WINDOWS FORENSICS

Forensic analysis of the NTFS file system – The foundation of virtually every Windows investigation

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination of NTFS file systems is carried out exclusively on a forensic copy or a forensic image. The original evidence remains untouched and is stored in a manner that preserves its evidential integrity.

Forensic analysis
Documentation admissible in court
GDPR-compliant processing
Experienced experts

TECHNICAL BACKGROUND

Technical Fundamentals

The NTFS file system contains a wealth of metadata that extends far beyond the visible file contents. This often reveals technical relationships that remain hidden when viewed in the conventional manner. A professional analysis is therefore an essential part of almost every Windows forensic investigation.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Once a forensic image has been created, the relevant NTFS structures are analysed. The information obtained is cross-referenced with other Windows artefacts such as the registry, event logs and USB traces. Only a comprehensive analysis enables reliable technical conclusions to be drawn. All stages of the investigation are documented in a transparent manner.

TYPICAL QUESTIONS

When is this analysis required?

  • Suspected data deletion
  • Data theft
  • Allegations of manipulation
  • Reconstruction of file movements
  • Examination of external data storage media
  • Support for legal proceedings
  • Reports for private individuals and businesses

LIMITATIONS & CONCLUSION

What you should know

Among other things, we analyse the Master File Table (MFT), file attributes, timestamps, directory structures, deleted entries, file associations and other NTFS metadata. The aim is to objectively reconstruct technical processes on the basis of verifiable artefacts.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you need a professional analysis of a Windows system or an NTFS file system? LanCologne can assist you with the forensically sound preservation of digital evidence and the traceable analysis of relevant file system artefacts.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Do you have any further questions?
Please contact us for a free initial consultation.