What is anti-forensics?¶
The practical answer¶
Anti-forensics is activity intended to obstruct, mislead or reduce the effectiveness of investigation and evidence recovery.
The key evidential caution¶
The dangerous assumption is that missing evidence automatically proves anti-forensic activity.
It may not.
Records may be absent because of:
Key points¶
- limited logging
- short retention
- system failure
- normal cleanup
- software behaviour
- rebuilds
- containment
- misconfiguration
Anti-forensic activity may include:
- log deletion
- timestamp alteration
- secure deletion
- artefact wiping
- data encryption
- file renaming
- history clearing
- evidence fabrication
- use of memory-only tools
- destruction of storage
What investigators should establish¶
Investigators should establish:
Key points¶
- what evidence should normally exist
- whether it existed earlier
- what action altered or removed it
- which account or process acted
- when it happened
- whether the action was authorised
- what traces remain
A missing log is a gap.
A log-clear event or deletion command is stronger evidence of deliberate removal.
Even then, intent should be supported by context, sequence and surrounding activity.
Anti-forensic activity may itself leave evidence in audit records, system metadata, security alerts, backups and provider logs.
Anti-forensic activity may be partial. An offender may remove command history while leaving provider, network or endpoint records untouched. Investigators should avoid assuming that one missing source has erased the whole incident. Reconstruct the activity from independent systems and record where the evidence still conflicts.
Where concealment is suspected, identify the investigative advantage the alteration may have created. Deleting one local history may be significant if it followed remote commands, but less so where comprehensive central logs remained intact and the action formed part of documented recovery.
Operational takeaway¶
Treat missing evidence as a limitation first, and describe anti-forensics only where records support deliberate alteration, concealment or destruction.