IT Forensics · Linux

Using checksums and integrity mechanisms in a forensic context – cryptographically verifying file integrity

Cryptographic checksums and more advanced integrity mechanisms make it possible to verify that a file or a complete disk image has remained unchanged since a specific point in time.

Enquire without obligation

This verification is of crucial importance for forensic evidence, as only an image that can be proven to be unaltered can serve as a reliable basis for further investigative steps.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We generate and verify cryptographic checksums during the backup process and throughout the subsequent investigation, thereby ensuring that the integrity of all evidence can be verified without exception.

Typical areas of application

Proof that secured data carrier images have not been altered
Verification of the integrity of individual files relevant to the investigation
Detection of system files that have been tampered with retrospectively
Documentation of the chain of custody for court proceedings
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a checksum-based integrity check works

Immediately after the forensic backup has been completed, cryptographic checksums of the entire image are generated and documented. As the investigation progresses, these checksums are repeatedly verified to demonstrate that the data used as the basis for the investigation has remained unaltered throughout.

Why are checksums relevant in a forensic context?

Without reliable evidence that a piece of evidence has remained unchanged, its admissibility in court may, in principle, be called into question; this is why the consistent generation of checksums is a fundamental part of proper forensic work.

Even within a system under investigation, checksums can be used to determine whether certain system files have been altered from a known, trusted state.

Frequently Asked Questions

Which checksum methods are used?+
Commonly used cryptographic hash functions that enable a reliable and, in practice, collision-resistant integrity check.
When are checksums first generated?+
Immediately following the forensic backup, before the actual analysis begins.
Can it also detect individual tampered system files?+
Yes, by comparing them with known, trusted reference checksums, altered files can be specifically identified.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into the „forensic use of checksums and integrity mechanisms"? LanCologne can assist you with the court-admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now