IT Forensics · Linux

Forensic analysis of MySQL/MariaDB databases – Forensic reconstruction of database accesses and changes

MySQL and the compatible MariaDB are among the most widely used relational database systems on Linux and, depending on their configuration, log accesses, queries executed and data changes in varying degrees of detail.

Enquire without obligation

As this logging is not always fully enabled by default, the extent of the forensic insights that can be gained depends largely on the configuration that was actually in place at the time of the incident.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse MySQL/MariaDB database instances, including existing log files and transaction logs, and use this information to reconstruct accesses, queries and data changes during the relevant period.

Typical areas of application

Reconstruction of unauthorised database accesses
Evidence of data manipulation or deletion
Investigation of incidents caused by SQL injection
Recovery of deleted or altered records, insofar as this is technically possible
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How a MySQL/MariaDB analysis works

Once the database files and existing logs have been backed up, the logging configuration active at the time of the incident is first checked. Available access, query and transaction logs are then systematically analysed.

Why is MySQL/MariaDB analysis relevant to forensic investigations?

Databases often contain a company’s most sensitive business information, which is why evidence of unauthorised access or data manipulation is of crucial forensic importance.

The validity of the analysis depends heavily on the logging settings in force at the time of the incident, which is why these are always assessed and documented transparently.

Frequently Asked Questions

Are all queries logged by default?+
No, comprehensive query logging is often not enabled by default and must be checked separately.
Can deleted records be recovered?+
To some extent, depending on the storage engine used, the existing binary logs and the time at which the data was deleted.
Is it possible to carry out an analysis even whilst a database is up and running?+
Yes, using appropriate, gentle backup procedures that preserve data integrity, so as to minimise disruption to day-to-day operations.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of MySQL/MariaDB databases"? LanCologne can assist you with the court-admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now