IT Forensics – Windows
Forensic analysis of the Windows Reliability Monitor – tracking system changes and errors chronologically
The Windows Reliability Monitor (Reliability History) records a wide range of events relating to a system’s stability. These include programme crashes, Windows Updates, driver installations, software installations and various system errors.
As part of a professional IT forensic investigation, this information often provides a valuable supplement to event logs, prefetch files, registry artefacts and other pieces of evidence. Only by correlating all artefacts is it possible to carry out a robust technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of reliability trends, correlation with Windows event logs, registry data, software installations and other artefacts, as well as full documentation of all investigation steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, the relevant data from the reliability history is analysed and organised chronologically alongside other digital traces.
Why is the Reliability Monitor important?
It enables the chronological reconstruction of numerous system events and helps to categorise crashes, installations and security-related changes.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne helps you carry out a legally admissible analysis of the Windows reliability history and objectively reconstruct technical events.
Related to this topic
- Forensic analysis of the Windows Notification Database – notifications as digital evidence
- Forensic analysis of the Windows clipboard history – clipboard contents as a digital trail of evidence
- Forensic analysis of the Windows Activity Cache – reconstructing user activities
- Forensic analysis of the Windows font cache – clues regarding document and programme usage