IT Forensics · Linux

Forensic analysis of the XFS file system – Accurately analysing a high-performance file system on Servern

XFS is a file system designed for high throughput and large volumes, which is frequently used as the default on enterprise Linux distributions such as Red Hat and their derivatives. It differs significantly from ext-based file systems in terms of its allocation and journaling behaviour.

Enquire without obligation

It is important to note, for the purposes of forensic analysis, that XFS does not traditionally offer a simple ‘undelete’ function and that deleted inodes can be reused more quickly. This requires an investigation strategy tailored to the XFS architecture.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse XFS-specific metadata structures, allocation groups and the journal, and correlate the results with the actual system and usage context, taking into account the limited recoverability of deleted content.

Typical areas of application

Investigation of Enterprise Linux and Server systems
Analysis of large volumes of data with high write activity
Assessment of the recoverability of deleted files
Reconstruction of file and system activities
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How an XFS forensic investigation is carried out

Once the backup has been completed, the XFS structure – including allocation groups, inode tables and the journal – is analysed. As deleted inode regions can be reused relatively quickly in XFS, particular attention is paid to the urgency of the backup if deletion operations are suspected. The information obtained is then correlated with other system artefacts.

Why is XFS analysis relevant in a forensic context?

XFS is used on numerous enterprise servers, which often contain business-critical or tenant-specific data. A proper understanding of the XFS structure is essential for drawing reliable conclusions about file and system activities.

As XFS differs from ext-based systems in terms of its deletion and allocation behaviour, thoughtlessly applying assumptions specific to ext can easily lead to incorrect conclusions. These particular characteristics are therefore taken into account separately in every analysis.

Frequently Asked Questions

What distinguishes XFS from ext4?+
XFS is designed for high throughput and large volumes, and manages allocation and metadata differently from ext4, including through the use of allocation groups.
Can deleted files be recovered on XFS?+
The likelihood is generally lower than with ext4, as freed inode blocks can be reused more quickly. A definitive conclusion can only be reached once the diagnosis has been carried out.
Is XFS commonly used on the Servern?+
Yes, XFS is a widely used standard file system, particularly on enterprise Linux distributions such as Red Hat Enterprise Linux and its derivatives.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of the XFS file system"? LanCologne can assist you with the legally admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now