A forensic analyst is investigating a compromised Linux server running an ext4 file system. The analyst suspects the attacker deleted critical log files (e.g., /var/log/auth.log) and wants to recover them. Which TWO techniques would be MOST effective for recovering the deleted files?
Running `extundelete` on the partition is the correct approach because extundelete parses the ext3/ext4 journal to locate inodes and data blocks that were marked free after deletion, enabling reconstruction of the original file content even without filesystem metadata. Since system logs are typically removed with `rm`, which bypasses any trash mechanism, the journal often retains enough information to recover them—provided the partition is unmounted or mounted read-only to prevent subsequent writes from overwriting the freed blocks. This makes extundelete the most direct and appropriate forensic recovery method for deleted log files on an ext3/ext4 Linux server.
Why this answer
Option A is correct because `extundelete` is a specialized utility designed for ext3/ext4 file systems that reads the journal and inode tables to locate and restore recently deleted files, making it ideal for recovering deleted logs like /var/log/auth.log on an ext4 partition. Option C is correct because `foremost` performs file carving by scanning raw disk data for known file headers and footers, which can recover deleted files even when file system metadata (inodes) has been overwritten or is unavailable. Option B is incorrect because `.Trash-1000` is a per-user trash directory used by desktop environments, not a system-wide recovery location, and root-owned logs deleted by an attacker would not be moved there.
Option D is incorrect because `lost+found` is used by fsck to reconnect orphaned inodes (files with intact metadata but no directory entry), not to recover files whose inodes were freed upon deletion. Option E is incorrect because `dd` merely creates a bit-for-bit image and `strings` only extracts printable character sequences; neither reconstructs deleted files or their metadata, so this approach is not an effective recovery technique.
Exam trap
The EC-Council CHFI exam often tests the distinction between file system-specific recovery tools (like `extundelete`) and generic file carving tools (like `foremost`), and candidates mistakenly choose `lost+found` thinking it stores all deleted files, when it only holds files recovered from file system corruption.