IT Forensics · Linux

Forensic analysis of SSH known hosts and keys – reconstructing trust relationships between systems

SSH known hosts files record the remote systems with which a user or system has already established trusted connections, whilst authorised and private keys enable the actual key-based authentication.

Enquire without obligation

These files can provide forensically valuable insights into the actual paths taken by connections between systems, for example when investigating lateral movement within a compromised network.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse existing ‘Known Hosts’ entries, authorised keys and private key files, use them to reconstruct possible connection paths between systems, and check for unauthorised keys that may have been added subsequently.

Typical areas of application

Reconstruction of lateral motion between compromised systems
Detection of unauthorised SSH keys
Investigation of trust relationships between Servern
Evidence of the connection paths used in networks
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an analysis of SSH keys and known hosts works

Once the system has been secured, ‘known hosts’ files, authorised keys and private key files are systematically recorded. Authorised keys are checked for their creation date and validity, whilst ‘known hosts’ entries provide potential connection targets for further investigation.

Why is this analysis relevant from a forensic perspective?

An authorised key added retrospectively is a common mechanism for gaining permanent, password-free access to a compromised system, regardless of any subsequent password changes.

Known-hosts entries can also provide clues as to other systems on the same network that may also be affected, thereby enabling the scope of the investigation to be expanded in a targeted manner.

Frequently Asked Questions

What does a ‘known_hosts’ file show?+
A list of remote systems that have already been contacted, together with their host key fingerprints, which were used to establish previous connections.
How is an unauthorised SSH key detected?+
By checking the creation date, the comment field and the plausibility of the data against known, legitimately used keys.
Can private keys be analysed forensically?+
Yes, their existence and use can be analysed, but this does not bypass their password protection.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of SSH known hosts and keys"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now