IT Forensics – Windows

Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation

Das NTFS-Dateisystem (New Technology File System) bildet seit vielen Jahren die Grundlage moderner Windows-Systeme. Nahezu jede Datei, jeder Ordner und zahlreiche Systeminformationen werden innerhalb dieses Dateisystems verwaltet. Aus IT-forensischer Sicht zählt NTFS deshalb zu den wichtigsten Informationsquellen bei der Untersuchung eines Windows-Computers.

Enquire without obligation

Eine professionelle NTFS-Analyse ermöglicht es, Dateibewegungen nachzuvollziehen, Zeitstempel auszuwerten, gelöschte Einträge zu bewerten und Zusammenhänge mit weiteren Windows-Artefakten herzustellen. Dabei werden nicht einzelne Informationen isoliert betrachtet, sondern stets im Gesamtkontext der Untersuchung bewertet.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination of NTFS file systems is carried out exclusively on a forensic copy or a forensic image. The original evidence remains untouched and is stored in a manner that preserves its evidential integrity.

Our services

Among other things, we analyse the Master File Table (MFT), file attributes, timestamps, directory structures, deleted entries, file associations and other NTFS metadata. The aim is to objectively reconstruct technical processes on the basis of verifiable artefacts.

Typical areas of application

Suspected data deletion
Data theft
Allegations of manipulation
Reconstruction of file movements
Examination of external data storage media
Support for legal proceedings
Reports for private individuals and businesses

So läuft eine NTFS-forensische Untersuchung ab

Once a forensic image has been created, the relevant NTFS structures are analysed. The information obtained is cross-referenced with other Windows artefacts such as the registry, event logs and USB traces. Only a comprehensive analysis enables reliable technical conclusions to be drawn. All stages of the investigation are documented in a transparent manner.

Warum ist die NTFS-Analyse so wichtig?

The NTFS file system contains a wealth of metadata that extends far beyond the visible file contents. This often reveals technical relationships that remain hidden when viewed in the conventional manner. A professional analysis is therefore an essential part of almost every Windows forensic investigation.

Frequently Asked Questions

Kann eine gelöschte Datei noch nachgewiesen werden?+
Je nach Einzelfall können NTFS-Metadaten Hinweise auf gelöschte Dateien liefern.
Wird immer das Original untersucht?+
No. Only a forensic copy or forensic image is analysed.
Kann die MFT allein den Sachverhalt beweisen?+
Nein. Die MFT ist ein wichtiges Artefakt, wird jedoch stets zusammen mit weiteren Spuren bewertet.
Ist NTFS auch auf externen Festplatten relevant?+
Ja. Viele externe Datenträger verwenden ebenfalls NTFS.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of a Windows system or an NTFS file system? LanCologne can assist you with the forensically sound preservation of digital evidence and the traceable analysis of relevant file system artefacts.

Get in touch now