IT Forensics · Linux

Forensic recovery of deleted files on ext4 – possibilities and limitations of reconstruction

When a file is deleted on an ext4 filesystem, usually only the corresponding directory entry and inode reference are removed initially, whilst the actual data blocks may remain intact until they are overwritten. This, in principle, opens up possibilities for forensic reconstruction.

Enquire without obligation

However, the actual chances of success depend on numerous factors, including the time that has elapsed since the deletion, the system’s write activity, the journal mode, and the possible use of SSD TRIM.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse inode remnants, journal entries and data blocks that have not been overwritten in order to reconstruct deleted files to the greatest extent technically possible, whilst transparently documenting any existing limitations.

Typical areas of application

Recovery of accidentally deleted business data
Investigation into deliberate attempts to extinguish a fire prior to the preservation of evidence
Reconstruction of deleted log and configuration files
Support with incident response investigations
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how the recovery of deleted ext4 files works

Once the backup has been completed, the system first checks whether any relevant remnants of inodes and journals are still present. It then identifies data blocks that have not been overwritten and, where possible, assigns them to the original files. The success of this process is always assessed in the context of SSD TRIM, journal configuration and the time elapsed.

Why is recovery relevant to forensic analysis?

Deleted files may contain crucial evidence, particularly if they were deliberately deleted to conceal information. Recovering them is therefore a key part of many forensic investigations.

No one can reasonably guarantee success until the storage medium has been technically examined. In the case of SSDs with TRIM enabled in particular, deleted data may be irretrievably lost even after a short period of time.

Frequently Asked Questions

Can deleted files on ext4 always be recovered?+
No. The options depend on the journal configuration, write activity, SSD TRIM and the time that has elapsed since deletion.
What happens technically when a file is deleted on an ext4 filesystem?+
As a rule, the directory entry and inode reference are removed first, whilst the data blocks may remain intact until they are overwritten.
Does SSD TRIM reduce the chances of success?+
Yes, TRIM can result in data blocks marked as deleted being physically erased in a timely manner, which makes recovery more difficult or prevents it altogether.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic recovery of deleted files on ext4"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now