Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts
How to acquire Linux evidence soundly: order of volatility, live vs dead acquisition, dd/dc3dd/ewfacquire imaging, cloud snapshots and read-only mounts.
Linux DFIR field reference
Where the evidence lives, what it proves and how to collect it without destroying it: logs and the systemd journal, shell history, persistence, ext4 and XFS timestamps, memory, containers and triage.
/var/evidence
Nine areas cover the artifacts that matter on a compromised Linux system. Each links to deep guides with commands, tables and pitfalls.
Image disks, snapshot cloud volumes and run triage collectors without trampling evidence.
Read syslog, auth.log and secure, the systemd journal, login records and auditd.
Reconstruct what an account did from shell history, SSH files, editors and sudo.
Hunt cron jobs, systemd units and timers, SSH keys, preload hijacks and shell startup files.
Interpret MACB times on ext4 and XFS, inode metadata, timestomping and deleted files.
Capture RAM with LiME or AVML and analyse it with Volatility 3 and the right symbol tables.
Triage a running host through /proc, sockets and loaded modules with a minimal footprint.
Verify binaries against package databases and investigate Docker, containerd and Podman.
Merge filesystem, log and history events into one super-timeline and pivot from anchors.
workflow
The same five phases apply whether you are looking at one cloud VM or a fleet of servers.
Capture volatile data first: memory, processes, sockets. Snapshot or image disks and record hashes.
Run UAC or a Velociraptor collector to pull logs, history and configuration in minutes.
Read auth logs, the journal, shell history, persistence locations and package state.
Merge filesystem, log and memory evidence into one UTC super-timeline and pivot.
State what each artifact proves, what it cannot prove, and how you verified it.
~/guides
How to acquire Linux evidence soundly: order of volatility, live vs dead acquisition, dd/dc3dd/ewfacquire imaging, cloud snapshots and read-only mounts.
Investigate Docker, containerd and Podman hosts: container metadata, overlay2 upper layers, JSON logs, escape indicators and Kubernetes node log paths.
How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.
Where attackers hide persistence on Linux (cron, systemd units and timers, shell startup files, SSH keys, ld.so.preload, PAM, udev, modules) and how to find it.
How to analyse Linux logs in an investigation: rsyslog files, sshd and sudo lines, the journald binary journal, wtmp/btmp, auditd and tampering signs.
Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.
man 7 dfir
Short, precise definitions of the terms you will meet in Linux investigations.
Open the glossary