IT Forensics · Linux

Forensic analysis of wtmp and utmp files – analysing session data in detail

wtmp and utmp store structured records of user sessions, including the terminal, process ID, timestamp and, in some cases, the source address. Whilst utmp reflects the current session status, wtmp maintains a historical record.

Enquire without obligation

The binary structure of these files requires the structured extraction of individual data records for a forensically verifiable analysis, rather than relying solely on textual summaries.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We extract individual session records from wtmp and utmp, use them to reconstruct the session duration and origin, and assign the results to the relevant user accounts and processes.

Typical areas of application

Reconstruction of individual user sessions
Record of the duration of meetings relating to safety-related incidents
Investigation of parallel or unusual sessions
Reconciliation with process and network activities
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a wtmp/utmp analysis works

Once backed up, the binary data records from wtmp and utmp are extracted in a structured manner and organised chronologically. The start and end times of sessions, as well as the processes involved, are documented and correlated with other system artefacts such as process lists and network connections.

Why is this analysis relevant from a forensic perspective?

Detailed meeting information allows for a more precise chronological reconstruction than a simple attendance list, particularly when examining meetings that take place simultaneously or over a longer period.

Combining wtmp and utmp data with process and network information allows for a more reliable assessment of which activities may actually have taken place during a particular session.

Frequently Asked Questions

What does utmp show that wtmp does not?+
utmp reflects the current session status, whilst wtmp contains a continuous historical record of all sessions.
Are these files present on every Linux system?+
Generally speaking, yes; they are among the standard mechanisms for session management on traditional Linux systems.
Can any conclusions be drawn from this regarding remote access?+
In some cases, provided that origin information such as the terminal or IP address has also been logged.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of wtmp and utmp files"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now