IT Forensics – Windows

Forensic analysis of Windows memory dumps – analysing volatile data from RAM

During operation, the random access memory (RAM) contains a great deal of volatile information which is lost when the system is switched off. Memory dumps allow the memory state at the time the dump was taken to be analysed and can provide clues about running processes, network connections, loaded drivers or malware.

Enquire without obligation

A professional analysis is never carried out in isolation. Only by correlating the findings with file system artefacts, registry data, event logs, prefetch files and other digital traces is it possible to arrive at a reliable technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The investigation is carried out exclusively on a forensic copy or a forensic image. Memory images are backed up in a manner that preserves their evidential integrity, and all stages of the investigation are documented in a traceable manner. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of memory dumps, investigation of running processes, network connections, DLLs, handles, injected code and malware indicators, as well as full documentation of all investigation steps.

Typical areas of application

Incident Response
Malware and rootkit investigations
Analysis of ongoing processes
Reconstruction of transient system states
Employment law proceedings
Expert reports for the courts

This is how the analysis works

Once the system memory has been securely backed up, the relevant memory structures are analysed and correlated with other Windows artefacts.

Why are memory dumps important?

They may contain information that is no longer available once the system has been restarted or switched off. As such, they are an important complement to persistent storage artefacts in many investigations.

Frequently Asked Questions

What information can memory dumps contain?+
Depending on the situation, these may include, amongst other things, running processes, network connections, storage objects and other volatile data.
Is it always possible to back up RAM?+
No. It requires that the system is still switched on and that a forensically valid backup can be carried out.
Are you working with the original data carrier?+
No. Only a forensic copy or forensic image is analysed; memory images are backed up separately.
Are memory dumps alone sufficient for an expert report?+
No. They are always analysed alongside other Windows artefacts.

LanCologne – Windows Forensics in Cologne

Do you need a professional analysis of Windows memory dumps or other Windows artefacts? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.

Get in touch now