IT Forensics · Linux
Detecting log manipulation and anti-forensics – uncovering evidence tampering on Linux systems
Experienced attackers often deliberately attempt to cover their tracks by deleting or altering log files, as well as by using other anti-forensic techniques, in order to make a subsequent investigation more difficult or to thwart it altogether.
However, such attempts at manipulation often leave their own indirect traces, such as gaps in otherwise complete log series or inconsistencies between different, independent data sources.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We systematically examine systems for evidence of log tampering and other anti-forensic techniques, cross-check available data sources and document any detected attempts at tampering in a traceable manner.
Typical areas of application
This is how an anti-forensics investigation is carried out
Once the backup has been completed, the available log files are checked for completeness and for any indications of subsequent alterations. In addition, independent data sources such as the central Log-Server or file system metadata are cross-checked to detect any covert manipulation.
Why is anti-forensics analysis relevant to forensics?
The detection of deliberate attempts to cover one’s tracks is often in itself a strong indication of a deliberate, targeted compromise and can provide further insights into an attacker’s modus operandi and level of expertise.
As tampered logs are no longer entirely reliable when used as the sole basis of evidence, cross-checking against independent data sources is essential for reaching a sound forensic conclusion.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „detecting log manipulation and anti-forensics"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.
Related to this topic
- Forensic backup of volatile memory (RAM) under Linux – Capturing transient data from a running system
- Detecting web shells on Linux-Servern – Forensically identifying malicious Server scripts
- Detecting cryptomining malware on Linux systems – providing forensic evidence of unauthorised resource usage
- Forensic reconstruction of reverse shells – Forensic detection of outbound remote access by attackers