IT Forensics – Windows

Forensic analysis of Windows event logs – evaluating system events in a traceable manner

The Windows event logs are among the most important sources of information in a Windows forensic investigation. The operating system logs numerous security-related events such as log-ins, system starts, programme errors, changes to services or security-related actions. This information can provide valuable clues as to the chronology of an incident.

Enquire without obligation

To ensure a reliable assessment, event logs are never analysed in isolation. Only by correlating them with other artefacts – such as the Windows Registry, the Master File Table (MFT), the USN Journal or browser data – is it possible to objectively reconstruct technical processes.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

We analyse security-related Windows event logs, examining logins and logouts, system events, changes to services and logged security events. All findings are cross-referenced with other digital evidence and documented in a traceable manner.

Typical areas of application

Investigation into unauthorised logins
Reconstruction of system starts and restarts
Analysis of security incidents
Incident Response
Allegations of manipulation
Employment law proceedings
Expert reports for the courts

This is how an analysis of the event logs is carried out

Once a forensic image has been created, the relevant event logs are extracted and analysed. The individual events are ordered chronologically and correlated with other artefacts. This results in a clear chronology of the relevant system events.

Why are Windows event logs so important?

Windows event logs document numerous activities carried out by the operating system and often form the basis for reconstructing the timeline of an incident. However, their value is only realised when they are analysed in conjunction with other forensic artefacts.

Frequently Asked Questions

What are Windows event logs?+
Operating system event logs, in which numerous system and security events are recorded.
Is the original data being analysed?+
No. The analysis is carried out exclusively on a forensic copy or a forensic image.
Can event logs be deleted?+
Depending on the individual case, logs may be altered or deleted. Such anomalies may also form the subject of a forensic investigation.
Are event logs alone sufficient for an expert report?+
No. They are always assessed alongside other artefacts.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows event logs? LanCologne can assist you in securing digital evidence in a manner that meets legal standards and in objectively analysing relevant Windows artefacts.

Get in touch now