Skip to content

Disk forensics

Disk forensics reconstructs what happened on a system from its storage: files (including deleted), filesystem metadata, logs, and artifacts. The golden rule is to work on forensic copies, never the original, preserving integrity with hashes.

- work on a forensic IMAGE (bit-for-bit copy), never the original disk
- write-blocker (hardware/software) when acquiring -> don't alter the evidence
- hash (SHA-256) the image on acquisition and on analysis -> prove it didn't change
- document EVERYTHING (chain of custody, see dfir-cadena)
- order of volatility: RAM first (dfir-memoria), disk after
dd / dcfldd / dc3dd raw bit-for-bit image
ewfacquire (E01) format with metadata and compression (Expert Witness)
FTK Imager acquisition and inspection (Windows), widely used
# verify source hash == image hash; store the original safely
NTFS $MFT (each file's metadata: MAC times, size), $LogFile, $UsnJrnl (changes),
ADS (alternate data streams), $I30 (directory indexes)
ext4 inodes, journal, timestamps; deletion records
APFS/HFS+ snapshots, macOS metadata
# TIMESTAMPS (MACB) are the basis of the timeline (see dfir-timeline)
mmls image.dd # partition table
fls -r -m / image.dd # recursive listing with metadata (bodyfile for timeline)
icat image.dd <inode> # extract a file's content by inode
# Autopsy (GUI over TSK): keyword search, carving, timeline, hash sets
- deleted files still referenced -> recoverable from metadata
- file carving (by headers/signatures) when there's no metadata: foremost, photorec, scalpel
- recycle bin, Shadow Copies (VSS), prefetch, and other artifacts (see dfir-win-art)

Anti-forensic analysis (what the attacker does)

Section titled “Anti-forensic analysis (what the attacker does)”
- timestomping (altering MAC times) -> compare $STANDARD_INFORMATION vs $FILE_NAME in $MFT
- secure wiping, log clearing (see dfir-win-art), encryption
- living in memory/fileless (that's why memory forensics is critical, dfir-memoria)
  • $MFT/$UsnJrnl forensics is routine to date malware execution and timestomping in real IRs.
  • Shadow Copies have recovered files ransomware thought it destroyed (when it didn’t delete them).
  • Many court cases have been lost over poor chain of custody or hashing.
  • Acquire image with a write-blocker and verify source==image hash
  • Preserve the original and document chain of custody
  • Analyze $MFT/$UsnJrnl (NTFS) or inodes/journal (ext4)
  • Recover deleted files and carve (foremost/photorec) if needed
  • Review Shadow Copies, recycle bin, and artifacts (Windows artifacts)
  • Detect anti-forensics (timestomping: SI vs FN in $MFT)
  • Feed the timeline (Timeline analysis) with the bodyfile