHA-256 are used. Older algorithms such as MD5 are considered collision-prone and are no longer recommended for forensic integrity protection; where they appear for historical reasons, this is documented.

A hash value says nothing about who created, modified or copied data. It only proves that two data sets were identical at the time of computation. Everything beyond that belongs to analysis and documentation.

Sources

Topic 3 of 5

Which examination devices are used?

AQON INTELLIGENCE uses documented, industry-standard examination systems: Cellebrite Inseyets/UFED for mobile device acquisition, X-Ways Forensics for storage media analysis, MOBILedit Forensic as a complementary mobile method, the MEFF M3-PRO for the technical examination of mobile devices for anomalies, and REI measurement technology such as MESA 2.0 and ANDRE Deluxe for technical surveillance counter-measures. Version levels are recorded per instruction.

Each tool has its own remit. Cellebrite Inseyets (UFED and Physical Analyzer) covers the acquisition and analysis of smartphones and tablets. X-Ways Forensics is the working environment for file systems, disk images and artefact analysis. MOBILedit Forensic complements mobile acquisition, for example with models or data areas another method cannot reach. The MEFF M3-PRO supports the structured examination of iOS and Android devices for anomalies in apps, permissions, system logs and network connections; the resulting indications are assessed professionally and on their own prove neither surveillance nor its absence. REI measurement technology – including the MESA 2.0 spectrum analyser and the ANDRE Deluxe near-field receiver – is used in technical surveillance counter-measures.

Results depend on the tool generation and version level. The systems used and their relevant versions are therefore recorded for each instruction. Detailed descriptions of each system are on the technology pages; the statements there and here rest on the linked manufacturer documentation.

No tool guarantees a result. Support coverage changes with the model, operating system level and encryption. Whatever a system could not capture in a given case is stated as a limitation in the report.

Sources

Topic 4 of 5

How does a forensic examination proceed?

An examination follows a fixed chain: intake and documentation of the initial state, unambiguous labelling of the material, write-protected acquisition with checksums, analysis on the working copy, documented examination steps and a report that separates finding, assessment and limitations. This documented chain of handovers is called the chain of custody.

At intake, the time of handover, the external condition, the operating state and any existing markings are recorded. Each device receives its own identifier; serial numbers, IMEI and model designations are captured so that later statements can be assigned to a specific item.

Acquisition is write-protected wherever technically possible. Where systems can only be read while running, the resulting change is justified and documented. Every handover and every access to the material is logged.

The report describes the instruction, methodology, examination steps, technical findings and results in a verifiable way. No binding assurance of admissibility in court can be given – that decision rests with the competent authorities. The full description of evidence preservation is on the digital evidence page.

Sources

Topic 5 of 5

What to do in a suspected incident – and what not to do?

If spyware or a security incident is suspected: stop using the affected device, delete nothing, run no clean-up tools and leave the network state as unchanged as possible. Do not switch off a computer hastily after an incident if volatile data is to be secured. Any change to the device can overwrite traces and reduce the evidential value of a later examination.

On a smartphone this means: no supposed cleaning apps, no factory reset, no updates, no test calls. The device should be disconnected from the home network but not switched off without consultation – depending on the model and lock state, a powered-off device is harder to acquire later. Note the time suspicion arose, the observed anomalies and any steps already taken.

The same principle applies to computers: no clean-up tools, no manual deletions, no password changes on the affected system itself. Whether to power down depends on the situation; running systems hold volatile data that is lost on shutdown. When in doubt, the next step is agreed in a short call before anything is done.

These notes are no substitute for legal advice or an individual risk assessment. Where there is an acute threat or a concrete surveillance suspicion involving a safety risk, the competent authorities should additionally be involved.

Sources

Locations

The registered office and examination rooms of AQON INTELLIGENCE are in Krefeld, Germany. The following cities and regions are service areas – not branch offices. The linked pages describe what can be examined on site.

Krefeld location (registered office)

All locations at a glance

Clarify your question before traces are lost

Available Monday to Friday, 9 a.m. to 7 p.m. (CET).