IT Forensics – Windows

Forensic analysis of Windows user profiles – tracing user activities

Windows creates a separate profile for each user, containing individual settings, documents and application data. These profiles contain numerous artefacts relevant to forensic analysis, from which it is possible to reconstruct user activities, log-in processes, configurations and the use of installed applications.

Enquire without obligation

A reliable assessment is never based on individual files. Only by correlating these with registry hives, event logs, file system artefacts and other digital traces is it possible to arrive at a well-founded technical assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and provide support to businesses, solicitors, private individuals and, on a regular basis, the courts.

The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.

Our services

Analysis of user profiles, AppData directories, NTUSER.DAT and USRCLASS.DAT artefacts, chronological reconstruction of user activities, and comprehensive documentation of all investigation steps.

Typical areas of application

Reconstruction of user actions
Incident Response
Insider investigations
Employment law proceedings
Corporate Forensics
Expert reports for the courts

This is how the analysis works

Once a forensic image has been created, all relevant user profiles are identified and analysed alongside other Windows artefacts.

Why are user profiles important?

They contain a wealth of information about an individual’s use of a system and therefore form a key part of many IT forensic investigations.

Frequently Asked Questions

What data is contained in a user profile?+
These include, amongst other things, personal settings, application data, document references and other user-specific items.
Are deleted user profiles also examined?+
Where technically possible, deleted or partially preserved traces are also taken into account.
Are you working on the original system?+
No. Only a forensic copy or forensic image is analysed.
Is a user profile alone sufficient for an expert report?+
No. It is always assessed in conjunction with other digital evidence.

LanCologne – Windows Forensics in Cologne

LanCologne supports you in carrying out legally admissible analyses of Windows user profiles and in the objective assessment of complex IT forensic issues.

Get in touch now