Diese Übersicht bündelt alle Fragen und Antworten rund um professionelle Windows-Forensik bei LanCologne – von Dateisystem und Registry über Nutzungsspuren und Sicherheitssoftware bis hin zu Netzwerk-, Cloud- und Anwendungsartefakten. Klicken Sie auf eine Kategorie, um die passenden Fragen zu sehen.
Dateisystem und Speicherstruktur
- Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation
- Forensic Analysis of the Master File Table (MFT) – The Heart of the NTFS File System
- Forensic analysis of the USN Journal – tracking changes on Windows systems
- Windows-Auslagerungsdatei (pagefile.sys) forensisch analysieren
- Forensic analysis of the Windows hibernation file (hiberfil.sys)
- Windows Thumbnail Cache forensisch analysieren – Vorschaubilder als digitale Spur
- Windows pagefile.sys vertieft forensisch analysieren – Ausgelagerte Speicherinhalte rekonstruieren
- In-depth forensic analysis of Windows’ hiberfil.sys – Reconstructing saved RAM contents
- Forensic analysis of Windows ReadyBoot and ReadyBoost artefacts – tracing boot processes and system usage
- Forensic analysis of Windows RAM dumps – Securing ephemeral evidence from main memory
- Forensic analysis of the Windows swapfile.sys – Evaluating additional memory artefacts
Registry und Systemkonfiguration
- Forensic Analysis of the Windows Registry – One of the most important sources of information in Windows forensics
- Forensic analysis of Windows Registry transaction logs – tracing changes to the Registry
- Forensic Analysis of Windows User Accounts (SAM) – Evaluating Local Accounts and Security Information
- Forensic analysis of the Windows SECURITY hive – understanding security configurations
- Windows SOFTWARE-Hive forensisch analysieren – Software- und Systemkonfigurationen rekonstruieren
- Forensic analysis of the Windows SYSTEM hive – reconstructing system configurations and hardware information
- Forensic analysis of the Windows BCD – Understanding boot configurations
- Windows WMI forensisch analysieren – Persistenzmechanismen und Systemaktivitäten nachvollziehen
- Windows Sicherheitsrichtlinien forensisch analysieren – Sicherheitskonfigurationen nachvollziehen
- Forensic analysis of Windows Group Policy – Understanding system configurations
- Windows Active Directory-Artefakte forensisch analysieren – Domänenaktivitäten technisch nachvollziehen
Nutzungsspuren und Programmausführung
- Forensic analysis of Windows Prefetch files – identifying evidence of programme execution
- Forensic analysis of LNK files – reconstructing user activities in a traceable manner
- Forensic analysis of jump lists – Important insights into user activity
- ShellBags forensisch analysieren – Ordnerzugriffe und Benutzeraktivitäten rekonstruieren
- Forensic analysis of Amcache – evidence of programmes and system activity
- Forensic analysis of ShimCache (AppCompatCache) – evidence of applications that have been run
- SRUM forensisch analysieren – System- und Netzwerkaktivitäten nachvollziehen
- Windows Timeline forensisch analysieren – Benutzeraktivitäten chronologisch nachvollziehen
- Forensic analysis of the Windows Reliability Monitor – tracking system changes and errors chronologically
- Forensic analysis of the Windows Notification Database – notifications as digital evidence
- Windows Clipboard History forensisch analysieren – Inhalte der Zwischenablage als digitale Beweisspur
- Forensic analysis of the Windows Activity Cache – reconstructing user activities
- Forensic analysis of the Windows font cache – clues regarding document and programme usage
Sicherheit, Verschlüsselung und Schutzsoftware
- Forensic analysis of Windows BitLocker artefacts – understanding encryption status and system information
- Windows Credential Manager forensisch analysieren – Gespeicherte Anmeldeinformationen nachvollziehen
- Forensic Analysis of Windows DPAPI – Tracing Protected User Data and Keys
- Windows Defender-Artefakte forensisch analysieren – Sicherheitsereignisse nachvollziehen
- Forensic analysis of Windows Microsoft Defender for Endpoint (MDE) artefacts – tracing security events
- Windows EDR-Artefakte forensisch analysieren – Sicherheitsereignisse und Angriffsketten rekonstruieren
- Windows Antiviren- und Sicherheitssoftware forensisch analysieren – Sicherheitsereignisse technisch bewerten
- Forensic Analysis of Windows Sandbox Artifacts – Tracing Temporary Execution Environments
- Forensic analysis of Windows Defender Application Control (WDAC) – Understanding application policies
- Forensic analysis of Windows Defender Antivirus artefacts – tracing security events
Netzwerk und Kommunikation
- Windows DNS-Cache forensisch analysieren – Netzwerkaktivitäten nachvollziehen
- Windows Firewall-Artefakte forensisch analysieren – Netzwerkkommunikation und Konfigurationsänderungen nachvollziehen
- Forensic analysis of Windows COM artefacts – tracing components and system activities
- Forensic Analysis of Windows COM+ – Tracing Distributed Components and Services
- Windows MountPoints2-Artefakte forensisch analysieren – Hinweise auf angeschlossene Datenträger
- Windows Device Metadata Cache forensisch analysieren – Hinweise auf erkannte Hardware
- Windows Portable Devices (WPD) forensisch analysieren – Mobile Geräte als digitale Spur
- Forensic Analysis of Windows Bluetooth Artifacts – Tracing Paired Devices and Connections
- Forensic analysis of Windows Nearby Sharing – Reconstructing local file transfers
- Forensic analysis of Windows Delivery Optimisation – tracing Update and transmission artefacts
Autostart, Prozesse und Systemprotokolle
- Forensic analysis of Windows event logs – evaluating system events in a traceable manner
- Forensic Analysis of Windows Services – Investigating Persistence and System Configuration
- Forensic analysis of Windows autostart entries – identifying persistence mechanisms
- Geplante Aufgaben (Scheduled Tasks) forensisch analysieren – Automatische Abläufe nachvollziehen
- Forensic analysis of Windows Setup API logs – tracing device installations
- Forensic Analysis of Windows PowerShell Artifacts – Tracing Commands and Activities
- Forensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system events
- Forensic Analysis of Windows ETL Logs – Tracing Detailed System Events
- Windows Performance Monitor und Performance Logs forensisch analysieren – Systemzustände nachvollziehen
- Windows Live Response Artefakte forensisch analysieren – Flüchtige Systeminformationen sichern
- Forensic analysis of the Windows Print Spooler – Technical investigation of print jobs
Benutzer, Cloud und Anwendungen
- Forensic analysis of the Windows Recycle Bin – Tracing deleted files
- Forensic analysis of Windows USB artefacts – Tracing connected devices
- Windows-Benutzerprofile forensisch analysieren – Benutzeraktivitäten nachvollziehen
- Windows AppData forensisch analysieren – Anwendungs- und Benutzerdaten auswerten
- Windows Temp-Dateien forensisch analysieren – Temporäre Artefakte als digitale Beweismittel
- Windows Papierkorb (.Bin) vertieft forensisch analysieren – Löschvorgänge nachvollziehen
- Forensic Analysis of Windows Offline Files (CSC) – Analysing Cached Network Files
- Forensic analysis of Windows synchronisation artefacts – tracing synchronisation processes
- Windows OneDrive-Artefakte forensisch analysieren – Lokale Cloud-Spuren technisch bewerten
- Forensic analysis of Windows Update artefacts – tracing installations and system changes
- Forensic analysis of Windows Microsoft Store artefacts – Tracing installed apps and updates
- Forensic Analysis of Windows AppX Packages – Understanding Modern Windows Applications
- Forensic Analysis of Windows MSIX Packages – Understanding Modern Application Installations
- Forensic Analysis of Windows Hyper-V Artefacts – Understanding Virtual Infrastructures
Sonstige Fragen
- Forensic Analysis of Windows EFS – Examining Encrypted Files and Certificates
- Windows Zertifikatsspeicher forensisch analysieren – Digitale Zertifikate und Vertrauensstellungen nachvollziehen
- Forensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibility
- Forensic analysis of Windows network profiles – tracing network connections and configurations
- Windows WLAN-Artefakte forensisch analysieren – Drahtlose Netzwerkverbindungen nachvollziehen
- Windows RDP-Artefakte forensisch analysieren – Remote-Desktop-Verbindungen nachvollziehen
- Forensic Analysis of Windows SMB Artifacts – Tracing Network Shares and File Accesses
- Forensic analysis of Windows VPN artefacts – tracing VPN connections and configurations
- Windows DNS-Client-Artefakte forensisch analysieren – Namensauflösungen und Netzwerkaktivitäten nachvollziehen
- Forensic analysis of Windows proxy artefacts – Understanding proxy configurations and network communication
- Windows Hosts-Datei forensisch analysieren – Manuelle Namensauflösungen nachvollziehen
- Forensic analysis of Windows TCP/IP configuration – Understanding network settings
- Forensic analysis of Windows network adapters – understanding network interfaces and system configuration
- Windows Volume Shadow Copies forensisch analysieren – Frühere Dateistände und Systeminformationen nachvollziehen
- Forensic analysis of the Windows Search database – Tracing indexed files and search information
- Windows Search Index forensisch analysieren – Indizierte Daten und Dateiverweise nachvollziehen
- Windows Error Reporting (WER) forensisch analysieren – Programmabstürze und Systemfehler nachvollziehen
- Forensic analysis of Windows crash dumps – Technical reconstruction of system crashes
- Windows Memory Dumps forensisch analysieren – Flüchtige Daten aus dem Arbeitsspeicher auswerten