IT Forensics · Linux

Forensic analysis of LVM snapshots – Evaluating historical volume states

LVM snapshots preserve the state of a logical volume at a specific point in time and are often created prior to system changes, Updates or backups. They are based on a mechanism similar to copy-on-write.

Enquire without obligation

As an LVM snapshot only stores separately those data blocks that have been modified since it was created, its available storage space is limited and may become invalid once this space is exhausted. This must be taken into account when conducting a forensic assessment of availability and completeness.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We identify existing LVM snapshots or those referenced in metadata, check their validity and analyse the historical data states they contain in comparison with the current logical volume.

Typical areas of application

Reconstruction of previous system states prior to Updates
Investigation of automated backup snapshots
Comparison of data sets before and after system changes
Assessment of snapshot capacity and validity
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an LVM snapshot analysis works

After the backup, any existing LVM snapshots are identified and checked for validity, as an exhausted snapshot may become invalid. The data blocks they contain are then compared with the current logical volume in order to document any changes precisely.

Why is LVM snapshot analysis relevant in a forensic context?

A snapshot taken prior to a critical system change can preserve the state of the system immediately before an incident, thereby providing a valuable forensic reference point.

As LVM snapshots may become invalid when storage space is limited, their availability cannot be guaranteed. Their actual usability is therefore assessed on a case-by-case basis.

Frequently Asked Questions

How does an LVM snapshot work from a technical point of view?+
When it is created, it initially stores only a reference to the original and subsequently retains only those data blocks that have been modified since its creation.
Can an LVM snapshot become invalid?+
Yes, if the storage space reserved for changes is exhausted, the snapshot may become invalid and unusable.
Are LVM snapshots created by default?+
No, they must be created in a targeted manner, for example manually or via automated backup and Update processes.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of LVM snapshots"? LanCologne can assist you with the court-admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now