IT Forensics – Windows
Forensic analysis of Windows Live Response artefacts – Backing up transient system information
A live response involves backing up information from a Windows system that is still running before the device is switched off. This includes, amongst other things, running processes, services, network connections, logged-in users, open files and other volatile system information.
As volatile data may be lost following a restart, its secure collection constitutes an important part of an IT forensic investigation in appropriate cases. The results are always assessed in conjunction with data carrier artefacts.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Backup of volatile data, analysis of running processes, network connections and services, correlation with RAM images, registry, event and file system artefacts, and comprehensive documentation.
Typical areas of application
This is how the analysis works
Before the system is shut down, volatile data is backed up using appropriate forensic tools. This is then analysed alongside all other digital evidence.
Why is Live Response important?
Much security-related information exists solely within the running system and is no longer available after a restart.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne helps you to securely back up volatile data in a way that preserves evidence and to carry out legally admissible analysis of complex Windows systems.
Related to this topic
- Forensic analysis of the Windows Print Spooler – Technical investigation of print jobs
- Forensic analysis of Windows event logs – evaluating system events in a traceable manner
- Forensic Analysis of Windows Services – Investigating Persistence and System Configuration
- Forensic analysis of Windows autostart entries – identifying persistence mechanisms