IT Forensics – Windows

Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation

The NTFS (New Technology File System) file system has formed the basis of modern Windows systems for many years. Virtually every file, every folder and a great deal of system information is managed within this file system. From a digital forensics perspective, NTFS is therefore one of the most important sources of information when investigating a Windows computer.

Enquire without obligation

A professional NTFS analysis makes it possible to trace file movements, evaluate timestamps, assess deleted entries and establish links with other Windows artefacts. In doing so, individual pieces of information are not considered in isolation, but are always assessed within the overall context of the investigation.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination of NTFS file systems is carried out exclusively on a forensic copy or a forensic image. The original evidence remains untouched and is stored in a manner that preserves its evidential integrity.

Our services

Among other things, we analyse the Master File Table (MFT), file attributes, timestamps, directory structures, deleted entries, file associations and other NTFS metadata. The aim is to objectively reconstruct technical processes on the basis of verifiable artefacts.

Typical areas of application

Suspected data deletion
Data theft
Allegations of manipulation
Reconstruction of file movements
Examination of external data storage media
Support for legal proceedings
Reports for private individuals and businesses

How an NTFS forensic investigation is carried out

Once a forensic image has been created, the relevant NTFS structures are analysed. The information obtained is cross-referenced with other Windows artefacts such as the registry, event logs and USB traces. Only a comprehensive analysis enables reliable technical conclusions to be drawn. All stages of the investigation are documented in a transparent manner.

Why is NTFS analysis so important?

The NTFS file system contains a wealth of metadata that extends far beyond the visible file contents. This often reveals technical relationships that remain hidden when viewed in the conventional manner. A professional analysis is therefore an essential part of almost every Windows forensic investigation.

Frequently Asked Questions

Can a deleted file still be recovered?+
Depending on the individual case, NTFS metadata may provide clues as to deleted files.
Is the original always examined?+
No. Only a forensic copy or forensic image is analysed.
Can the MFT prove the facts of the case on its own?+
No. The MFT is an important artefact, but it is always assessed in conjunction with other evidence.
Is NTFS also relevant for external hard drives?+
Yes. Many external storage devices also use NTFS.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of a Windows system or an NTFS file system? LanCologne can assist you with the forensically sound preservation of digital evidence and the traceable analysis of relevant file system artefacts.

Get in touch now