IT Forensics – Windows

Forensic analysis of Windows USB artefacts – Tracing connected devices

Windows speichert zahlreiche Informationen über angeschlossene USB-Geräte. Dazu gehören unter anderem Einträge in der Registry, Gerätekennungen, Zeitinformationen und weitere Metadaten. Diese Artefakte können wichtige Hinweise darauf liefern, welche USB-Sticks, externen Festplatten oder anderen Speichermedien an einem System verwendet wurden.

Enquire without obligation

Im Rahmen einer professionellen IT-forensischen Untersuchung werden USB-Artefakte niemals isoliert ausgewertet. Erst die Korrelation mit der Windows Registry, Event Logs, LNK-Dateien, ShellBags, Jump Lists und weiteren digitalen Spuren ermöglicht eine belastbare technische Bewertung.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse registry entries, device identifiers, timestamps and other USB-related artefacts. The results are correlated with additional Windows artefacts and fully documented.

Typical areas of application

Data theft
Analysis of external storage media
Incident Response
Investigation into allegations of manipulation
Employment law proceedings
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, all relevant USB artefacts are analysed. The results are then cross-referenced with other digital evidence and assessed from a technical perspective.

Warum sind USB-Artefakte wichtig?

USB artefacts can provide clues about connected devices and their use. However, their significance only becomes apparent following a comprehensive analysis of all relevant digital traces relating to the case in question.

Frequently Asked Questions

Welche Informationen können USB-Artefakte enthalten?+
Je nach Datenlage unter anderem Gerätekennungen, Anschlussinformationen und Zeitstempel.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Können entfernte USB-Geräte nachgewiesen werden?+
Je nach vorhandenen Artefakten können frühere Geräteverbindungen nachvollziehbar sein.
Reichen USB-Artefakte allein für ein Gutachten aus?+
No. They are always analysed alongside other Windows artefacts.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows USB artefacts or other Windows artefacts? LanCologne can assist you with the forensic-grade preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now