IT Forensics – Windows
Forensic analysis of the Windows Activity Cache – reconstructing user activities
Depending on the version of Windows and the system configuration, the Windows Activity Cache contains information about user activities and their chronological sequence. These artefacts can help to track application usage, document access and other activities on a system.
As part of a professional IT forensic investigation, data from the activity cache is never assessed in isolation. Only by correlating it with timeline artefacts, event logs, registry data, file system traces and other digital evidence is it possible to carry out a reliable technical reconstruction.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of the Windows Activity Cache, chronological reconstruction of user activities, correlation with other Windows artefacts, and full documentation of all investigative steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, any existing activity cache artefacts are identified, technically analysed and correlated with other digital traces.
Why is the activity cache important?
The Activity Cache can provide additional clues as to the chronological sequence of user activities and thereby assist in reconstructing a digital sequence of events.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne helps you carry out a legally admissible analysis of the Windows Activity Cache and objectively reconstruct digital user activities.
Related to this topic
- Forensic analysis of the Windows font cache – clues regarding document and programme usage
- Forensic analysis of Windows Prefetch files – identifying evidence of programme execution
- Forensic analysis of LNK files – reconstructing user activities in a traceable manner
- Forensic analysis of jump lists – Important insights into user activity