Skip to content
CIM-220 Cyber Incidents & Offender Methods

What is anti-forensics?

The practical answer

Anti-forensics is activity intended to obstruct, mislead or reduce the effectiveness of investigation and evidence recovery.

The key evidential caution

The dangerous assumption is that missing evidence automatically proves anti-forensic activity.

It may not.

Records may be absent because of:

Key points

  • limited logging
  • short retention
  • system failure
  • normal cleanup
  • software behaviour
  • rebuilds
  • containment
  • misconfiguration

Anti-forensic activity may include:

  • log deletion
  • timestamp alteration
  • secure deletion
  • artefact wiping
  • data encryption
  • file renaming
  • history clearing
  • evidence fabrication
  • use of memory-only tools
  • destruction of storage

What investigators should establish

Investigators should establish:

Key points

  • what evidence should normally exist
  • whether it existed earlier
  • what action altered or removed it
  • which account or process acted
  • when it happened
  • whether the action was authorised
  • what traces remain

A missing log is a gap.

A log-clear event or deletion command is stronger evidence of deliberate removal.

Even then, intent should be supported by context, sequence and surrounding activity.

Anti-forensic activity may itself leave evidence in audit records, system metadata, security alerts, backups and provider logs.

Anti-forensic activity may be partial. An offender may remove command history while leaving provider, network or endpoint records untouched. Investigators should avoid assuming that one missing source has erased the whole incident. Reconstruct the activity from independent systems and record where the evidence still conflicts.

Where concealment is suspected, identify the investigative advantage the alteration may have created. Deleting one local history may be significant if it followed remote commands, but less so where comprehensive central logs remained intact and the action formed part of documented recovery.

Operational takeaway

Treat missing evidence as a limitation first, and describe anti-forensics only where records support deliberate alteration, concealment or destruction.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.