A security analyst is investigating a Linux workstation from which sensitive intellectual property was exfiltrated. The attacker is suspected of having deleted their tracks using 'shred' or 'rm -rf' commands. To determine if specific files were deleted and potentially recover their names, which of the following host-based forensic artifacts would be most valuable to examine, assuming the attacker could not overwrite the entire disk?
- AThe 'bash_history' file of the compromised user.
- BThe inode tables and directory entries in the file system journal.
- CThe '/var/log/syslog' for deletion events.
- DUnallocated slack space on the file system.
Show answer & explanationAnswer & explanation
Correct answer: B. The inode tables and directory entries in the file system journal.
When files are deleted on Linux, their data blocks are marked as unallocated, but the metadata (like filename, size, timestamps) often remains in the file system journal and inode table until overwritten. Examining these structures can reveal the names and paths of recently deleted files, even if their content is gone. The journal, in particular, records changes to file system metadata, offering a valuable trail.
Why the other options are wrong
- A. Bash history would show the 'rm' or 'shred' commands, but it might be cleared by the attacker, and it doesn't directly provide information about the deleted files' metadata on disk.
- C. Syslog typically records system-level events, but not detailed file deletion actions by users unless specifically configured with an audit rule.
- D. Unallocated slack space might contain remnants of file data, but it doesn't directly provide the filenames or directory structure of deleted files; it's more for data recovery.
Linux File Deletion Forensics
Investigating deleted files on Linux by examining file system metadata structures like inode tables and the journal, which can retain information about deleted files even if their data blocks are marked as free.
- Deletion marks blocks as free, doesn't erase data.
- Inode tables store file metadata.
- File system journals record metadata changes.
Memory trick: Deleted files leave behind journal clues and inode identities.