IT Forensics – Windows

Forensic analysis of Windows EDR artefacts – reconstructing security events and attack chains

Modern endpoint detection and response (EDR) solutions log security-related events on endpoints. Depending on the vendor, this may include information on processes, network connections, file access, user activities and detected threats.

Enquire without obligation

As part of a professional IT forensic investigation, EDR artefacts are never assessed in isolation. Only by correlating them with Windows event logs, Sysmon data, registry artefacts, file system traces and other digital evidence is it possible to carry out a robust technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of local EDR artefacts from various manufacturers, reconstruction of attack chains, correlation with other Windows artefacts, and full documentation of all investigation steps.

Typical areas of application

Incident Response
Ransomware investigations
Malware analysis
Advanced Persistent Threats (APT)
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, any existing EDR artefacts are identified, analysed and technically assessed alongside other digital evidence.

Why are EDR artefacts important?

They can provide a detailed chronology of security-related events, thereby significantly aiding the reconstruction of complex incidents. However, the assessment is always carried out within the overall context of all available evidence.

Frequently Asked Questions

Which EDR solutions can be assessed?+
In principle, it is possible to analyse the locally available artefacts from various EDR products, provided they are present on the system.
Is EDR data always available?+
No. This depends on whether a suitable EDR solution was installed and active.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Are EDR artefacts alone sufficient for an expert report?+
No. They are always assessed alongside other digital evidence.

🔗 Related topics

LanCologne – Windows Forensics in Cologne

LanCologne supports you in the legally admissible analysis of EDR artefacts and the objective assessment of complex IT forensic security incidents.

Get in touch now