IT Forensics – Windows
Forensic analysis of the Windows Notification Database – notifications as digital evidence
Windows stores a wide range of information about system and application notifications in the Notification Database. Depending on the version of Windows, this may include details of messages received, app notifications and time-based events.
As part of a professional IT forensic investigation, these artefacts are never assessed in isolation. Only by correlating them with event logs, user profiles, registry data, app artefacts and other digital traces is it possible to carry out a reliable technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of the Windows Notification Database, chronological ordering of notifications, correlation with other Windows artefacts, and comprehensive documentation of all investigative steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, the relevant databases and artefacts are analysed and cross-referenced with other digital evidence.
Why is the Notification Database important?
It can provide information on the chronological sequence of certain events and user interactions, thereby helping to reconstruct the facts of a case.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne helps you carry out a legally admissible analysis of the Windows Notification Database and objectively reconstruct digital events.
Related to this topic
- Forensic analysis of the Windows clipboard history – clipboard contents as a digital trail of evidence
- Forensic analysis of the Windows Activity Cache – reconstructing user activities
- Forensic analysis of the Windows font cache – clues regarding document and programme usage
- Forensic analysis of Windows Prefetch files – identifying evidence of programme execution