Diese Übersicht bündelt alle Fragen und Antworten rund um professionelle Windows-Forensik bei LanCologne – von Dateisystem und Registry über Nutzungsspuren und Sicherheitssoftware bis hin zu Netzwerk-, Cloud- und Anwendungsartefakten. Klicken Sie auf eine Kategorie, um die passenden Fragen zu sehen.
Dateisystem und Speicherstruktur
- Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation
- Forensic Analysis of the Master File Table (MFT) – The Heart of the NTFS File System
- Forensic analysis of the USN Journal – tracking changes on Windows systems
- Forensic analysis of the Windows page file (pagefile.sys)
- Forensic analysis of the Windows hibernation file (hiberfil.sys)
- Forensic analysis of the Windows thumbnail cache – thumbnails as digital evidence
- In-depth forensic analysis of the Windows pagefile.sys – Reconstructing paged-out memory contents
- In-depth forensic analysis of Windows’ hiberfil.sys – Reconstructing saved RAM contents
- Forensic analysis of Windows ReadyBoot and ReadyBoost artefacts – tracing boot processes and system usage
- Forensic analysis of Windows RAM dumps – Securing ephemeral evidence from main memory
- Forensic analysis of the Windows swapfile.sys – Evaluating additional memory artefacts
Registry und Systemkonfiguration
- Forensic Analysis of the Windows Registry – One of the most important sources of information in Windows forensics
- Forensic analysis of Windows Registry transaction logs – tracing changes to the Registry
- Forensic Analysis of Windows User Accounts (SAM) – Evaluating Local Accounts and Security Information
- Forensic analysis of the Windows SECURITY hive – understanding security configurations
- Forensic analysis of the Windows SOFTWARE hive – reconstructing software and system configurations
- Forensic analysis of the Windows SYSTEM hive – reconstructing system configurations and hardware information
- Forensic analysis of the Windows BCD – Understanding boot configurations
- Forensic analysis of Windows WMI – Understanding persistence mechanisms and system activities
- Forensic analysis of Windows security policies – Understanding security configurations
- Forensic analysis of Windows Group Policy – Understanding system configurations
- Forensic analysis of Windows Active Directory artefacts – Technical investigation of domain activity
Nutzungsspuren und Programmausführung
- Forensic analysis of Windows Prefetch files – identifying evidence of programme execution
- Forensic analysis of LNK files – reconstructing user activities in a traceable manner
- Forensic analysis of jump lists – Important insights into user activity
- Forensic analysis of ShellBags – reconstructing folder access and user activity
- Forensic analysis of Amcache – evidence of programmes and system activity
- Forensic analysis of ShimCache (AppCompatCache) – evidence of applications that have been run
- Forensic analysis of SRUM – Tracking system and network activity
- Forensic analysis of Windows Timeline – tracing user activities chronologically
- Forensic analysis of the Windows Reliability Monitor – tracking system changes and errors chronologically
- Forensic analysis of the Windows Notification Database – notifications as digital evidence
- Forensic analysis of the Windows clipboard history – clipboard contents as a digital trail of evidence
- Forensic analysis of the Windows Activity Cache – reconstructing user activities
- Forensic analysis of the Windows font cache – clues regarding document and programme usage
Sicherheit, Verschlüsselung und Schutzsoftware
- Forensic analysis of Windows BitLocker artefacts – understanding encryption status and system information
- Forensic analysis of Windows Credential Manager – Tracing stored login credentials
- Forensic Analysis of Windows DPAPI – Tracing Protected User Data and Keys
- Forensic analysis of Windows Defender artefacts – tracing security events
- Forensic analysis of Windows Microsoft Defender for Endpoint (MDE) artefacts – tracing security events
- Forensic analysis of Windows EDR artefacts – reconstructing security events and attack chains
- Forensic analysis of Windows antivirus and security software – technical assessment of security incidents
- Forensic Analysis of Windows Sandbox Artifacts – Tracing Temporary Execution Environments
- Forensic analysis of Windows Defender Application Control (WDAC) – Understanding application policies
- Forensic analysis of Windows Defender Antivirus artefacts – tracing security events
Netzwerk und Kommunikation
- Forensic analysis of the Windows DNS cache – tracing network activity
- Forensic analysis of Windows Firewall artefacts – tracing network communication and configuration changes
- Forensic analysis of Windows COM artefacts – tracing components and system activities
- Forensic Analysis of Windows COM+ – Tracing Distributed Components and Services
- Forensic analysis of Windows MountPoints2 artefacts – evidence of connected storage devices
- Forensic analysis of the Windows Device Metadata Cache – evidence of detected hardware
- Forensic Analysis of Windows Portable Devices (WPD) – Mobile Devices as Digital Evidence
- Forensic Analysis of Windows Bluetooth Artifacts – Tracing Paired Devices and Connections
- Forensic analysis of Windows Nearby Sharing – Reconstructing local file transfers
- Forensic analysis of Windows Delivery Optimisation – tracing Update and transmission artefacts
Autostart, Prozesse und Systemprotokolle
- Forensic analysis of Windows event logs – evaluating system events in a traceable manner
- Forensic Analysis of Windows Services – Investigating Persistence and System Configuration
- Forensic analysis of Windows autostart entries – identifying persistence mechanisms
- Forensic analysis of scheduled tasks – Tracing automated processes
- Forensic analysis of Windows Setup API logs – tracing device installations
- Forensic Analysis of Windows PowerShell Artifacts – Tracing Commands and Activities
- Forensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system events
- Forensic Analysis of Windows ETL Logs – Tracing Detailed System Events
- Forensic analysis of Windows Performance Monitor and Performance Logs – Understanding system states
- Forensic analysis of Windows Live Response artefacts – Backing up transient system information
- Forensic analysis of the Windows Print Spooler – Technical investigation of print jobs
Benutzer, Cloud und Anwendungen
- Forensic analysis of the Windows Recycle Bin – Tracing deleted files
- Forensic analysis of Windows USB artefacts – Tracing connected devices
- Forensic analysis of Windows user profiles – tracing user activities
- Forensic analysis of Windows AppData – analysing application and user data
- Forensic analysis of Windows temporary files – Temporary artefacts as digital evidence
- In-depth forensic analysis of the Windows Recycle Bin (.Bin) – tracing deletion processes
- Forensic Analysis of Windows Offline Files (CSC) – Analysing Cached Network Files
- Forensic analysis of Windows synchronisation artefacts – tracing synchronisation processes
- Forensic analysis of Windows OneDrive artefacts – Technical assessment of local cloud traces
- Forensic analysis of Windows Update artefacts – tracing installations and system changes
- Forensic analysis of Windows Microsoft Store artefacts – Tracing installed apps and updates
- Forensic Analysis of Windows AppX Packages – Understanding Modern Windows Applications
- Forensic Analysis of Windows MSIX Packages – Understanding Modern Application Installations
- Forensic Analysis of Windows Hyper-V Artefacts – Understanding Virtual Infrastructures
Sonstige Fragen
- Forensic Analysis of Windows EFS – Examining Encrypted Files and Certificates
- Forensic analysis of the Windows certificate store – Tracing digital certificates and trust relationships
- Forensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibility
- Forensic analysis of Windows network profiles – tracing network connections and configurations
- Forensic analysis of Windows WLAN artefacts – Tracing wireless network connections
- Forensic analysis of Windows RDP artefacts – tracing Remote Desktop connections
- Forensic Analysis of Windows SMB Artifacts – Tracing Network Shares and File Accesses
- Forensic analysis of Windows VPN artefacts – tracing VPN connections and configurations
- Forensic analysis of Windows DNS client artefacts – tracing name resolutions and network activity
- Forensic analysis of Windows proxy artefacts – Understanding proxy configurations and network communication
- Forensic analysis of the Windows hosts file – Tracing manual name resolutions
- Forensic analysis of Windows TCP/IP configuration – Understanding network settings
- Forensic analysis of Windows network adapters – understanding network interfaces and system configuration
- Forensic analysis of Windows Volume Shadow Copies – Tracing previous file states and system information
- Forensic analysis of the Windows Search database – Tracing indexed files and search information
- Forensic analysis of the Windows Search Index – Tracing indexed data and file references
- Forensic analysis of Windows Error Reporting (WER) – investigating programme crashes and system errors
- Forensic analysis of Windows crash dumps – Technical reconstruction of system crashes
- Forensic analysis of Windows memory dumps – analysing volatile data from RAM