IT Forensics · Linux
Forensic analysis of KVM/QEMU virtualisation – Forensic examination of virtual machines running on Linux
KVM, in conjunction with QEMU, is the most widely used native virtualisation solution on Linux and enables the operation of complete virtual machines with their own virtual hard disks, which are usually stored as files.
Both the configuration of the virtual machine and its virtual hard disks, as well as any snapshots that may exist, constitute separate subjects of forensic investigation.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We back up and analyse KVM/QEMU configurations, virtual hard disk images and existing snapshots, and, where necessary, carry out a full forensic examination of the virtual systems they contain.
Typical areas of application
How a KVM/QEMU analysis works
Once the configuration files and virtual hard disk images have been backed up, they are mounted for forensic analysis, where necessary, and examined as if they were standalone systems. Any existing snapshots are analysed separately to determine previous system states.
Why is KVM/QEMU analysis relevant in a forensic context?
Virtual machines, just like physical systems, can be the target or starting point of an attack, and their configuration and existing snapshots can provide additional forensic clues that do not exist on physical systems.
In particular, unauthorised or concealed virtual machines on a virtualisation host may indicate misuse of the infrastructure and are therefore specifically targeted for detection.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of KVM/QEMU virtualisation"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of VMware on Linux – Investigating VMware virtualisation environments on Linux
- Forensic analysis of VirtualBox on Linux – Forensic examination of VirtualBox environments on Linux
- Forensic analysis of Cloud Init configuration – Forensic investigation of automated system initialisation
- Forensic backup of AWS EC2 Linux instances – Backing up and analysing cloud instances in a forensically traceable manner