IT Forensics · Linux
Forensic analysis of software RAID (mdadm) – correctly reconstructing arrays
Linux software RAID using mdadm allows multiple storage devices to be combined into a single array without the need for dedicated RAID hardware. Common levels include RAID 0, 1, 5, 6 and 10.
Each RAID member contains metadata that provides information on its membership of the array, its order and its status. This metadata is essential for the correct reconstruction of the array prior to the actual file system analysis.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We back up all the data storage devices involved individually as raw images, analyse the mdadm metadata and reconstruct the original RAID array before analysing the file systems it contains.
Typical areas of application
This is how an mdadm RAID analysis works
Once all the data volumes involved have been backed up individually, the mdadm metadata for each member is analysed to determine the RAID level, order and status. The array is then reconstructed on a working copy, without altering the original data volumes, before the file systems it contains are analysed.
Why is RAID analysis relevant in a forensic context?
Server data is often not stored on a single storage medium, but is distributed across a RAID array. An incomplete or faulty reconstruction of the array can result in an incomplete or corrupted data set.
Particularly in the case of degraded or partially lost data sets, a careful technical assessment is required before any conclusions can be drawn about the complete original dataset.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of software RAID (mdadm)"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Classifying LUKS encryption in a forensic context – Correctly assessing encrypted Linux volumes
- Forensic analysis of a swap partition – analysing the contents of the swap file
- Forensic classification of tmpfs and RAM-based file systems – Correctly assessing volatile memory areas
- Forensic recovery of deleted files on ext4 – possibilities and limitations of reconstruction