IT Forensics – Windows
Forensic analysis of Windows memory dumps – analysing volatile data from RAM
During operation, the random access memory (RAM) contains a great deal of volatile information which is lost when the system is switched off. Memory dumps allow the memory state at the time the dump was taken to be analysed and can provide clues about running processes, network connections, loaded drivers or malware.
A professional analysis is never carried out in isolation. Only by correlating the findings with file system artefacts, registry data, event logs, prefetch files and other digital traces is it possible to arrive at a reliable technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The investigation is carried out exclusively on a forensic copy or a forensic image. Memory images are backed up in a manner that preserves their evidential integrity, and all stages of the investigation are documented in a traceable manner. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of memory dumps, investigation of running processes, network connections, DLLs, handles, injected code and malware indicators, as well as full documentation of all investigation steps.
Typical areas of application
This is how the analysis works
Once the system memory has been securely backed up, the relevant memory structures are analysed and correlated with other Windows artefacts.
Why are memory dumps important?
They may contain information that is no longer available once the system has been restarted or switched off. As such, they are an important complement to persistent storage artefacts in many investigations.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows memory dumps or other Windows artefacts? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic Analysis of Windows EFS – Examining Encrypted Files and Certificates
- Forensic analysis of the Windows certificate store – Tracing digital certificates and trust relationships
- Forensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibility
- Forensic analysis of Windows network profiles – tracing network connections and configurations