IT Forensics · Linux
Forensic analysis of partition tables (GPT/MBR) under Linux – Reconstructing the basic disk structure
GPT and the older MBR scheme define how a disk is divided into partitions. Under Linux, both schemes are used, depending on the age of the system, the hardware and the boot method (BIOS or UEFI).
A damaged or deliberately altered partition table can result in partitions appearing to be missing, even though the underlying data is still physically present. Forensic reconstruction therefore requires a thorough low-level analysis.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We analyse the existing partition table, reconstruct the original partition structure using file system signatures if it is damaged, and ensure that no partition is overlooked during further analysis.
Typical areas of application
This is how the analysis of a partition table works
Once the complete raw image has been backed up, the system first checks whether a valid GPT or MBR structure is present. If the structure is corrupted, the data carrier is systematically scanned for existing partitions using known file system signatures in order to reconstruct the original structure.
Why is the analysis of the partition table relevant from a forensic perspective?
An incompletely identified partition structure may result in relevant data areas being completely overlooked during the investigation. Correct reconstruction is therefore an essential first step in any data carrier analysis.
Where there is a suspicion of deliberate manipulation of the partition table, for example to conceal data, the analysis is documented with particular care in order to provide verifiable evidence for subsequent conclusions.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of partition tables (GPT/MBR) under Linux"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic classification of deleted files on Btrfs and XFS – specifically taking into account the differences compared to ext4
- Forensic analysis of encrypted LVM volumes – handling LUKS and LVM correctly in combination
- Forensic acquisition of encrypted LUKS volumes
- Forensic analysis of the ext4 file system – the basis for most Linux investigations