IT Forensics – Windows
Forensic Analysis of Windows AppX Packages – Understanding Modern Windows Applications
AppX packages form the basis for modern Windows applications (UWP apps). The installation, updating and removal of these applications leave behind various artefacts that can provide clues about a system’s usage.
As part of a professional IT forensic investigation, AppX artefacts are never assessed in isolation. Only by correlating them with registry artefacts, user profiles, event logs, Microsoft Store data and other digital traces is it possible to carry out a robust technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of installed AppX packages, reconstruction of installation and update processes, correlation with other Windows artefacts, and full documentation of all investigation steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, AppX-related artefacts are identified, analysed and technically assessed alongside other digital traces.
Why are AppX artefacts important?
They enable conclusions to be drawn about modern Windows applications that have been installed, their updates and, in some cases, their use, thereby contributing to the overall reconstruction of a digital scenario.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne helps you carry out a legally admissible analysis of Windows AppX packages and objectively reconstruct installation and user activities.
Related to this topic
- Forensic Analysis of Windows MSIX Packages – Understanding Modern Application Installations
- Forensic Analysis of Windows Hyper-V Artefacts – Understanding Virtual Infrastructures
- Forensic analysis of the Windows Recycle Bin – Tracing deleted files
- Forensic analysis of Windows USB artefacts – Tracing connected devices