
Service
IT forensics
What is examined
- File systems and deleted or partially overwritten file remnants
- System and application logs, execution traces and scheduled tasks
- User accounts, login events and connected devices
- Application databases, mail stores and browser artefacts
How the examination is carried out
- 1.Acquisition through a write blocker, with cryptographic hashes of the resulting image
- 2.Analysis exclusively on the secured copy, using two independent tools where the finding is critical
- 3.Manual review of automated results before any statement is made
- 4.Documentation of methods, tool versions, findings and limits
Technical limits
These limits are stated before the instruction, not afterwards.
- Overwritten storage areas cannot be reconstructed.
- Logs are retained only for a limited period and may already have rotated.
- Encrypted data without a key or lawful access remains unreadable.
- Content held only by a provider cannot be obtained by technical means alone.
FREQUENTLY ASKED QUESTIONS
IT forensics: frequently asked questions
Which files existed, when they were created, changed or deleted, which accounts were active, which programs were executed and which devices were connected — as far as the surviving data allows.
Analysis takes place on the secured working copy in the permanent examination rooms at the registered office in Krefeld, Germany. Devices are handed over in person or sent by insured carrier; by prior arrangement, processing in Munich is also possible. Where the technical conditions allow it, the acquisition itself can also be carried out at the client’s premises or at the location of the item; unavoidable changes to a running system are documented with reasons.
Whether an expert report is used in proceedings, and what evidential value it carries, is decided by the competent court or investigating authority. Our examinations are documented so that third parties can review them: recorded handover, cryptographic hashes, described methods and a clear separation between technical finding and assessment. A binding assurance of later admissibility cannot be given.
Partly. Windows reliably records which USB devices were connected and when they were first set up – traceable via the registry, the setupapi.dev.log file and system events. The act of copying itself, however, is not fully logged. Whether a specific file reached a specific stick can only be narrowed down through indicators such as shortcut files, program histories and timestamps. A complete copying record is technically impossible; any remaining uncertainty is stated in the report.
Sources: NIST SP 800-86 – Guide to Integrating Forensic Techniques into Incident Response · SWGDE – published best-practice documents
A hash value proves that a data set remained unchanged between two points in time: if the checksum of the original computed before acquisition matches that of the copy, the copy is bit-identical. If even a single bit changes later, a fresh computation returns a different value. A hash value does not prove who created, modified or copied data, nor anything about its content or accuracy. Cryptographic algorithms such as SHA-256 are used; MD5 is considered collision-prone.
Sources: NIST SP 800-86 – Guide to Integrating Forensic Techniques into Incident Response · NIST – Secure Hash Standard (FIPS 180-4)
Not hastily. Memory contents, active network connections and signed-in sessions are volatile and are lost on shutdown – they can be decisive for the investigation. Equally, no clean-up tools should run, no files should be deleted and no passwords changed on the affected system. The next step depends on the situation and is agreed before acquisition; when in doubt, the system remains unchanged until the method of preservation is settled.
Sources: NIST SP 800-86 – Guide to Integrating Forensic Techniques into Incident Response
How findings are recorded from intake to assessment is set out under documented evidence preservation and chain of custody.
Equipment used
Systems used in this examination
- X-Ways Forensics
Examination of storage media, file system structures and timestamps on the working copy.
- Cellebrite Digital Collector and Inspector
Controlled acquisition and analysis of computer data within the licensed scope.
Next step
Discuss your case
Describe the situation briefly. We will say what can realistically be established, and what cannot.