LANCOLOGNE IT-FORENSIK

Alle Forensik-Leistungen im Überblick

Professionelle IT-Forensik für Mobile Geräte und Windows-Systeme – gerichtsverwertbar, DSGVO-konform, erfahren.

136
Mobile forensics
100
Windows Forensik

MOBILE FORENSICS

Mobile forensics

136 spezialisierte Leistungen rund um Smartphones & Tablets

ADB (Android Debug Bridge) in IT forensicsAirDrop artefactsAndroid Keystore and Security ArchitectureAndroid Verified Boot (AVB)Forensic analysis of Android app permissionsForensic analysis of Android backup artefactsAndroid Backups – Options and LimitationsForensic analysis of Android notificationsForensic analysis of Android Bluetooth artefactsForensic analysis of Android call logsForensic analysis of Android cloud synchronisationForensic analysis of Android crash dumps and tombstonesForensic analysis of Android file managers and downloadsForensic analysis of Android file system artefactsAndroid email forensicsAndroid eSIM ForensicsAndroid Forensics – Professional analysis of digital evidence on Android devicesForensic analysis of Android device logs (events and system logs)Forensic analysis of the Android calendarForensic analysis of Android contactsForensic analysis of Android NFC artefactsAndroid-SIM-Karten-Artefakte forensisch analysierenForensic analysis of Android SMS and MMS messagesForensic analysis of Android location dataForensic analysis of Android system settingsAndroid system logs and LogcatAndroid Timeline and Event ReconstructionAndroid Trojans, banking malware and RATsAndroid-USB- und OTG-Artefakte forensisch analysierenForensic analysis of Android-WLAN artefactsForensic analysis of Android timestamps and time zonesDetecting anti-forensics on AndroidAPFS – Apple’s file systemApple Data Protection and data protection mechanismsApple Health (HealthKit) – IT forensic investigationApple Maps artefactsApple ID, synchronisation and device pairingVerification of the authenticity of digital evidenceThe evidential value of digital artefactsPreservation of evidence from smartphonesCellebrite in mobile forensicsCellebrite in der Mobilforensik – Professionelle Datensicherung und Analyse digitaler BeweismittelChain of Custody for SmartphonesProving chat manipulationDetecting chat manipulation – Objective IT forensic analysis of digital communicationsCustom Recovery (TWRP & Co.) aus Sicht der Android-ForensikCustom-ROMs aus Sicht der Android-ForensikThe Android file system explained in simple termsThe iOS file system explained in simple termsHave digital metadata professionally analysedAdvanced logical extraction from a smartphoneForensic analysis of EXIF metadata in imagesForensic analysis of Facebook Messenger on AndroidFaceTime artefactsFastboot and bootloaderFile-Based Encryption (FBE) and Full Disk Encryption (FDE)Full File System (FFS) in mobile IT forensicsCounter-assessment / Plausibility checkRecovering deleted data on AndroidMobile phone expert reports admissible in courtForensic analysis of Google Chrome on AndroidForensic analysis of Google Photos on AndroidForensic analysis of Google Maps on AndroidGoogle Account and Google Cloud artefactsLimitations and uncertainties in IT forensic reportsExpert reports for courts and public prosecutors’ officesExpert reports for solicitorsFrequently asked questions about costs, remuneration and invoicingiCloud forensics and Apple cloud dataiMessage forensicsConduct a forensic analysis of installed appsForensic analysis of installed apps (Android)iOS logs and system logsiPhone Backups – Options and LimitationsiPhone Forensics – Admissible analysis of digital evidence on Apple devicesIT-forensische Malware-Gutachten für SmartphonesForensic analysis of iTunes and Finder backupsJailbreaking in iPhone forensicsJailbreaking in iPhone forensicsCosts of an IT forensic investigationCosts of an IT forensic reportLogical extraction of a smartphoneMalware Indicators (IoCs), MVT and YARAChecking Messenger messages for tamperingMessenger forensics – Analysis of digital communications on smartphones and tabletsMetadaten in der mobilen Forensik – was digitale Begleitspuren verraten könnenMetadata in mobile forensicsMobile artefacts – call logs in IT forensicsMobile artefacts – App usage in IT forensicsMobile artefacts – Notifications in IT forensicsMobile Devices – Screen Time in IT ForensicsMobile devices – Bluetooth devices in IT forensicsMobile artefacts – browser artefacts in IT forensicsMobile artefacts – files in IT forensicsMobile devices – Downloads in IT forensicsMobile Artefacts – EXIF Metadata in IT ForensicsMobile artefacts – photographs in IT forensicsMobile artefacts – calendars in IT forensicsMobile Artefacts – Contacts in IT ForensicsMobile Artefacts – MMS in IT ForensicsMobile Artefacts – Notes on IT ForensicsMobile Artefakte – SMS in der IT-ForensikMobile artefacts – location data in IT forensicsMobile Artefakte – Videos in der IT-ForensikMobile artefacts – WLAN artefacts in IT forensicsMobile artefacts – The clipboard in IT forensicsMobile malware analysis – scanning smartphones for malware and digital anomaliesEvidence of deleted dataPackage deals for private individuals, businesses and solicitorsPhysical removal of a smartphonePrivate report on smartphonesRoot in Android forensicsRoot in Android forensicsRooting from the perspective of Android forensicsExpert reports in accordance with recognised forensic standardsSafari artefactsForensic analysis of Samsung Gallery on AndroidSecure Enclave – Security in the iPhoneConducting a forensic analysis of Signal Messenger on AndroidSignal-Forensik – Analyse verschlüsselter Kommunikation auf SmartphonesDetecting spyware on smartphonesSQLite Forensics – When digital traces are stored in databasesGovernment-sponsored malware (e.g. Pegasus) – the scope and limitations of investigationsStalkerware on smartphonesTechnical documentation and reproducibilityForensic analysis of Telegram on AndroidTelegram Forensics – Forensic Analysis of Telegram CommunicationsForensic analysis of Threema on AndroidFees in accordance with the JVEG and individual fee agreementsWAL and SHM Analysis – Unassuming files of great significance to IT forensicsWAL and SHM analysis in IT forensicsWhy different tools in mobile IT forensics produce different resultsForensic analysis of WhatsApp on AndroidWhatsApp Forensics – Analysis of chat histories and digital evidenceTimeline analysisTimestamps and metadata on Android

WINDOWS FORENSICS

Windows Forensik

100 spezialisierte Leistungen rund um Windows-Systeme

Forensic analysis of Amcache – evidence of programmes and system activityForensic analysis of scheduled tasks – Tracing automated processesForensic analysis of jump lists – Important insights into user activityForensic analysis of LNK files – reconstructing user activities in a traceable mannerForensic Analysis of the Master File Table (MFT) – The Heart of the NTFS File SystemForensic analysis of the NTFS file system – The foundation of virtually every Windows investigationProfessional Windows Forensics – Securing and analysing digital evidence to stand up in courtForensic analysis of ShellBags – reconstructing folder access and user activityForensic analysis of ShimCache (AppCompatCache) – evidence of applications that have been runForensic analysis of SRUM – Tracking system and network activityForensic analysis of the USN Journal – tracking changes on Windows systemsForensic analysis of Windows Active Directory artefacts – Technical investigation of domain activityForensic analysis of the Windows Activity Cache – reconstructing user activitiesForensic analysis of Windows antivirus and security software – technical assessment of security incidentsForensic analysis of Windows AppCompat artefacts – tracing programme executions and compatibilityForensic analysis of Windows AppData – analysing application and user dataForensic Analysis of Windows AppX Packages – Understanding Modern Windows ApplicationsForensic analysis of Windows autostart entries – identifying persistence mechanismsForensic analysis of the Windows BCD – Understanding boot configurationsForensic Analysis of Windows User Accounts (SAM) – Evaluating Local Accounts and Security InformationForensic analysis of Windows BitLocker artefacts – understanding encryption status and system informationForensic Analysis of Windows Bluetooth Artifacts – Tracing Paired Devices and ConnectionsForensic analysis of the Windows clipboard history – clipboard contents as a digital trail of evidenceForensic analysis of Windows COM artefacts – tracing components and system activitiesForensic Analysis of Windows COM+ – Tracing Distributed Components and ServicesForensic analysis of Windows crash dumps – Technical reconstruction of system crashesForensic analysis of Windows Credential Manager – Tracing stored login credentialsForensic analysis of Windows Defender Antivirus artefacts – tracing security eventsForensic analysis of Windows Defender Application Control (WDAC) – Understanding application policiesForensic analysis of Windows Defender artefacts – tracing security eventsForensic analysis of Windows Delivery Optimisation – tracing Update and transmission artefactsForensic analysis of the Windows Device Metadata Cache – evidence of detected hardwareForensic Analysis of Windows Services – Investigating Persistence and System ConfigurationForensic analysis of the Windows DNS cache – tracing network activityForensic analysis of Windows DNS client artefacts – tracing name resolutions and network activityForensic Analysis of Windows DPAPI – Tracing Protected User Data and KeysForensic analysis of Windows EDR artefacts – reconstructing security events and attack chainsForensic Analysis of Windows EFS – Examining Encrypted Files and CertificatesForensic analysis of Windows Error Reporting (WER) – investigating programme crashes and system errorsForensic Analysis of Windows ETL Logs – Tracing Detailed System EventsForensic analysis of Windows event logs – evaluating system events in a traceable mannerForensic analysis of Windows Firewall artefacts – tracing network communication and configuration changesForensic analysis of the Windows font cache – clues regarding document and programme usageForensic analysis of Windows Group Policy – Understanding system configurationsIn-depth forensic analysis of Windows’ hiberfil.sys – Reconstructing saved RAM contentsForensic analysis of the Windows hosts file – Tracing manual name resolutionsForensic Analysis of Windows Hyper-V Artefacts – Understanding Virtual InfrastructuresForensic analysis of Windows Live Response artefacts – Backing up transient system informationForensic analysis of Windows memory dumps – analysing volatile data from RAMForensic analysis of Windows Microsoft Defender for Endpoint (MDE) artefacts – tracing security eventsForensic analysis of Windows Microsoft Store artefacts – Tracing installed apps and updatesForensic analysis of Windows MountPoints2 artefacts – evidence of connected storage devicesForensic Analysis of Windows MSIX Packages – Understanding Modern Application InstallationsForensic analysis of Windows Nearby Sharing – Reconstructing local file transfersForensic analysis of Windows network adapters – understanding network interfaces and system configurationForensic analysis of Windows network profiles – tracing network connections and configurationsForensic analysis of the Windows Notification Database – notifications as digital evidenceForensic Analysis of Windows Offline Files (CSC) – Analysing Cached Network FilesForensic analysis of Windows OneDrive artefacts – Technical assessment of local cloud tracesIn-depth forensic analysis of the Windows pagefile.sys – Reconstructing paged-out memory contentsIn-depth forensic analysis of the Windows Recycle Bin ($Recycle.Bin) – tracing deletion processesForensic analysis of the Windows Recycle Bin – Tracing deleted filesForensic analysis of Windows Performance Monitor and Performance Logs – Understanding system statesForensic Analysis of Windows Portable Devices (WPD) – Mobile Devices as Digital EvidenceForensic Analysis of Windows PowerShell Artifacts – Tracing Commands and ActivitiesForensic analysis of Windows Prefetch files – identifying evidence of programme executionForensic analysis of the Windows Print Spooler – Technical investigation of print jobsForensic analysis of Windows proxy artefacts – Understanding proxy configurations and network communicationForensic analysis of Windows RAM dumps – Securing ephemeral evidence from main memoryForensic analysis of Windows RDP artefacts – tracing Remote Desktop connectionsForensic analysis of Windows ReadyBoot and ReadyBoost artefacts – tracing boot processes and system usageForensic Analysis of the Windows Registry – One of the most important sources of information in Windows forensicsForensic analysis of Windows Registry transaction logs – tracing changes to the RegistryForensic analysis of the Windows Reliability Monitor – tracking system changes and errors chronologicallyForensic Analysis of Windows Sandbox Artifacts – Tracing Temporary Execution EnvironmentsForensic analysis of the Windows Search database – Tracing indexed files and search informationForensic analysis of the Windows Search Index – Tracing indexed data and file referencesForensic analysis of the Windows SECURITY hive – understanding security configurationsForensic analysis of Windows Setup API logs – tracing device installationsForensic analysis of Windows security policies – Understanding security configurationsForensic Analysis of Windows SMB Artifacts – Tracing Network Shares and File AccessesForensic analysis of the Windows SOFTWARE hive – reconstructing software and system configurationsForensic analysis of the Windows swapfile.sys – Evaluating additional memory artefactsForensic analysis of Windows synchronisation artefacts – tracing synchronisation processesForensic analysis of Windows Sysmon artefacts – tracing processes, network connections and system eventsForensic analysis of the Windows SYSTEM hive – reconstructing system configurations and hardware informationForensic analysis of Windows TCP/IP configuration – Understanding network settingsForensic analysis of Windows temporary files – Temporary artefacts as digital evidenceForensic analysis of the Windows thumbnail cache – thumbnails as digital evidenceForensic analysis of Windows Timeline – tracing user activities chronologicallyForensic analysis of Windows Update artefacts – tracing installations and system changesForensic analysis of Windows USB artefacts – Tracing connected devicesForensic analysis of Windows Volume Shadow Copies – Tracing previous file states and system informationForensic analysis of Windows VPN artefacts – tracing VPN connections and configurationsForensic analysis of Windows WLAN artefacts – Tracing wireless network connectionsForensic analysis of Windows WMI – Understanding persistence mechanisms and system activitiesForensic analysis of the Windows certificate store – Tracing digital certificates and trust relationshipsForensic analysis of the Windows page file (pagefile.sys)Forensic analysis of Windows user profiles – tracing user activitiesForensic analysis of the Windows hibernation file (hiberfil.sys)

Enquire now – free initial consultation

Sie wissen nicht welche Forensik-Leistung Sie benötigen? Wir beraten Sie kostenlos und unverbindlich.