IT Forensics · Linux

Forensic analysis of software RAID (mdadm) – correctly reconstructing arrays

Linux software RAID using mdadm allows multiple storage devices to be combined into a single array without the need for dedicated RAID hardware. Common levels include RAID 0, 1, 5, 6 and 10.

Enquire without obligation

Each RAID member contains metadata that provides information on its membership of the array, its order and its status. This metadata is essential for the correct reconstruction of the array prior to the actual file system analysis.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up all the data storage devices involved individually as raw images, analyse the mdadm metadata and reconstruct the original RAID array before analysing the file systems it contains.

Typical areas of application

Reconstruction of Server memory complexes
Investigation following the failure of individual RAID members
Evaluation of RAID rebuild operations
Analysis of degraded or inconsistent composites
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an mdadm RAID analysis works

Once all the data volumes involved have been backed up individually, the mdadm metadata for each member is analysed to determine the RAID level, order and status. The array is then reconstructed on a working copy, without altering the original data volumes, before the file systems it contains are analysed.

Why is RAID analysis relevant in a forensic context?

Server data is often not stored on a single storage medium, but is distributed across a RAID array. An incomplete or faulty reconstruction of the array can result in an incomplete or corrupted data set.

Particularly in the case of degraded or partially lost data sets, a careful technical assessment is required before any conclusions can be drawn about the complete original dataset.

Frequently Asked Questions

What is mdadm?+
mdadm is the standard tool in Linux for managing software RAID arrays of various levels.
Can a RAID array be reconstructed from individual storage devices if one member is missing?+
Depending on the RAID level and the number of missing members, a partial or complete reconstruction may be possible. A definitive assessment can only be made following a technical diagnosis.
Are the original data carriers altered during the reconstruction process?+
No. The reconstruction is carried out using raw images of the individual storage media; the original remains unchanged.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of software RAID (mdadm)"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now