IT Forensics – Windows

Forensic analysis of the USN Journal – tracking changes on Windows systems

Das USN Journal (Update Sequence Number Journal) ist ein wichtiges Artefakt des NTFS-Dateisystems. Es protokolliert zahlreiche Änderungen an Dateien und Verzeichnissen und kann dadurch wertvolle Hinweise auf Dateioperationen liefern. Im Rahmen einer professionellen Windows-Forensik wird das USN Journal gemeinsam mit weiteren Artefakten ausgewertet, um technische Abläufe möglichst vollständig zu rekonstruieren.

Enquire without obligation

Die im USN Journal enthaltenen Informationen werden niemals isoliert bewertet. Erst die Korrelation mit der Master File Table (MFT), der Windows Registry, Event-Logs und weiteren Artefakten ermöglicht belastbare technische Feststellungen.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse entries in the USN journal, correlate these with other Windows artefacts, and document all technical findings in a transparent manner. This often enables us to date file modifications, moves or deletions and compare them with other digital traces.

Typical areas of application

Suspected data deletion
Reconstruction of file changes
Data theft
Allegations of manipulation
Incident Response
Employment law proceedings
Presentation of evidence in court

So läuft eine USN-Journal-Analyse ab

Once a forensic image has been created, the USN journal is read out and analysed alongside other file system artefacts. The results are technically assessed, correlated with one another and fully documented. The aim is to objectively reconstruct the relevant events on the basis of verifiable digital traces.

Warum ist das USN Journal so wichtig?

The USN Journal can record changes to files and directories, and as such often provides important insights into the chronological sequence of events within a Windows system. Together with other artefacts, it forms an essential part of modern Windows forensic investigations.

Frequently Asked Questions

Was ist das USN Journal?+
Ein NTFS-Artefakt, das zahlreiche Änderungen an Dateien und Verzeichnissen protokolliert.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Kann das USN Journal allein einen Sachverhalt beweisen?+
Nein. Es wird stets gemeinsam mit weiteren Artefakten bewertet.
Ist das USN Journal auf jedem Windows-System vorhanden?+
Es ist auf vielen NTFS-Systemen vorhanden, die tatsächliche Verfügbarkeit hängt jedoch von der jeweiligen Systemkonfiguration ab.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of the USN journal or other Windows artefacts? LanCologne can assist you with the forensic preservation of digital evidence and the traceable analysis of complex Windows systems.

Get in touch now