IT Forensics – Windows
Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation
Das NTFS-Dateisystem (New Technology File System) bildet seit vielen Jahren die Grundlage moderner Windows-Systeme. Nahezu jede Datei, jeder Ordner und zahlreiche Systeminformationen werden innerhalb dieses Dateisystems verwaltet. Aus IT-forensischer Sicht zählt NTFS deshalb zu den wichtigsten Informationsquellen bei der Untersuchung eines Windows-Computers.
Eine professionelle NTFS-Analyse ermöglicht es, Dateibewegungen nachzuvollziehen, Zeitstempel auszuwerten, gelöschte Einträge zu bewerten und Zusammenhänge mit weiteren Windows-Artefakten herzustellen. Dabei werden nicht einzelne Informationen isoliert betrachtet, sondern stets im Gesamtkontext der Untersuchung bewertet.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination of NTFS file systems is carried out exclusively on a forensic copy or a forensic image. The original evidence remains untouched and is stored in a manner that preserves its evidential integrity.
Our services
Among other things, we analyse the Master File Table (MFT), file attributes, timestamps, directory structures, deleted entries, file associations and other NTFS metadata. The aim is to objectively reconstruct technical processes on the basis of verifiable artefacts.
Typical areas of application
So läuft eine NTFS-forensische Untersuchung ab
Once a forensic image has been created, the relevant NTFS structures are analysed. The information obtained is cross-referenced with other Windows artefacts such as the registry, event logs and USB traces. Only a comprehensive analysis enables reliable technical conclusions to be drawn. All stages of the investigation are documented in a transparent manner.
Warum ist die NTFS-Analyse so wichtig?
The NTFS file system contains a wealth of metadata that extends far beyond the visible file contents. This often reveals technical relationships that remain hidden when viewed in the conventional manner. A professional analysis is therefore an essential part of almost every Windows forensic investigation.
Frequently Asked Questions
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of a Windows system or an NTFS file system? LanCologne can assist you with the forensically sound preservation of digital evidence and the traceable analysis of relevant file system artefacts.