IT Forensics – Windows
Forensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system events
Sysmon (System Monitor) from Microsoft Sysinternals extends Windows event logging to include detailed information on processes, network connections, driver loads, file creation and other security-related events. Provided that Sysmon has been installed and configured on a system, these logs can serve as a valuable basis for reconstructing digital events.
A professional analysis is never carried out in isolation. Only by correlating the findings with event logs, registry artefacts, prefetch files, file system artefacts and other digital traces is it possible to arrive at a reliable technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of Sysmon events, reconstruction of process chains, analysis of network connections and file access, correlation with other Windows artefacts, and full documentation of all investigation steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, existing Sysmon logs are analysed and technically correlated with other relevant artefacts.
Why are Sysmon artefacts important?
Provided that Sysmon was active, they provide significantly more detailed information than standard Windows logging and can therefore be of considerable assistance in reconstructing complex incidents.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows Sysmon artefacts? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic Analysis of Windows ETL Logs – Tracing Detailed System Events
- Forensic analysis of Windows Performance Monitor and Performance Logs – Understanding system states
- Forensic analysis of Windows Live Response artefacts – Backing up transient system information
- Forensic analysis of the Windows Print Spooler – Technical investigation of print jobs