IT Forensics – Windows

Forensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system events

Sysmon (System Monitor) aus den Microsoft Sysinternals erweitert die Windows-Ereignisprotokollierung um detaillierte Informationen zu Prozessen, Netzwerkverbindungen, Treiberladungen, Dateierstellungen und weiteren sicherheitsrelevanten Ereignissen. Sofern Sysmon auf einem System installiert und konfiguriert war, können diese Protokolle eine wertvolle Grundlage für die Rekonstruktion digitaler Ereignisse bilden.

Enquire without obligation

Eine professionelle Analyse erfolgt niemals isoliert. Erst die Korrelation mit Event Logs, Registry-Artefakten, Prefetch-Dateien, Dateisystemartefakten und weiteren digitalen Spuren ermöglicht eine belastbare technische Bewertung.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of Sysmon events, reconstruction of process chains, analysis of network connections and file access, correlation with other Windows artefacts, and full documentation of all investigation steps.

Typical areas of application

Incident Response
Malware and ransomware investigations
Analysis of attack chains
Internal security investigations
Employment law proceedings
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, existing Sysmon logs are analysed and technically correlated with other relevant artefacts.

Warum sind Sysmon-Artefakte wichtig?

Provided that Sysmon was active, they provide significantly more detailed information than standard Windows logging and can therefore be of considerable assistance in reconstructing complex incidents.

Frequently Asked Questions

Ist Sysmon auf jedem Windows-System vorhanden?+
Nein. Sysmon muss separat installiert und konfiguriert werden.
Können Sysmon-Protokolle gelöschte Aktivitäten ersetzen?+
Nein. Sie ergänzen andere Artefakte, ersetzen diese jedoch nicht.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Reichen Sysmon-Protokolle allein für ein Gutachten aus?+
Nein. Sie werden immer gemeinsam mit weiteren digitalen Spuren bewertet.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows Sysmon artefacts? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now