IT Forensics – Windows

Forensic Analysis of Windows EFS – Examining Encrypted Files and Certificates

The Encrypting File System (EFS) enables file-based encryption of individual files and folders in Windows. As part of an IT forensic investigation, EFS artefacts can provide clues regarding encrypted data, certificates, user assignments and the security mechanisms in use.

Enquire without obligation

A professional analysis is never carried out in isolation. Only by correlating the data with user profiles, certificate stores, DPAPI artefacts, registry entries and other Windows artefacts is it possible to make a robust technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse EFS-related artefacts, evaluate encryption information and correlate all findings with other Windows artefacts. All stages of the investigation are documented in a transparent manner.

Typical areas of application

Examination of encrypted files
Incident Response
Analysis of compromised user accounts
Reconstruction of system configurations
Employment law proceedings
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, all relevant EFS artefacts are analysed and technically assessed alongside other digital evidence.

Why are EFS artefacts important?

EFS artefacts provide evidence of the use of file encryption and its configuration. However, their significance can only be determined through a comprehensive analysis of all relevant digital traces.

Frequently Asked Questions

What is Windows EFS?+
EFS is Windows’ built-in file-based encryption feature.
Can any encrypted file be decrypted?+
No. This depends, amongst other things, on the keys and certificates available and the scope of the investigation.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Are EFS artefacts alone sufficient for an expert report?+
No. They are always analysed alongside other Windows artefacts.

LanCologne – Windows Forensics in Cologne

Do you require a professional analysis of Windows EFS artefacts or other Windows components? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now