IT Forensics – Windows

Forensic analysis of Windows event logs – evaluating system events in a traceable manner

Die Windows-Ereignisprotokolle (Event Logs) gehören zu den wichtigsten Informationsquellen einer Windows-forensischen Untersuchung. Das Betriebssystem protokolliert zahlreiche sicherheitsrelevante Ereignisse wie Anmeldungen, Systemstarts, Programmfehler, Dienständerungen oder sicherheitsrelevante Aktionen. Diese Informationen können wertvolle Hinweise auf den zeitlichen Ablauf eines Vorfalls liefern.

Enquire without obligation

Für eine belastbare Bewertung werden Event Logs niemals isoliert betrachtet. Erst die Korrelation mit weiteren Artefakten wie der Windows Registry, der Master File Table (MFT), dem USN Journal oder Browserdaten ermöglicht eine objektive Rekonstruktion technischer Abläufe.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse security-related Windows event logs, examining logins and logouts, system events, changes to services and logged security events. All findings are cross-referenced with other digital evidence and documented in a traceable manner.

Typical areas of application

Investigation into unauthorised logins
Reconstruction of system starts and restarts
Analysis of security incidents
Incident Response
Allegations of manipulation
Employment law proceedings
Expert reports for the courts

So läuft eine Analyse der Event Logs ab

Once a forensic image has been created, the relevant event logs are extracted and analysed. The individual events are ordered chronologically and correlated with other artefacts. This results in a clear chronology of the relevant system events.

Warum sind Windows Event Logs so wichtig?

Windows event logs document numerous activities carried out by the operating system and often form the basis for reconstructing the timeline of an incident. However, their value is only realised when they are analysed in conjunction with other forensic artefacts.

Frequently Asked Questions

Was sind Windows Event Logs?+
Ereignisprotokolle des Betriebssystems, in denen zahlreiche System- und Sicherheitsereignisse gespeichert werden.
Werden die Originaldaten ausgewertet?+
Nein. Die Analyse erfolgt ausschließlich auf einer forensischen Kopie beziehungsweise einem forensischen Abbild.
Können Event Logs gelöscht werden?+
Je nach Einzelfall können Protokolle verändert oder gelöscht werden. Auch solche Auffälligkeiten können Gegenstand einer forensischen Untersuchung sein.
Reichen Event Logs allein für ein Gutachten aus?+
Nein. Sie werden stets gemeinsam mit weiteren Artefakten bewertet.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows event logs? LanCologne can assist you in securing digital evidence in a manner that meets legal standards and in objectively analysing relevant Windows artefacts.

Get in touch now