IT Forensics · Linux
Forensic analysis of immutable flags and chattr attributes – Evaluating advanced file system protection attributes
The `chattr` tool can be used on certain Linux file systems to set extended attributes which, for example, make a file immutable or allow only appending, regardless of the standard access rights.
Such attributes can be used legitimately to protect important system files, but they can also be exploited by an attacker – for example, to protect their own modifications from being removed at a later date by the actual system owner.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We examine relevant files and directories for any extended attributes that have been set and contextualise their presence within the forensic investigation, including an assessment of any potential misuse.
Typical areas of application
This is how a chattr attribute analysis works
Once the backup has been completed, relevant files and directories are systematically checked for any set extended attributes. Suspicious findings are evaluated in the context of other system artefacts in order to distinguish between legitimate system hardening and malicious use.
Why is the chattr attribute analysis relevant in a forensic context?
An attacker can make targeted use of extended attributes to permanently secure their own manipulations or to make it more difficult for the system administrator to detect and remove them at a later date.
Conversely, such attributes may also have been legitimately used to harden critical system files, which is why any such finding must be carefully assessed within the specific system context.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of immutable flags and chattr attributes"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.