IT Forensics – Windows
Forensic Analysis of Windows EFS – Examining Encrypted Files and Certificates
The Encrypting File System (EFS) enables file-based encryption of individual files and folders in Windows. As part of an IT forensic investigation, EFS artefacts can provide clues regarding encrypted data, certificates, user assignments and the security mechanisms in use.
A professional analysis is never carried out in isolation. Only by correlating the data with user profiles, certificate stores, DPAPI artefacts, registry entries and other Windows artefacts is it possible to make a robust technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
We analyse EFS-related artefacts, evaluate encryption information and correlate all findings with other Windows artefacts. All stages of the investigation are documented in a transparent manner.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, all relevant EFS artefacts are analysed and technically assessed alongside other digital evidence.
Why are EFS artefacts important?
EFS artefacts provide evidence of the use of file encryption and its configuration. However, their significance can only be determined through a comprehensive analysis of all relevant digital traces.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you require a professional analysis of Windows EFS artefacts or other Windows components? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic analysis of the Windows certificate store – Tracing digital certificates and trust relationships
- Forensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibility
- Forensic analysis of Windows network profiles – tracing network connections and configurations
- Forensic analysis of Windows WLAN artefacts – Tracing wireless network connections