IT Forensics – Windows
Forensic Analysis of Windows Offline Files (CSC) – Analysing Cached Network Files
Windows kann Dateien aus Netzwerkfreigaben lokal im sogenannten Client Side Cache (CSC) speichern, damit diese auch ohne aktive Netzwerkverbindung verfügbar sind. Diese Offline-Dateien können forensisch relevante Informationen über Dateizugriffe, Synchronisationsvorgänge und Benutzeraktivitäten enthalten.
Im Rahmen einer professionellen IT-forensischen Untersuchung werden CSC-Artefakte stets gemeinsam mit Dateisystemspuren, Benutzerprofilen, Registry-Daten und Ereignisprotokollen ausgewertet. Erst die Gesamtschau ermöglicht eine belastbare technische Bewertung.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of the client-side cache (CSC), reconstruction of synchronisation processes, evaluation of cached network files, correlation with other Windows artefacts, and comprehensive documentation of all investigative steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, any existing CSC artefacts are identified, analysed and correlated with other digital traces in terms of both timing and technical characteristics.
Warum sind Offline Files wichtig?
Even if files were stored on a Server, local offline copies and metadata can provide valuable insights into their use.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne supports you in carrying out legally admissible analyses of Windows Offline Files and in the objective assessment of complex IT forensic issues.