IT Forensics – Windows
Forensic analysis of Windows Volume Shadow Copies – Tracing previous file states and system information
Depending on the system configuration and usage, Windows creates what are known as volume shadow copies. These shadow copies may contain earlier versions of files and directories and, in many cases, provide valuable clues for reconstructing digital events.
As part of a professional IT forensic investigation, existing shadow copies are analysed in a structured manner and correlated with other Windows artefacts. Only a comprehensive analysis enables a reliable technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
Analysis of existing Volume Shadow Copies, comparison of historical file versions, reconstruction of deleted or altered information, correlation with registry, file system and event logs, and comprehensive documentation of all investigation steps.
Typical areas of application
This is how the analysis works
Once a forensic image has been created, any existing shadow copies are identified and analysed. The findings are then technically assessed alongside other digital evidence.
Why are Volume Shadow Copies important?
They can document previous states of files and system areas, thereby assisting in the chronological reconstruction of events. However, their evidential value only arises from the overall assessment of all relevant artefacts.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of Windows Volume Shadow Copies or other Windows artefacts? LanCologne can assist you with the forensically sound preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic analysis of the Windows Search database – Tracing indexed files and search information
- Forensic analysis of the Windows Search Index – Tracing indexed data and file references
- Forensic analysis of Windows Error Reporting (WER) – investigating programme crashes and system errors
- Forensic analysis of Windows crash dumps – Technical reconstruction of system crashes