IT Forensics – Windows
Forensic analysis of Windows Performance Monitor and Performance Logs – Understanding system states
The Windows Performance Monitor can collect performance data on the processor, RAM, storage devices, network and numerous other system components. Depending on the configuration, this generates performance logs that can provide insights into system utilisation and technical events.
As part of a professional IT forensic investigation, this data is never examined in isolation. Only by correlating it with event logs, ETL files, registry artefacts, Sysmon logs and other digital traces is it possible to carry out a robust technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of existing performance logs, reconstruction of system states over time, evaluation of performance data, and comprehensive documentation of all investigative steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, existing performance logs are analysed and technically assessed alongside other Windows artefacts.
Why are performance logs important?
They can provide an indication of a system’s workload and technical condition at specific points in time. However, their significance only becomes apparent through a comprehensive analysis of all relevant artefacts.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows performance logs or other Windows artefacts? LanCologne can assist you with the collection of digital evidence that meets legal standards, as well as the objective analysis of complex Windows systems.
Related to this topic
- Forensic analysis of Windows Live Response artefacts – Backing up transient system information
- Forensic analysis of the Windows Print Spooler – Technical investigation of print jobs
- Forensic analysis of Windows event logs – evaluating system events in a traceable manner
- Forensic Analysis of Windows Services – Investigating Persistence and System Configuration