Antiforensik

Anti-Forensics

Anti-Forensik

Anti-forensics denotes techniques by which attackers cover their tracks, destroy evidence or hinder forensic investigations — for instance by deleting logs, manipulating timestamps or obfuscating malicious code. It is the deliberate counter-movement to forensic analysis. Its presence is often itself a telltale indicator.

History & facts. Common methods include the targeted deletion or disabling of logs, altering file timestamps (timestomping), hiding data in rarely examined areas, encryption and steganography, as well as memory-resident malware that leaves no traces on the disk. The aim is always to prevent the reconstruction of the course of events, or at least to make it costly.

Outlook & recommendation. Anti-forensics underlines why traces must be collected centrally and tamper-resistantly: if logs are kept only locally, they are the first target. Central, tamper-proof logging (for instance with hash-chained audit data) and memory forensics deprive many anti-forensic techniques of their basis. Conspicuous gaps — missing logs, manipulated timestamps — are not proof of innocence but an investigative lead.

Antiforensik — Anti-Forensics