IT Forensics · Linux

Forensic analysis of KVM/QEMU virtualisation – Forensic examination of virtual machines running on Linux

KVM, in conjunction with QEMU, is the most widely used native virtualisation solution on Linux and enables the operation of complete virtual machines with their own virtual hard disks, which are usually stored as files.

Enquire without obligation

Both the configuration of the virtual machine and its virtual hard disks, as well as any snapshots that may exist, constitute separate subjects of forensic investigation.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up and analyse KVM/QEMU configurations, virtual hard disk images and existing snapshots, and, where necessary, carry out a full forensic examination of the virtual systems they contain.

Typical areas of application

Forensic backup and analysis of virtual machines
Investigation of compromised virtualisation environments
Analysis of existing snapshots to reconstruct historical system states
Evidence of unauthorised virtual machines
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How a KVM/QEMU analysis works

Once the configuration files and virtual hard disk images have been backed up, they are mounted for forensic analysis, where necessary, and examined as if they were standalone systems. Any existing snapshots are analysed separately to determine previous system states.

Why is KVM/QEMU analysis relevant in a forensic context?

Virtual machines, just like physical systems, can be the target or starting point of an attack, and their configuration and existing snapshots can provide additional forensic clues that do not exist on physical systems.

In particular, unauthorised or concealed virtual machines on a virtualisation host may indicate misuse of the infrastructure and are therefore specifically targeted for detection.

Frequently Asked Questions

How are virtual hard disk images incorporated into a forensic analysis?+
Through specialised, read-only embedding methods that enable analysis without altering the original image.
Can snapshots fully reconstruct previous system states?+
In many cases, yes, depending on the snapshot format used and when it was created.
Is it possible to carry out a live analysis of a running virtual machine?+
Yes, comparable to a live monitoring of a physical system, whilst taking into account the specific characteristics of virtualisation.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of KVM/QEMU virtualisation"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now