IT Forensics – Windows

Forensic analysis of Windows RAM dumps – Securing ephemeral evidence from main memory

Ein Speicherabbild (RAM-Dump) enthält den Inhalt des Arbeitsspeichers zu einem bestimmten Zeitpunkt. Darin können sich laufende Prozesse, aktive Netzwerkverbindungen, entschlüsselte Daten, geladene Module, Malware-Komponenten sowie zahlreiche weitere flüchtige Informationen befinden.

Enquire without obligation

Die Auswertung eines RAM-Dumps erfolgt stets im Zusammenhang mit weiteren digitalen Spuren wie Dateisystemartefakten, Ereignisprotokollen, Registry-Daten und Speicherdateien. Erst die Gesamtauswertung ermöglicht eine fundierte technische Bewertung.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of RAM dumps, reconstruction of running processes and network connections, investigation of potential malware artefacts, correlation with other Windows artefacts, and full documentation of all investigation steps.

Typical areas of application

Incident Response
Ransomware analyses
Malware and rootkit investigations
Analysis of attack chains
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Once the RAM has been securely backed up, the memory dump is analysed using specialised forensic tools and correlated with other artefacts in terms of both timing and technical characteristics.

Warum sind RAM-Dumps wichtig?

Much of this information exists solely in volatile RAM and is lost after a reboot. For this reason, memory dumps often form a key part of a comprehensive IT forensic investigation.

Frequently Asked Questions

Welche Informationen enthält ein RAM-Dump?+
Unter anderem laufende Prozesse, Netzwerkverbindungen, Speicherobjekte, geladene Module und je nach Situation weitere flüchtige Daten.
Kann Malware im Arbeitsspeicher erkannt werden?+
In vielen Fällen können Speicheranalysen wertvolle Hinweise liefern. Das Ergebnis hängt jedoch vom Einzelfall ab.
Wird der Originaldatenträger analysiert?+
Nein. Die Auswertung erfolgt ausschließlich auf den beweissicher gesicherten forensischen Daten.
Reicht ein RAM-Dump allein für ein Gutachten aus?+
Nein. Er wird stets gemeinsam mit weiteren digitalen Spuren bewertet.

🔗 Related topics

LanCologne – Windows Forensics in Cologne

LanCologne supports you in the evidence-secure backup and legally admissible analysis of Windows memory images, as well as complex IT forensic investigations.

Get in touch now