IT Forensics – Windows

Forensic analysis of SRUM – Tracking system and network activity

The System Resource Usage Monitor (SRUM) is a key component of modern Windows systems. The SRUM database may contain information on application usage, network communication and resource utilisation, thereby providing valuable insights into system activity. The information available depends on the version of Windows and the specific case under investigation.

Enquire without obligation

A professional analysis is never carried out in isolation. Only by correlating the data with other artefacts – such as event logs, the Windows Registry, prefetch files, Amcache, the USN Journal or the Master File Table (MFT) – is it possible to arrive at a reliable technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse the SRUM database, evaluate application and network information, and cross-check the results against other digital traces. Every stage of the investigation is documented in a way that allows for full traceability.

Typical areas of application

Incident Response
Analysis of network activity
Investigation into potential malware
Reconstruction of user activities
Allegations of manipulation
Expert reports for the courts

This is how a SRUM forensic investigation is carried out

Once a forensic image has been created, the SRUM database is extracted and analysed. The information obtained is correlated with other Windows artefacts and then subjected to a technical assessment.

Why is SRUM important?

SRUM can provide additional insights into system and network activity. However, its significance only becomes apparent following a comprehensive analysis of all relevant artefacts in the specific case under investigation.

Frequently Asked Questions

What is SRUM?+
A Windows database for recording various system and resource details.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Can SRUM document network activities?+
Depending on the version of Windows and the data available, relevant information may be provided.
Is SRUM alone sufficient for an expert opinion?+
No. The assessment is always carried out in conjunction with other Windows artefacts.

LanCologne – Windows Forensics in Cologne

Do you require a professional analysis of the SRUM database or other Windows artefacts? LanCologne can assist you with the forensic preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now