Zum Inhalt springen

Forensische Linux-Artefakte

Eine Seite pro Artefakt: wo es auf Debian, Ubuntu und RHEL-Systemen liegt, was es belegt, wie seine Zeitstempel funktionieren, wie lange es erhalten bleibt und wie man es mit Open-Source-Werkzeugen sichert und auswertet.

Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.

Ausführung

Persistenz

Dateizugriff

Benutzeraktivität

Netzwerk

  • /etc/hosts, nsswitch.conf and resolv.conf on LinuxEnglisch

    Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.

    /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory

  • Linux Firewall Logs: iptables, nftables, ufw, firewalldEnglisch

    Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.

    /var/log/ufw.log, /var/log/kern.log

  • NetworkManager Profiles and State: Linux Network HistoryEnglisch

    NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.

    /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/

USB & Geräte

  • udev and USB Device History on LinuxEnglisch

    Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.

    /etc/udev/rules.d/, /var/log/kern.log

Anti-Forensik

  • logrotate State and Log Gaps: Detecting Linux Log TamperingEnglisch

    logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.

    /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)

Logs

  • Apache and Nginx Logs: Linux Web Server ForensicsEnglisch

    Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.

    /var/log/apache2/, /var/log/httpd/, /var/log/nginx/

  • AppArmor and SELinux Denials: Linux MAC Audit LogsEnglisch

    SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.

    /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal

  • auditd audit.log: der Kernel-Audit-Trail unter Linux

    Das von auditd geschriebene Linux-Audit-Log: PAM-Anmeldungen, Syscalls, execve-Argumente und überwachte Dateizugriffe, jeweils mit dem Login-Benutzer (auid).

    /var/log/audit/audit.log

  • auth.log, secure und syslog: Textlogs unter Linux

    rsyslog-Textlogs unter Linux: auth.log und syslog unter Debian/Ubuntu, secure und messages unter RHEL, mit Fallstricken bei Rotation und Zeitformat.

    /var/log/auth.log, /var/log/secure

  • cloud-init Logs and Instance Data: Linux Cloud VM ForensicsEnglisch

    cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.

    /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/

  • dmesg, kern.log and the Kernel Ring Buffer on LinuxEnglisch

    The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.

    /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)

  • dpkg, APT, RPM and DNF Logs: Linux Package HistoryEnglisch

    Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.

    /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log

  • MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsEnglisch

    Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.

    /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)

  • systemd-Journal: das binäre Systemlog unter Linux

    Das binäre Log von systemd-journald: strukturierte Einträge mit vertrauenswürdigen Prozessfeldern und UTC-Zeitstempeln in Mikrosekunden.

    /var/log/journal/<machine-id>/