IT Forensics · Linux
Forensic classification of deleted files on Btrfs and XFS – specifically taking into account the differences compared to ext4
Btrfs and XFS differ significantly from ext4 in terms of their deletion and allocation behaviour. Whilst Btrfs, through copy-on-write, may offer additional recovery options via snapshots, XFS tends to reuse freed space more quickly.
Applying ext4-specific expectations across the board to Btrfs or XFS therefore often leads to incorrect assessments of the prospects of success. Each file system requires a separate technical assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
For each file system in question, we assess on a case-by-case basis which recovery methods are available – such as via Btrfs snapshots, copy-on-write remnants or remaining XFS metadata fragments – and document the respective limitations transparently.
Typical areas of application
This is how deleted data is handled on Btrfs and XFS
Once the backup has been completed, the specific file system is first identified. For Btrfs, the system checks whether any usable snapshots or copy-on-write remnants are present. For XFS, it examines the extent to which metadata and data blocks have not yet been reused. The respective results are documented in a transparent manner.
Why is this file system-specific classification important?
Customers often expect that deleted files can be recovered in the same way, regardless of the file system used. This assumption is not technically correct and can lead to false expectations.
A realistic, file-system-specific assessment is essential for providing sound advice and prevents unnecessary effort being wasted on reconstruction attempts that are technically unfeasible.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic classification of deleted files on Btrfs and XFS"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of encrypted LVM volumes – handling LUKS and LVM correctly in combination
- Forensic acquisition of encrypted LUKS volumes
- Forensic analysis of the ext4 file system – the basis for most Linux investigations
- Forensic analysis of the ext4 journal – reconstructing write operations and system states