IT Forensics · Linux

Forensic analysis of encrypted LVM volumes – handling LUKS and LVM correctly in combination

In many enterprise environments, LUKS encryption is combined with the Logical Volume Manager, either by encrypting the physical storage devices at a level prior to the LVM layer or by encrypting individual logical volumes.

Enquire without obligation

During a forensic analysis, this combination requires the layers to be peeled back in the correct order: the LUKS layer must first be unlocked before the LVM structure beneath or above it can be properly analysed.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We determine the specific layering from LUKS and LVM, decrypt the data if a valid access path is available, and then reconstruct the logical volumes for further file system analysis.

Typical areas of application

Investigation of encrypted corporate servers
Reconstruction of complex encryption and volume layouts
Assessment of existing unlocking paths prior to analysis
Preparing the file system analysis on decrypted volumes
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how the analysis of encrypted LVM volumes works

Once the backup has been completed, the specific layering of LUKS and LVM is first determined. If a valid unlock path is available, the encryption is unlocked and the underlying or overlying LVM structure is reconstructed. Only then does the actual file system analysis of the affected logical volumes take place.

Why is this combined analysis relevant from a forensic perspective?

The combination of encryption and logical volume management is widely used in professional environments and requires a precise understanding of the order of the layers involved, so as not to mistakenly classify data as inaccessible.

If the stratification is not correctly identified, an investigation may be terminated prematurely, even though a valid access route would, in principle, have existed. A thorough preliminary technical analysis is therefore crucial.

Frequently Asked Questions

Which is unmounted first, LUKS or LVM?+
That depends on the specific configuration. LUKS is often set up beneath LVM, but other combinations are also possible.
Can any data still be analysed without LUKS access?+
Generally speaking, no, as the actual data cannot be accessed without successful decryption.
Is this combination common in companies?+
Yes, particularly in the case of Servern, which has enhanced security requirements, encryption is often combined with flexible volume management.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of encrypted LVM volumes"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now