IT Forensics – Windows
Forensic analysis of Windows event logs – evaluating system events in a traceable manner
Die Windows-Ereignisprotokolle (Event Logs) gehören zu den wichtigsten Informationsquellen einer Windows-forensischen Untersuchung. Das Betriebssystem protokolliert zahlreiche sicherheitsrelevante Ereignisse wie Anmeldungen, Systemstarts, Programmfehler, Dienständerungen oder sicherheitsrelevante Aktionen. Diese Informationen können wertvolle Hinweise auf den zeitlichen Ablauf eines Vorfalls liefern.
Für eine belastbare Bewertung werden Event Logs niemals isoliert betrachtet. Erst die Korrelation mit weiteren Artefakten wie der Windows Registry, der Master File Table (MFT), dem USN Journal oder Browserdaten ermöglicht eine objektive Rekonstruktion technischer Abläufe.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
We analyse security-related Windows event logs, examining logins and logouts, system events, changes to services and logged security events. All findings are cross-referenced with other digital evidence and documented in a traceable manner.
Typical areas of application
So läuft eine Analyse der Event Logs ab
Once a forensic image has been created, the relevant event logs are extracted and analysed. The individual events are ordered chronologically and correlated with other artefacts. This results in a clear chronology of the relevant system events.
Warum sind Windows Event Logs so wichtig?
Windows event logs document numerous activities carried out by the operating system and often form the basis for reconstructing the timeline of an incident. However, their value is only realised when they are analysed in conjunction with other forensic artefacts.
Frequently Asked Questions
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows event logs? LanCologne can assist you in securing digital evidence in a manner that meets legal standards and in objectively analysing relevant Windows artefacts.