IT Forensics · Linux

Forensic analysis of the inode structure – using metadata as a key forensic source

Inodes store key metadata about a file, including its size, permissions, owner, and timestamps for access, modification and status changes. The file name itself, however, is stored in the relevant directory entry, not in the inode.

Enquire without obligation

This distinction between an inode and a directory entry is significant from a forensic perspective, as several directory entries may point to the same inode (hard links) and inodes may initially remain even after a directory entry has been removed.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We systematically analyse inode metadata, reconstruct time-stamp-consistent sequences of events, and map inode information even when the associated directory entries no longer exist.

Typical areas of application

Reconstruction of access and modification times
Analysis of hard-link structures
Allocation of orphaned inodes without a directory entry
Investigation of authorisation and ownership histories
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an inode analysis works

Following the backup, relevant inode metadata is systematically extracted and cross-referenced with the corresponding directory entries. Orphaned inodes without a current directory entry are examined separately in order to reconstruct any previous associations.

Why is inode analysis relevant in a forensic context?

Inode metadata provides precise timestamp and permission information, which is essential for reconstructing the chronology of system events. It often forms the basis for further forensic conclusions.

However, interpreting timestamps requires knowledge of the relevant mount options and kernel configuration, as these can affect how individual timestamps are updated. This is taken into account in every analysis.

Frequently Asked Questions

What timestamps does an inode contain?+
Typically, the access time (atime), the last modification time of the content (mtime) and the last status change time of the metadata (ctime), depending on the file system and configuration.
Where is the file name saved?+
The file name is stored in the directory entry, not in the inode itself. An inode can be referenced by several directory entries.
What is an orphaned inode?+
An inode whose associated directory entry has been removed, but whose data content may not yet have been overwritten.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of the inode structure"? LanCologne can assist you with the legally admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now