IT Forensics – Windows

Forensic analysis of Windows Live Response artefacts – Backing up transient system information

A live response involves backing up information from a Windows system that is still running before the device is switched off. This includes, amongst other things, running processes, services, network connections, logged-in users, open files and other volatile system information.

Enquire without obligation

As volatile data may be lost following a restart, its secure collection constitutes an important part of an IT forensic investigation in appropriate cases. The results are always assessed in conjunction with data carrier artefacts.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Backup of volatile data, analysis of running processes, network connections and services, correlation with RAM images, registry, event and file system artefacts, and comprehensive documentation.

Typical areas of application

Incident Response
Ransomware
Malware investigations
Insider incidents
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Before the system is shut down, volatile data is backed up using appropriate forensic tools. This is then analysed alongside all other digital evidence.

Why is Live Response important?

Much security-related information exists solely within the running system and is no longer available after a restart.

Frequently Asked Questions

When is a live response carried out?+
If the system is still running and you need to back up volatile data.
Does a live response replace digital forensics?+
No. The two methods complement each other.
Is the work carried out directly on the original?+
Only to the extent technically necessary to secure volatile data in a manner that preserves its evidential value. The subsequent analysis is carried out exclusively on the secured forensic data.
Is Live Response always a good idea?+
No. This depends on the specific issue and the evidence available.

🔗 Related topics

LanCologne – Windows Forensics in Cologne

LanCologne helps you to securely back up volatile data in a way that preserves evidence and to carry out legally admissible analysis of complex Windows systems.

Get in touch now