What is anti-forensics?¶
Anti-forensics deliberately obstructs or misleads investigation by altering, concealing, fabricating or destroying evidence. Missing evidence should first be treated as a gap because retention, failure, cleanup and response can cause the same absence.
Move from absence to an evidenced action¶
Establish what should have existed, whether it existed earlier, and which account, process or command changed it. Log-clear events, wiping commands, timestamp tools and configuration changes are stronger than an unexplained gap.
Then assess authority, timing and purpose. A local history deletion after remote commands can support concealment; a documented recovery cleanup may not.
Reconstruct from independent systems¶
Anti-forensic action is often partial. Provider, central security, network, backup and system metadata may survive when a local source is removed.
Identify the investigative advantage the alteration could create and any remaining conflicts. Do not assume one missing source erased the entire incident or that the account executing the change identifies its controller.
Key takeaway
Describe anti-forensics only where evidence supports deliberate alteration or concealment, using independent sources to reconstruct what missing local records cannot show.