IT Forensics · Linux
Forensic analysis of LVM snapshots – Evaluating historical volume states
LVM snapshots preserve the state of a logical volume at a specific point in time and are often created prior to system changes, Updates or backups. They are based on a mechanism similar to copy-on-write.
As an LVM snapshot only stores separately those data blocks that have been modified since it was created, its available storage space is limited and may become invalid once this space is exhausted. This must be taken into account when conducting a forensic assessment of availability and completeness.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We identify existing LVM snapshots or those referenced in metadata, check their validity and analyse the historical data states they contain in comparison with the current logical volume.
Typical areas of application
This is how an LVM snapshot analysis works
After the backup, any existing LVM snapshots are identified and checked for validity, as an exhausted snapshot may become invalid. The data blocks they contain are then compared with the current logical volume in order to document any changes precisely.
Why is LVM snapshot analysis relevant in a forensic context?
A snapshot taken prior to a critical system change can preserve the state of the system immediately before an incident, thereby providing a valuable forensic reference point.
As LVM snapshots may become invalid when storage space is limited, their availability cannot be guaranteed. Their actual usability is therefore assessed on a case-by-case basis.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of LVM snapshots"? LanCologne can assist you with the court-admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of software RAID (mdadm) – correctly reconstructing arrays
- Classifying LUKS encryption in a forensic context – Correctly assessing encrypted Linux volumes
- Forensic analysis of a swap partition – analysing the contents of the swap file
- Forensic classification of tmpfs and RAM-based file systems – Correctly assessing volatile memory areas