IT Forensics – Windows
Forensic analysis of the Windows swapfile.sys – Evaluating additional memory artefacts
Neben der pagefile.sys und der hiberfil.sys verwendet Windows auf modernen Systemen zusätzlich die Datei swapfile.sys. Sie dient insbesondere der Verwaltung bestimmter Speicherbereiche moderner Windows-Anwendungen und kann – abhängig von Systemzustand und Nutzung – weitere forensisch relevante Informationen enthalten.
Im Rahmen einer professionellen IT-forensischen Untersuchung wird die swapfile.sys niemals isoliert betrachtet. Erst die gemeinsame Auswertung mit Arbeitsspeicherabbildern, pagefile.sys, hiberfil.sys, Registry-Daten und weiteren Windows-Artefakten ermöglicht eine fundierte technische Bewertung.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of swapfile.sys, correlation with other memory artefacts, reconstruction of technical relationships, and comprehensive documentation of all investigative steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, the swapfile.sys is identified and analysed alongside other memory and file system artefacts.
Warum ist die swapfile.sys wichtig?
It may contain supplementary information that is not present, or is no longer present in full, in other archival artefacts. However, its significance only becomes apparent when evaluated as part of the overall analysis.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
LanCologne supports you in the legally admissible analysis of Windows memory artefacts and complex IT forensic investigations.