IT Forensics – Windows

Forensic Analysis of Windows COM+ – Tracing Distributed Components and Services

COM+ extends the Component Object Model (COM) with additional features such as transaction management, event handling and security-related services. Applications and system components can utilise COM+ objects, whilst leaving configuration and audit trails.

Enquire without obligation

In the context of a professional IT forensic investigation, COM+ artefacts are never assessed in isolation. Only by correlating them with registry artefacts, Windows services, event logs, file system traces and other digital evidence is it possible to carry out a robust technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of COM+ configurations, services and applications; evaluation of security-related settings; correlation with other Windows artefacts; and comprehensive documentation of all investigation steps.

Typical areas of application

Incident Response
Malware analysis
Investigation of persistence mechanisms
Software forensics
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, any existing COM+ artefacts are identified, analysed and technically categorised alongside other digital traces.

Why are COM+ artefacts important?

They can provide information on installed applications, security-related configurations and changes to system components, thereby helping to reconstruct complex IT scenarios.

Frequently Asked Questions

Which COM+ artefacts are being examined?+
These include, amongst other things, COM+ applications, services, configuration data and associated registry entries.
Are COM+ artefacts always present?+
No. Their size depends on the applications installed and the system configuration.
Are you working on the original system?+
No. Only a forensic copy or forensic image is analysed.
Are COM+ artefacts alone sufficient for an expert report?+
No. They are always assessed alongside other digital evidence.

LanCologne – Windows Forensics in Cologne

LanCologne assists you in carrying out legally admissible analyses of Windows COM+ artefacts and in the objective reconstruction of complex IT forensic cases.

Get in touch now