IT Forensics – Windows
Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation
The NTFS (New Technology File System) file system has formed the basis of modern Windows systems for many years. Virtually every file, every folder and a great deal of system information is managed within this file system. From a digital forensics perspective, NTFS is therefore one of the most important sources of information when investigating a Windows computer.
A professional NTFS analysis makes it possible to trace file movements, evaluate timestamps, assess deleted entries and establish links with other Windows artefacts. In doing so, individual pieces of information are not considered in isolation, but are always assessed within the overall context of the investigation.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination of NTFS file systems is carried out exclusively on a forensic copy or a forensic image. The original evidence remains untouched and is stored in a manner that preserves its evidential integrity.
Our services
Among other things, we analyse the Master File Table (MFT), file attributes, timestamps, directory structures, deleted entries, file associations and other NTFS metadata. The aim is to objectively reconstruct technical processes on the basis of verifiable artefacts.
Typical areas of application
How an NTFS forensic investigation is carried out
Once a forensic image has been created, the relevant NTFS structures are analysed. The information obtained is cross-referenced with other Windows artefacts such as the registry, event logs and USB traces. Only a comprehensive analysis enables reliable technical conclusions to be drawn. All stages of the investigation are documented in a transparent manner.
Why is NTFS analysis so important?
The NTFS file system contains a wealth of metadata that extends far beyond the visible file contents. This often reveals technical relationships that remain hidden when viewed in the conventional manner. A professional analysis is therefore an essential part of almost every Windows forensic investigation.
Frequently Asked Questions
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of a Windows system or an NTFS file system? LanCologne can assist you with the forensically sound preservation of digital evidence and the traceable analysis of relevant file system artefacts.
Related to this topic