IT Forensics – Windows

Forensic analysis of Windows Update artefacts – tracing installations and system changes

Windows Updates regularly modify system files, drivers and security components. This results in various logs, databases and configuration artefacts that can provide insights into installed Updates, failed installations and the chronological sequence of system changes.

Enquire without obligation

As part of a professional IT forensic investigation, Windows Update artefacts are never assessed in isolation. Only by correlating them with event logs, registry artefacts, Delivery Optimisation, reliability history and other digital traces is it possible to arrive at a robust technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of the Windows Update history, evaluation of update-related logs and databases, chronological reconstruction of system changes, correlation with other Windows artefacts, and comprehensive documentation of all investigative steps.

Typical areas of application

Incident Response
Malware analysis
Investigation of system changes
Compliance audits
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, all relevant Update artefacts are identified, analysed and correlated with other digital evidence.

Why are Windows Update artefacts important?

They enable system changes to be dated and help to assess whether security-related Updates have been installed, have failed or have been subsequently modified.

Frequently Asked Questions

What information can be analysed?+
These include, amongst other things, Updatehistories, installation events, error logs and configuration data.
Can all Update transactions be traced?+
The scope depends on the artefacts available and the version of Windows.
Is the original system being examined?+
No. Only a forensic copy or forensic image is analysed.
Are Windows Update artefacts enough on their own?+
No. They are always assessed alongside other digital evidence.

LanCologne – Windows Forensics in Cologne

LanCologne supports you in carrying out legally admissible analysis of Windows-Update artefacts and the objective reconstruction of technical system events.

Get in touch now