Forensische Linux-Artefakte
Eine Seite pro Artefakt: wo es auf Debian, Ubuntu und RHEL-Systemen liegt, was es belegt, wie seine Zeitstempel funktionieren, wie lange es erhalten bleibt und wie man es mit Open-Source-Werkzeugen sichert und auswertet.
Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.
Ausführung
/proc-Live-Artefakte: Prozesse, Sockets, gelöschte Dateien
Das Pseudo-Dateisystem /proc auf einem laufenden Linux-Host: Befehlszeilen, Umgebungen, offene Dateien, Memory Maps, Sockets und gelöschte Programme.
/proc/<pid>/
/tmp, /var/tmp and /dev/shm: Linux Staging DirectoriesEnglisch
World-writable Linux directories attackers use to stage tools: tmpfs versus disk, cleanup ages, noexec, memfd fileless execution and what survives reboot.
/tmp, /var/tmp, /dev/shm, /run/user/<uid>
Docker, containerd and Podman Artifacts on Linux HostsEnglisch
Container evidence on a Linux host: Docker config.v2.json and JSON logs, overlay2 upper layers, containerd snapshots, Podman storage and Kubernetes pod logs.
/var/lib/docker/containers/<id>/
Linux Crash Reports and Core Dumps: coredump, apportEnglisch
systemd-coredump, Ubuntu apport, ABRT and kdump on Linux: where crash data lands and how it exposes failed exploits and unstable implants.
/var/lib/systemd/coredump/, /var/crash/
Linux Memory Acquisition: LiME, AVML and /proc/kcoreEnglisch
Capturing Linux RAM with LiME or AVML: memory sources, output formats, lockdown limits and the Volatility 3 symbol tables needed to analyse the image.
/proc/kcore, /dev/crash, /dev/mem
Shell-History: Befehlslogs von bash, zsh und fish
Befehlshistorie pro Benutzer von bash, zsh und fish unter Linux: was jede Datei erfasst, wann es Zeitstempel gibt und wie sich Umgehung zeigt.
~/.bash_history
Snap and Flatpak Artifacts: Linux Sandboxed App ForensicsEnglisch
Snap and Flatpak evidence on Linux: snapd state.json change history, sideloaded snaps, Flatpak installations and remotes, and per-app data directories.
/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/
sudo-Logs: Nachweise der Rechtenutzung unter Linux
Wie sudo unter Linux festhält, wer was als root ausgeführt hat: syslog- und Journal-Zeilen, optionale Logdateien, I/O-Mitschnitte und sudoers-Richtlinien.
/var/log/auth.log, /var/log/secure
Persistenz
/etc/ld.so.preload und LD_PRELOAD: Linker-Hijacking
Preload-Datei des dynamischen Linkers, LD_PRELOAD und ld.so.conf: wie Userland-Rootkits Bibliotheken in jeden Prozess einschleusen und wie man sie erkennt.
/etc/ld.so.preload
/etc/passwd, shadow and group: Linux Local AccountsEnglisch
Linux local account databases (passwd, shadow, group, gshadow and their backups) that reveal rogue accounts, UID 0 clones and password change dates.
/etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
Cron, Anacron, at und systemd-Timer: Zeitplanung unter Linux
Artefakte geplanter Aufgaben unter Linux (Crontabs, Anacron-Stempel, at-Jobs, systemd-Timer), die Persistenz aufdecken und Ausführungen belegen.
/var/spool/cron/
eBPF Programs and Pinned Maps: Linux Kernel ImplantsEnglisch
Loaded eBPF programs, pinned objects in /sys/fs/bpf and their loaders on disk: how eBPF rootkits and BPF backdoors hide on Linux and how to find them.
Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk
Linux Kernel Modules: lsmod, Taint Flags and Boot ConfigEnglisch
Loaded and configured Linux kernel modules (/proc/modules, /sys/module, modules-load.d, modprobe.d, taint flags) for spotting rootkits and module persistence.
/proc/modules
PAM Configuration and Modules: Linux Auth BackdoorsEnglisch
Linux PAM stacks in /etc/pam.d and the pam_*.so modules they load: where attackers plant password loggers and master passwords, and how to verify them.
/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)
rc.local, SysV init.d and MOTD Scripts: Linux Boot HooksEnglisch
Legacy Linux boot and login script locations (rc.local, /etc/init.d, rc?.d links, Upstart jobs, update-motd.d) and how they reveal persistence.
/etc/rc.local
Shell Startup Files: Linux bashrc and profile PersistenceEnglisch
System and per-user shell startup files (profile, bashrc, zshrc, logout) on Linux: load order, where attackers hide persistence and how to review them.
/etc/profile.d/
SSH-Artefakte: authorized_keys, known_hosts und sshd-Logs
OpenSSH-Artefakte unter Linux (authorized_keys, known_hosts, Konfiguration, Host-Keys, sshd-Logs) als Beleg für Fernzugriff, Persistenz und Lateral Movement.
~/.ssh/authorized_keys
SUID, SGID and File Capabilities: Linux Privilege BackdoorsEnglisch
SUID/SGID bits and file capabilities (security.capability) on Linux: how attackers plant root backdoors and how to baseline them against packages.
Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system
sysctl, Boot Parameters and binfmt_misc on LinuxEnglisch
Linux kernel settings in sysctl.d, /proc/sys and the boot command line: core_pattern and modprobe hijacks, weakened protections, ip_forward, binfmt_misc.
/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/
systemd-Unit-Dateien: Dienst-Persistenz unter Linux
systemd-Service-, Timer- und Drop-in-Dateien, Aktivierungs-Symlinks, Generatoren und Lingering: wo Linux-Dienste definiert sind und wie sie Persistenz verraten.
/etc/systemd/system/
Web Shells in the Web Root: Finding Them on Linux ServersEnglisch
Where Linux web roots live per distro, how PHP, JSP and CGI web shells and .htaccess or module backdoors look on disk, and how to date and hunt them.
/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps
XDG Autostart .desktop Entries: Linux Desktop PersistenceEnglisch
XDG autostart entries in /etc/xdg/autostart and ~/.config/autostart that launch programs at every graphical login, plus KDE and X session hooks.
~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop
Dateizugriff
ext4-Zeitstempel, crtime und gelöschte Dateien
ext4-Inode-Zeitstempel (atime, mtime, ctime, crtime, dtime) mit Nanosekunden, relatime, jbd2-Journal und die Grenzen der Wiederherstellung gelöschter Dateien.
/dev/<ext4-partition>
Linux Thumbnail Cache: ~/.cache/thumbnails ForensicsEnglisch
The freedesktop thumbnail cache on Linux: PNG previews named by the MD5 of the file URI, holding path and mtime, that outlive deleted files.
~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/
Linux Trash: freedesktop .trashinfo Files and Deleted ItemsEnglisch
The freedesktop.org Trash on Linux desktops: .trashinfo records with original path and deletion time, the trashed files themselves and per-volume trash folders.
~/.local/share/Trash/{files,info}/
recently-used.xbel: GNOME and GTK Recent Files on LinuxEnglisch
The freedesktop recently-used.xbel file on Linux desktops: which files and URIs a user opened through GTK (and newer KDE) applications, with UTC times.
~/.local/share/recently-used.xbel
Tracker / LocalSearch DB: GNOME File Index on LinuxEnglisch
GNOME's Tracker and LocalSearch file index on Linux: SQLite databases listing indexed files, their timestamps and extracted content for a user's home.
~/.cache/tracker3/files/
viminfo, ShaDa and lesshst: Linux Editor and Pager HistoryEnglisch
Vim viminfo, Neovim ShaDa and less history files on Linux: which files a user edited, what they searched for and typed, often after shell history is wiped.
~/.viminfo
XFS Forensics: Inode Timestamps, crtime and Deleted FilesEnglisch
XFS on RHEL-family Linux: v5 inode timestamps with crtime, bigtime, xfs_db inspection, the metadata log, and what remains after a file is deleted.
/dev/<xfs-volume>
Benutzeraktivität
Browser Profiles on Linux: Firefox and Chrome HistoryEnglisch
Firefox and Chrome/Chromium profile databases on Linux, including snap and Flatpak paths: history, downloads, epochs and how to query them offline.
~/.mozilla/firefox/<profile>/places.sqlite
wtmp, btmp, utmp und lastlog: Login-Daten unter Linux
Binäre Login-Daten unter Linux: wtmp-Sitzungshistorie, btmp-Fehlversuche, utmp-Live-Sitzungen, lastlog pro UID und die Nachfolger wtmpdb/lastlog2.
/var/log/wtmp
Netzwerk
/etc/hosts, nsswitch.conf and resolv.conf on LinuxEnglisch
Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.
/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory
Linux Firewall Logs: iptables, nftables, ufw, firewalldEnglisch
Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.
/var/log/ufw.log, /var/log/kern.log
NetworkManager Profiles and State: Linux Network HistoryEnglisch
NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.
/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/
USB & Geräte
udev and USB Device History on LinuxEnglisch
Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.
/etc/udev/rules.d/, /var/log/kern.log
Anti-Forensik
logrotate State and Log Gaps: Detecting Linux Log TamperingEnglisch
logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.
/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)
Logs
Apache and Nginx Logs: Linux Web Server ForensicsEnglisch
Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.
/var/log/apache2/, /var/log/httpd/, /var/log/nginx/
AppArmor and SELinux Denials: Linux MAC Audit LogsEnglisch
SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.
/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal
auditd audit.log: der Kernel-Audit-Trail unter Linux
Das von auditd geschriebene Linux-Audit-Log: PAM-Anmeldungen, Syscalls, execve-Argumente und überwachte Dateizugriffe, jeweils mit dem Login-Benutzer (auid).
/var/log/audit/audit.log
auth.log, secure und syslog: Textlogs unter Linux
rsyslog-Textlogs unter Linux: auth.log und syslog unter Debian/Ubuntu, secure und messages unter RHEL, mit Fallstricken bei Rotation und Zeitformat.
/var/log/auth.log, /var/log/secure
cloud-init Logs and Instance Data: Linux Cloud VM ForensicsEnglisch
cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.
/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/
dmesg, kern.log and the Kernel Ring Buffer on LinuxEnglisch
The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.
/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)
dpkg, APT, RPM and DNF Logs: Linux Package HistoryEnglisch
Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.
/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log
MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsEnglisch
Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.
/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)
systemd-Journal: das binäre Systemlog unter Linux
Das binäre Log von systemd-journald: strukturierte Einträge mit vertrauenswürdigen Prozessfeldern und UTC-Zeitstempeln in Mikrosekunden.
/var/log/journal/<machine-id>/