Disk forensics
Disk forensics reconstructs what happened on a system from its storage: files (including deleted), filesystem metadata, logs, and artifacts. The golden rule is to work on forensic copies, never the original, preserving integrity with hashes.
Principles
Section titled “Principles”- work on a forensic IMAGE (bit-for-bit copy), never the original disk- write-blocker (hardware/software) when acquiring -> don't alter the evidence- hash (SHA-256) the image on acquisition and on analysis -> prove it didn't change- document EVERYTHING (chain of custody, see dfir-cadena)- order of volatility: RAM first (dfir-memoria), disk afterAcquisition
Section titled “Acquisition”dd / dcfldd / dc3dd raw bit-for-bit imageewfacquire (E01) format with metadata and compression (Expert Witness)FTK Imager acquisition and inspection (Windows), widely used# verify source hash == image hash; store the original safelyFilesystems and what they hold
Section titled “Filesystems and what they hold”NTFS $MFT (each file's metadata: MAC times, size), $LogFile, $UsnJrnl (changes), ADS (alternate data streams), $I30 (directory indexes)ext4 inodes, journal, timestamps; deletion recordsAPFS/HFS+ snapshots, macOS metadata# TIMESTAMPS (MACB) are the basis of the timeline (see dfir-timeline)Analysis with The Sleuth Kit / Autopsy
Section titled “Analysis with The Sleuth Kit / Autopsy”mmls image.dd # partition tablefls -r -m / image.dd # recursive listing with metadata (bodyfile for timeline)icat image.dd <inode> # extract a file's content by inode# Autopsy (GUI over TSK): keyword search, carving, timeline, hash setsDeleted-file recovery and carving
Section titled “Deleted-file recovery and carving”- deleted files still referenced -> recoverable from metadata- file carving (by headers/signatures) when there's no metadata: foremost, photorec, scalpel- recycle bin, Shadow Copies (VSS), prefetch, and other artifacts (see dfir-win-art)Anti-forensic analysis (what the attacker does)
Section titled “Anti-forensic analysis (what the attacker does)”- timestomping (altering MAC times) -> compare $STANDARD_INFORMATION vs $FILE_NAME in $MFT- secure wiping, log clearing (see dfir-win-art), encryption- living in memory/fileless (that's why memory forensics is critical, dfir-memoria)Blue Team / DFIR
Section titled “Blue Team / DFIR”- Image + hash + write-blocker + chain of custody (Chain of custody): without this, evidence won’t hold in court.
- Prioritize high-value artifacts (triage, see Malware triage) before exhaustive analysis.
- Correlate with memory (Memory forensics), network (Network forensics), and build a timeline (Timeline analysis).
Real-world cases
Section titled “Real-world cases”- $MFT/$UsnJrnl forensics is routine to date malware execution and timestomping in real IRs.
- Shadow Copies have recovered files ransomware thought it destroyed (when it didn’t delete them).
- Many court cases have been lost over poor chain of custody or hashing.
Testing checklist
Section titled “Testing checklist”- Acquire image with a write-blocker and verify source==image hash
- Preserve the original and document chain of custody
- Analyze $MFT/$UsnJrnl (NTFS) or inodes/journal (ext4)
- Recover deleted files and carve (foremost/photorec) if needed
- Review Shadow Copies, recycle bin, and artifacts (Windows artifacts)
- Detect anti-forensics (timestomping: SI vs FN in $MFT)
- Feed the timeline (Timeline analysis) with the bodyfile