IT Forensics · Linux

Forensic analysis of partition tables (GPT/MBR) under Linux – Reconstructing the basic disk structure

GPT and the older MBR scheme define how a disk is divided into partitions. Under Linux, both schemes are used, depending on the age of the system, the hardware and the boot method (BIOS or UEFI).

Enquire without obligation

A damaged or deliberately altered partition table can result in partitions appearing to be missing, even though the underlying data is still physically present. Forensic reconstruction therefore requires a thorough low-level analysis.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse the existing partition table, reconstruct the original partition structure using file system signatures if it is damaged, and ensure that no partition is overlooked during further analysis.

Typical areas of application

Reconstruction of damaged partition structures
Investigation following deliberate manipulation of the partition table
Finding hidden or unmounted partitions
Preparing for file system analysis on complex storage media
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how the analysis of a partition table works

Once the complete raw image has been backed up, the system first checks whether a valid GPT or MBR structure is present. If the structure is corrupted, the data carrier is systematically scanned for existing partitions using known file system signatures in order to reconstruct the original structure.

Why is the analysis of the partition table relevant from a forensic perspective?

An incompletely identified partition structure may result in relevant data areas being completely overlooked during the investigation. Correct reconstruction is therefore an essential first step in any data carrier analysis.

Where there is a suspicion of deliberate manipulation of the partition table, for example to conceal data, the analysis is documented with particular care in order to provide verifiable evidence for subsequent conclusions.

Frequently Asked Questions

What is the difference between GPT and MBR?+
MBR is the older partitioning scheme with limits on the number of partitions and volume size, whilst GPT is the more modern successor with significantly higher limits and additional redundancy.
Can a damaged partition table be reconstructed?+
In many cases, yes – based on file system signatures and known structural characteristics. Success depends on the extent of the damage.
Can partitions be hidden deliberately?+
Yes, by manipulating the partition table, partitions can be hidden from the operating system, even though the data remains physically present.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of partition tables (GPT/MBR) under Linux"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now