Glossary
Inode
An inode is the on-disk structure that stores a Linux file's metadata, timestamps and pointers to its data blocks, separate from its file name.
An inode (index node) is the data structure that Unix-like filesystems such as ext4 and XFS use to describe a file. It stores the file type and permissions, owner UID and GID, size, link count, timestamps and the location of the data (extents on ext4). It does not store the file name: names live in directory entries that point to inode numbers, which is why a file can have several hard links.
stat -c 'inode=%i links=%h mtime=%y' /etc/passwd
ls -i /usr/bin/sshd
For investigators, the inode is where timestamps come from. ext4 inodes carry atime, mtime, ctime and, on the default 256-byte inodes, a creation time (crtime) with nanosecond precision. Inode numbers themselves can be telling: files created in the same burst often receive nearby inode numbers in the same block group, and an old-looking system binary with an inode number far from its neighbours may have been replaced.
When a file is deleted on ext4, its directory entry is removed and the inode is freed with a deletion time (dtime), but extent information is typically cleared, which makes content recovery difficult. Tools from The Sleuth Kit (istat, icat, fls) and debugfs read inodes directly from an image. See ext4 and XFS timestamps and deleted files.