IT Forensics · Linux
Forensic analysis of LVM – Correctly classifying logical volumes
The Logical Volume Manager (LVM) abstracts physical storage devices into flexible logical volumes and is used for storage management on numerous Linux Servern and Workstation systems. Volume groups combine several physical volumes, from which logical volumes are created.
For forensic analysis, it is crucial to correctly reconstruct the actual mapping between physical storage devices, volume groups and logical volumes before the actual file system analysis begins. An incorrect mapping can lead to an incomplete or inaccurate analysis.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We reconstruct the LVM structure from volume group and logical volume metadata, correctly map the associated physical storage devices, and prepare the logical volumes for subsequent file system analysis.
Typical areas of application
This is how an LVM forensic investigation is carried out
Once all the physical storage media involved have been backed up, the LVM metadata structure is first analysed in order to correctly reconstruct the volume groups and logical volumes. The logical volumes are then made available for further file system analysis without altering the original image.
Why is LVM analysis relevant in a forensic context?
Many Linux Server systems use LVM for flexible storage management, which allows data to be distributed across multiple physical storage devices. Correct reconstruction of the LVM structure is essential for a comprehensive file system analysis.
If the LVM structure is not reconstructed correctly, parts of the data set may be overlooked during the analysis. For this reason, the volume mapping is carefully checked before any further investigation.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of LVM"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of LVM snapshots – Evaluating historical volume states
- Forensic analysis of software RAID (mdadm) – correctly reconstructing arrays
- Classifying LUKS encryption in a forensic context – Correctly assessing encrypted Linux volumes
- Forensic analysis of a swap partition – analysing the contents of the swap file