IT Forensics · Linux
Forensic analysis of SSH known hosts and keys – reconstructing trust relationships between systems
SSH known hosts files record the remote systems with which a user or system has already established trusted connections, whilst authorised and private keys enable the actual key-based authentication.
These files can provide forensically valuable insights into the actual paths taken by connections between systems, for example when investigating lateral movement within a compromised network.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We analyse existing ‘Known Hosts’ entries, authorised keys and private key files, use them to reconstruct possible connection paths between systems, and check for unauthorised keys that may have been added subsequently.
Typical areas of application
This is how an analysis of SSH keys and known hosts works
Once the system has been secured, ‘known hosts’ files, authorised keys and private key files are systematically recorded. Authorised keys are checked for their creation date and validity, whilst ‘known hosts’ entries provide potential connection targets for further investigation.
Why is this analysis relevant from a forensic perspective?
An authorised key added retrospectively is a common mechanism for gaining permanent, password-free access to a compromised system, regardless of any subsequent password changes.
Known-hosts entries can also provide clues as to other systems on the same network that may also be affected, thereby enabling the scope of the investigation to be expanded in a targeted manner.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of SSH known hosts and keys"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of the Bash history – the command-line history as a key forensic source
- Forensic analysis of Zsh history – Evaluating advanced shell logging
- Forensic analysis of Shell environment variables – assessing the configuration context of individual sessions
- .Forensic analysis of .bashrc and profile files – examining shell initialisation as a source of persistence