LANCOLOGNE IT-FORENSIK

Alle Forensik-Leistungen im Überblick

Professionelle IT-Forensik für Mobile Geräte und Windows-Systeme – gerichtsverwertbar, DSGVO-konform, erfahren.

136
Mobile forensics
100
Windows Forensik

MOBILE FORENSICS

Mobile forensics

136 spezialisierte Leistungen rund um Smartphones & Tablets

ADB (Android Debug Bridge) in IT forensicsAirDrop artefactsAndroid Keystore and Security ArchitectureAndroid Verified Boot (AVB)Forensic analysis of Android app permissionsForensic analysis of Android backup artefactsAndroid Backups – Options and LimitationsForensic analysis of Android notificationsAndroid-Bluetooth-Artefakte forensisch analysierenForensic analysis of Android call logsAndroid-Cloud-Synchronisation forensisch analysierenForensic analysis of Android crash dumps and tombstonesForensic analysis of Android file managers and downloadsForensic analysis of Android file system artefactsAndroid email forensicsAndroid eSIM ForensicsAndroid-Forensik – Professionelle Analyse digitaler Beweismittel auf Android-GerätenForensic analysis of Android device logs (events and system logs)Forensic analysis of the Android calendarForensic analysis of Android contactsForensic analysis of Android NFC artefactsAndroid-SIM-Karten-Artefakte forensisch analysierenForensic analysis of Android SMS and MMS messagesForensic analysis of Android location dataForensic analysis of Android system settingsAndroid system logs and LogcatAndroid Timeline and Event ReconstructionAndroid Trojans, banking malware and RATsAndroid-USB- und OTG-Artefakte forensisch analysierenForensic analysis of Android-WLAN artefactsForensic analysis of Android timestamps and time zonesDetecting anti-forensics on AndroidAPFS – Apple’s file systemApple Data Protection and data protection mechanismsApple Health (HealthKit) – IT-forensische UntersuchungApple Maps artefactsApple ID, synchronisation and device pairingVerification of the authenticity of digital evidenceThe evidential value of digital artefactsPreservation of evidence from smartphonesCellebrite in mobile forensicsCellebrite in der Mobilforensik – Professionelle Datensicherung und Analyse digitaler BeweismittelChain of Custody for SmartphonesChatmanipulationen nachweisenDetecting chat manipulation – Objective IT forensic analysis of digital communicationsCustom Recovery (TWRP & Co.) aus Sicht der Android-ForensikCustom-ROMs aus Sicht der Android-ForensikThe Android file system explained in simple termsThe iOS file system explained in simple termsHave digital metadata professionally analysedAdvanced logical extraction from a smartphoneForensic analysis of EXIF metadata in imagesFacebook Messenger auf Android forensisch analysierenFaceTime artefactsFastboot and bootloaderFile Based Encryption (FBE) und Full Disk Encryption (FDE)Full File System (FFS) in mobile IT forensicsGegengutachten / PlausibilitätsprüfungRecovering deleted data on AndroidMobile phone expert reports admissible in courtForensic analysis of Google Chrome on AndroidGoogle Fotos auf Android forensisch analysierenForensic analysis of Google Maps on AndroidGoogle Account and Google Cloud artefactsLimitations and uncertainties in IT forensic reportsExpert reports for courts and public prosecutors’ officesExpert reports for solicitorsHäufige Fragen zu Kosten, Vergütung und AbrechnungiCloud forensics and Apple cloud dataiMessage forensicsConduct a forensic analysis of installed appsForensic analysis of installed apps (Android)iOS logs and system logsiPhone Backups – Options and LimitationsiPhone Forensics – Admissible analysis of digital evidence on Apple devicesIT-forensische Malware-Gutachten für SmartphonesForensic analysis of iTunes and Finder backupsJailbreaking in iPhone forensicsJailbreaking in iPhone forensicsCosts of an IT forensic investigationCosts of an IT forensic reportLogical extraction of a smartphoneMalware Indicators (IoCs), MVT and YARAChecking Messenger messages for tamperingMessenger forensics – Analysis of digital communications on smartphones and tabletsMetadaten in der mobilen Forensik – was digitale Begleitspuren verraten könnenMetadata in mobile forensicsMobile artefacts – call logs in IT forensicsMobile Artefakte – App-Nutzung (App Usage) in der IT-ForensikMobile artefacts – Notifications in IT forensicsMobile Devices – Screen Time in IT ForensicsMobile devices – Bluetooth devices in IT forensicsMobile Artefakte – Browser-Artefakte in der IT-ForensikMobile artefacts – files in IT forensicsMobile devices – Downloads in IT forensicsMobile Artefacts – EXIF Metadata in IT ForensicsMobile artefacts – photographs in IT forensicsMobile artefacts – calendars in IT forensicsMobile Artefacts – Contacts in IT ForensicsMobile Artefacts – MMS in IT ForensicsMobile Artefacts – Notes on IT ForensicsMobile Artefakte – SMS in der IT-ForensikMobile artefacts – location data in IT forensicsMobile Artefakte – Videos in der IT-ForensikMobile artefacts – WLAN artefacts in IT forensicsMobile artefacts – The clipboard in IT forensicsMobile malware analysis – scanning smartphones for malware and digital anomaliesEvidence of deleted dataPackage deals for private individuals, businesses and solicitorsPhysical removal of a smartphonePrivate report on smartphonesRoot in Android forensicsRoot in Android forensicsRooting from the perspective of Android forensicsExpert reports in accordance with recognised forensic standardsSafari artefactsForensic analysis of Samsung Gallery on AndroidSecure Enclave – Security in the iPhoneConducting a forensic analysis of Signal Messenger on AndroidSignal-Forensik – Analyse verschlüsselter Kommunikation auf SmartphonesSpyware auf Smartphones erkennenSQLite-Forensik – Wenn digitale Spuren in Datenbanken gespeichert werdenGovernment-sponsored malware (e.g. Pegasus) – the scope and limitations of investigationsStalkerware on smartphonesTechnical documentation and reproducibilityForensic analysis of Telegram on AndroidTelegram Forensics – Forensic Analysis of Telegram CommunicationsForensic analysis of Threema on AndroidVergütung nach JVEG und individuelle PreisvereinbarungenWAL- und SHM-Analyse – Unscheinbare Dateien mit großer Bedeutung für die IT-ForensikWAL and SHM analysis in IT forensicsWhy different tools in mobile IT forensics produce different resultsForensic analysis of WhatsApp on AndroidWhatsApp Forensics – Analysis of chat histories and digital evidenceTimeline analysisZeitstempel und Metadaten unter Android

WINDOWS FORENSICS

Windows Forensik

100 spezialisierte Leistungen rund um Windows-Systeme

Forensic analysis of Amcache – evidence of programmes and system activityGeplante Aufgaben (Scheduled Tasks) forensisch analysieren – Automatische Abläufe nachvollziehenForensic analysis of jump lists – Important insights into user activityForensic analysis of LNK files – reconstructing user activities in a traceable mannerForensic Analysis of the Master File Table (MFT) – The Heart of the NTFS File SystemForensic analysis of the NTFS file system – The foundation of virtually every Windows investigationProfessional Windows Forensics – Securing and analysing digital evidence to stand up in courtShellBags forensisch analysieren – Ordnerzugriffe und Benutzeraktivitäten rekonstruierenForensic analysis of ShimCache (AppCompatCache) – evidence of applications that have been runSRUM forensisch analysieren – System- und Netzwerkaktivitäten nachvollziehenForensic analysis of the USN Journal – tracking changes on Windows systemsWindows Active Directory-Artefakte forensisch analysieren – Domänenaktivitäten technisch nachvollziehenForensic analysis of the Windows Activity Cache – reconstructing user activitiesWindows Antiviren- und Sicherheitssoftware forensisch analysieren – Sicherheitsereignisse technisch bewertenForensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibilityWindows AppData forensisch analysieren – Anwendungs- und Benutzerdaten auswertenForensic Analysis of Windows AppX Packages – Understanding Modern Windows ApplicationsForensic analysis of Windows autostart entries – identifying persistence mechanismsForensic analysis of the Windows BCD – Understanding boot configurationsForensic Analysis of Windows User Accounts (SAM) – Evaluating Local Accounts and Security InformationForensic analysis of Windows BitLocker artefacts – understanding encryption status and system informationForensic Analysis of Windows Bluetooth Artifacts – Tracing Paired Devices and ConnectionsWindows Clipboard History forensisch analysieren – Inhalte der Zwischenablage als digitale BeweisspurForensic analysis of Windows COM artefacts – tracing components and system activitiesForensic Analysis of Windows COM+ – Tracing Distributed Components and ServicesForensic analysis of Windows crash dumps – Technical reconstruction of system crashesWindows Credential Manager forensisch analysieren – Gespeicherte Anmeldeinformationen nachvollziehenForensic analysis of Windows Defender Antivirus artefacts – tracing security eventsForensic analysis of Windows Defender Application Control (WDAC) – Understanding application policiesWindows Defender-Artefakte forensisch analysieren – Sicherheitsereignisse nachvollziehenForensic analysis of Windows Delivery Optimisation – tracing Update and transmission artefactsWindows Device Metadata Cache forensisch analysieren – Hinweise auf erkannte HardwareForensic Analysis of Windows Services – Investigating Persistence and System ConfigurationWindows DNS-Cache forensisch analysieren – Netzwerkaktivitäten nachvollziehenWindows DNS-Client-Artefakte forensisch analysieren – Namensauflösungen und Netzwerkaktivitäten nachvollziehenForensic Analysis of Windows DPAPI – Tracing Protected User Data and KeysWindows EDR-Artefakte forensisch analysieren – Sicherheitsereignisse und Angriffsketten rekonstruierenForensic Analysis of Windows EFS – Examining Encrypted Files and CertificatesWindows Error Reporting (WER) forensisch analysieren – Programmabstürze und Systemfehler nachvollziehenForensic Analysis of Windows ETL Logs – Tracing Detailed System EventsForensic analysis of Windows event logs – evaluating system events in a traceable mannerWindows Firewall-Artefakte forensisch analysieren – Netzwerkkommunikation und Konfigurationsänderungen nachvollziehenForensic analysis of the Windows font cache – clues regarding document and programme usageForensic analysis of Windows Group Policy – Understanding system configurationsIn-depth forensic analysis of Windows’ hiberfil.sys – Reconstructing saved RAM contentsWindows Hosts-Datei forensisch analysieren – Manuelle Namensauflösungen nachvollziehenForensic Analysis of Windows Hyper-V Artefacts – Understanding Virtual InfrastructuresWindows Live Response Artefakte forensisch analysieren – Flüchtige Systeminformationen sichernWindows Memory Dumps forensisch analysieren – Flüchtige Daten aus dem Arbeitsspeicher auswertenWindows Microsoft Defender for Endpoint (MDE) Artefakte forensisch analysieren – Sicherheitsereignisse nachvollziehenForensic analysis of Windows Microsoft Store artefacts – Tracing installed apps and updatesWindows MountPoints2-Artefakte forensisch analysieren – Hinweise auf angeschlossene DatenträgerForensic Analysis of Windows MSIX Packages – Understanding Modern Application InstallationsForensic analysis of Windows Nearby Sharing – Reconstructing local file transfersForensic analysis of Windows network adapters – understanding network interfaces and system configurationForensic analysis of Windows network profiles – tracing network connections and configurationsForensic analysis of the Windows Notification Database – notifications as digital evidenceForensic Analysis of Windows Offline Files (CSC) – Analysing Cached Network FilesWindows OneDrive-Artefakte forensisch analysieren – Lokale Cloud-Spuren technisch bewertenWindows pagefile.sys vertieft forensisch analysieren – Ausgelagerte Speicherinhalte rekonstruierenWindows Papierkorb ($Recycle.Bin) vertieft forensisch analysieren – Löschvorgänge nachvollziehenForensic analysis of the Windows Recycle Bin – Tracing deleted filesWindows Performance Monitor und Performance Logs forensisch analysieren – Systemzustände nachvollziehenWindows Portable Devices (WPD) forensisch analysieren – Mobile Geräte als digitale SpurForensic Analysis of Windows PowerShell Artifacts – Tracing Commands and ActivitiesForensic analysis of Windows Prefetch files – identifying evidence of programme executionForensic analysis of the Windows Print Spooler – Technical investigation of print jobsForensic analysis of Windows proxy artefacts – Understanding proxy configurations and network communicationForensic analysis of Windows RAM dumps – Securing ephemeral evidence from main memoryWindows RDP-Artefakte forensisch analysieren – Remote-Desktop-Verbindungen nachvollziehenForensic analysis of Windows ReadyBoot and ReadyBoost artefacts – tracing boot processes and system usageForensic Analysis of the Windows Registry – One of the most important sources of information in Windows forensicsForensic analysis of Windows Registry transaction logs – tracing changes to the RegistryWindows Reliability Monitor forensisch analysieren – Systemänderungen und Fehler chronologisch nachvollziehenForensic Analysis of Windows Sandbox Artifacts – Tracing Temporary Execution EnvironmentsForensic analysis of the Windows Search database – Tracing indexed files and search informationWindows Search Index forensisch analysieren – Indizierte Daten und Dateiverweise nachvollziehenForensic analysis of the Windows SECURITY hive – understanding security configurationsForensic analysis of Windows Setup API logs – tracing device installationsWindows Sicherheitsrichtlinien forensisch analysieren – Sicherheitskonfigurationen nachvollziehenForensic Analysis of Windows SMB Artifacts – Tracing Network Shares and File AccessesWindows SOFTWARE-Hive forensisch analysieren – Software- und Systemkonfigurationen rekonstruierenForensic analysis of the Windows swapfile.sys – Evaluating additional memory artefactsForensic analysis of Windows synchronisation artefacts – tracing synchronisation processesForensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system eventsWindows SYSTEM-Hive forensisch analysieren – Systemkonfigurationen und Hardwareinformationen rekonstruierenForensic analysis of Windows TCP/IP configuration – Understanding network settingsWindows Temp-Dateien forensisch analysieren – Temporäre Artefakte als digitale BeweismittelWindows Thumbnail Cache forensisch analysieren – Vorschaubilder als digitale SpurWindows Timeline forensisch analysieren – Benutzeraktivitäten chronologisch nachvollziehenForensic analysis of Windows Update artefacts – tracing installations and system changesForensic analysis of Windows USB artefacts – Tracing connected devicesWindows Volume Shadow Copies forensisch analysieren – Frühere Dateistände und Systeminformationen nachvollziehenForensic analysis of Windows VPN artefacts – tracing VPN connections and configurationsWindows WLAN-Artefakte forensisch analysieren – Drahtlose Netzwerkverbindungen nachvollziehenWindows WMI forensisch analysieren – Persistenzmechanismen und Systemaktivitäten nachvollziehenWindows Zertifikatsspeicher forensisch analysieren – Digitale Zertifikate und Vertrauensstellungen nachvollziehenWindows-Auslagerungsdatei (pagefile.sys) forensisch analysierenWindows-Benutzerprofile forensisch analysieren – Benutzeraktivitäten nachvollziehenForensic analysis of the Windows hibernation file (hiberfil.sys)

Enquire now – free initial consultation

Sie wissen nicht welche Forensik-Leistung Sie benötigen? Wir beraten Sie kostenlos und unverbindlich.