IT Forensics · Linux

Forensic analysis of NetworkManager artefacts – evaluating connection profiles and history

NetworkManager is responsible for managing network connections on numerous Linux desktop systems and, in some cases, Server systems, and stores profiles for WLAN, cable and VPN connections.

Enquire without obligation

These stored connection profiles can provide information about previously used networks, including WLAN names and, in some cases, connection times, depending on the relevant logging configuration.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse stored NetworkManager connection profiles and associated log data in order to reconstruct, as far as possible, the networks used and the times at which they were used.

Typical areas of application

Reconstruction of WLAN and network connections in use
Study of mobile or frequently changing working environments
Evidence of the use of specific networks at specific times
Supplementing location and movement analyses
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a NetworkManager analysis works

Once the data has been backed up, the saved connection profiles are systematically recorded and categorised by connection type. Available timestamp and log information is used to narrow down the periods of use for the respective networks as far as possible.

Why is the NetworkManager analysis relevant from a forensic perspective?

Saved network profiles can provide insights into a system’s previous locations or the working environments in which it has been used, which can be of particular forensic significance, especially in the case of mobile devices.

The accuracy of time-related inferences depends heavily on the specific logging configuration and is therefore assessed transparently on a case-by-case basis.

Frequently Asked Questions

What types of connections does NetworkManager manage?+
These include, amongst others, WLAN, cable and VPN connections, as well as, in some cases, mobile connections, depending on the system configuration.
Can earlier WLAN names be reconstructed?+
Often, yes, provided the relevant profiles are still stored and have not been deleted in the meantime.
Is NetworkManager available on the Servern?+
Although less common than on desktop systems, it is also used on certain Server configurations.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of NetworkManager artefacts"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now