Our process
From the question to the expert report
Six steps
What happens, in which order
Examinations of devices and data take place in the examination rooms in Krefeld. Technical surveillance counter-measures and vehicle screening are carried out on site.
Step 1
Initial consultation and defined question
We discuss what is to be clarified and which devices, data or rooms are involved. The result is a written question, an agreed scope and a realistic statement of what can be established. If a case is outside our field, we say so. The initial consultation is free of charge.
Step 2
Handover and chain of custody
Devices and storage media are handed over in person or sent by insured carrier. Condition, identifiers and time of handover are recorded. Every subsequent step is logged, so that the whereabouts of an item can be traced at any time.
Step 3
Forensic acquisition
Storage media are acquired through a write blocker, mobile devices with the extraction method appropriate to the model and firmware. Cryptographic hashes are calculated for the acquired image and verified. Original media are not altered.
Step 4
Analysis on the secured copy
File systems, databases, logs, artefacts and account activity are examined on the copy. Automated tool output is reviewed manually. Contradictory or ambiguous findings are stated as such, not smoothed over.
Step 5
Documentation and expert report
The report sets out the question, the methods, the tools and versions used, the findings and the limits of the examination. Technical finding and assessment remain separate. The expert prepares a traceable expert report setting out the findings and their professional assessment.
Step 6
Return, storage and deletion
Items are returned as agreed. Acquired data is stored for the agreed retention period and then deleted in a documented manner, unless a longer period has been agreed for pending proceedings.
Limits
What an examination cannot deliver
Overwritten storage areas cannot be reconstructed. Logs are only kept for a limited period. Encrypted data without a key or lawful access remains unreadable, and provider-side content cannot be obtained by technical means alone. These limits are named before the instruction, not afterwards.
