Zum Inhalt springen

Spickzettel Linux-Artefakte

Alle Artefakte in einer Tabelle, nach Kategorie gruppiert. Im Querformat drucken oder im Browser als PDF speichern.

Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.

ArtefaktSpeicherortBelegtZeitstempelZugriffAufbewahrungAuswertung
Ausführung
/proc-Live-ArtefakteDebian · RHEL · SUSE · Arch/proc/<pid>/Was gerade läuft, aus welcher Programmdatei, mit welchen Argumenten, Dateien und NetzwerkverbindungenKeine verwertbaren Dateizeitstempel; Prozessstart in Clock Ticks seit dem Boot (/proc/<pid>/stat, Feld 22)root, um exe, environ, fd und maps aller Prozesse zu sehen; andere Benutzer sehen nur ihre eigenenFlüchtig: weg bei Prozessende oder Neustartps, ss, lsof, Velociraptor, Volatility 3
/tmp, /var/tmp and /dev/shmEnglischDebian · RHEL · SUSE · Arch/tmp, /var/tmp, /dev/shm, /run/user/<uid>That files were dropped or run from world-writable locations, by which user and whenInode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM onlyAny user can write; root needed to read other users' files (mode 1777 with sticky bit)tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deletedfind, stat, debugfs, The Sleuth Kit, Velociraptor
Docker, containerd and Podman Artifacts on Linux HostsEnglischDebian · RHEL · SUSE · Arch/var/lib/docker/containers/<id>/Which containers ran, from which image and command, with which privileges, what they printed and which files they changedRFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layersroot (or docker group, which is root-equivalent); rootless Podman data is owned by the userUntil the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file setcontainer-explorer, jq, docker, crictl, ctr
Linux Crash Reports and Core DumpsEnglischDebian · RHEL · SUSE · Arch/var/lib/systemd/coredump/, /var/crash/Which program crashed, when, as which user, with which command line, and what its memory held at that momentJournal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctimeroot; per-user cores readable by the owning user through coredumpctlsystemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 dayscoredumpctl, gdb, getfattr, apport-unpack, crash
Linux Memory AcquisitionEnglischDebian · RHEL · SUSE · Arch/proc/kcore, /dev/crash, /dev/memRunning processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not showCapture time from your case log; in-memory structures carry their own times (process start as time since boot)root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEMVolatile: lost at power-off; changes continuously while the host runsVolatility 3, dwarf2json, AVML, LiME
Shell-HistoryDebian · RHEL · SUSE · Arch~/.bash_historyWelche Befehle in einer interaktiven Shell unter einem bestimmten Konto eingegeben wurden, manchmal auch wannSekunden seit der Unix-Epoche (UTC), sofern erfasst: bash nur mit HISTTIMEFORMAT, zsh mit EXTENDED_HISTORY, fish immerJeder Benutzer für die eigenen Dateien; root für die Home-Verzeichnisse anderer BenutzerBis zur Kürzung durch HISTFILESIZE/SAVEHIST oder bis zur LöschungPlaso, Volatility 3, Velociraptor
Snap and Flatpak ArtifactsEnglischDebian · RHEL · SUSE · Arch/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user dataRFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file timesroot for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each userInstalled apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journalsnap, flatpak, jq, journalctl, find
sudo-LogsDebian · RHEL · SUSE · Arch/var/log/auth.log, /var/log/secureWelches Konto welchen Befehl als welcher Zielbenutzer von welchem Terminal und Verzeichnis ausgeführt hat, dazu fehlgeschlagene Versuchesyslog-/Journal-Zeit des Hosts (siehe Syslog-Formate); I/O-Logs speichern relative Zeiten pro Sitzungroot (oder Gruppe adm für auth.log unter Debian/Ubuntu)Folgt der Rotation von auth.log/secure und den Journal-Limits; I/O-Logs bis zur Löschunggrep/zgrep, journalctl, sudoreplay, ausearch, Plaso
Persistenz
/etc/ld.so.preload und LD_PRELOADDebian · RHEL · SUSE · Arch/etc/ld.so.preloadOb eine Shared Library in dynamisch gelinkte Prozesse erzwungen wurde, welche und seit wannmtime/ctime/crtime der Preload-Datei und der Bibliothek; keine internen Zeitstempelroot zum Schreiben; für alle lesbar; kann vom Rootkit selbst vor Live-Werkzeugen verborgen werdenBis zur Löschung; LD_PRELOAD in Prozessumgebungen besteht, bis der Prozess endetdebugfs, UAC, Volatility 3, Velociraptor
/etc/passwd, shadow and groupEnglischDebian · RHEL · SUSE · Arch/etc/passwd, /etc/shadow, /etc/group, /etc/gshadowWhich local accounts and group memberships exist, which can log in, and when each password was last changedshadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal timepasswd and group: any user; shadow and gshadow: rootUntil changed; one backup generation (passwd-, shadow-, group-, gshadow-)awk, pwck -r, grpck -r, Velociraptor, ausearch
Cron, Anacron, at und systemd-TimerDebian · RHEL · SUSE · Arch/var/spool/cron/Welche Befehle von welchem Konto zur Ausführung geplant waren und wann cron, anacron oder ein Timer sie zuletzt ausgelöst hatmtime/ctime der Dateien; Zeit in syslog oder Journal für Ausführungen; Anacron-Stempel als lokales Datum YYYYMMDDroot für alle Spool-Verzeichnisse; jeder Benutzer für die eigene Crontab über crontab -lBis zur Löschung; Ausführungsspuren folgen der Rotation von syslog/JournalVelociraptor, UAC, grep, systemctl
eBPF Programs and Pinned MapsEnglischDebian · RHEL · SUSE · ArchKernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on diskWhich eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores thembpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file timesroot (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks othersPrograms live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on diskbpftool, Volatility 3, ss, ausearch, readelf, find
Linux Kernel ModulesEnglischDebian · RHEL · SUSE · Arch/proc/modulesWhich kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernelKernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file timesroot; kernel addresses in /proc/modules are zeroed for unprivileged readersLoaded state and taint until reboot; config files until deleted; log lines per journal/syslog limitsVolatility 3, modinfo, Velociraptor, UAC
PAM Configuration and ModulesEnglischDebian · RHEL · SUSE · Arch/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentialsFile system times of stack files and modules; PAM messages in auth logs and the journalroot to modify; configuration world-readable, modules readable by allPersistent until changed; package updates may overwrite a patched modulerpm, dpkg, debsums, authselect, find, grep / zgrep, strings
rc.local, SysV init.d and MOTD ScriptsEnglischDebian · RHEL/etc/rc.localWhether a script was set to run as root at boot or at every login, and when it was placed thereFile mtime/ctime/crtime only; execution times from journal or syslogroot to write; world-readable on most systemsUntil deleted; execution evidence follows journal/syslog rotationUAC, Velociraptor, grep, journalctl
Shell Startup FilesEnglischDebian · RHEL · SUSE · Arch/etc/profile.d/Whether code was set to run automatically each time a user or root starts or ends a shell sessionNone inside the files; use inode mtime/ctime/crtime (ext4, XFS v5)root for /etc files; any user for own dotfiles; root to read other users' homesUntil modified or deleted; package upgrades may replace /etc defaultsVelociraptor, debsums, rpm -V
SSH-ArtefakteDebian · RHEL · SUSE · Arch~/.ssh/authorized_keysWelche Schlüssel sich an einem Konto anmelden können, wohin sich ein Benutzer verbunden hat und wer sich von wo per SSH angemeldet hatSchlüsseldateien: nur Dateisystemzeiten; Logs: syslog-Ortszeit oder Journal in Mikrosekunden seit der Unix-Epoche (UTC)root (oder der Kontoinhaber für das eigene ~/.ssh); Gruppe adm/systemd-journal für LogsSchlüsseldateien bis zur Löschung; Logzeilen folgen der Syslog-Rotation und den Journal-Limitsssh-keygen, Velociraptor, UAC, grep
SUID, SGID and File CapabilitiesEnglischDebian · RHEL · SUSE · ArchInode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file systemWhich executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package managerSetting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or installReadable by any user with stat/getcap; root to setPersistent until the file is replaced or the bit removed; package updates reset package-owned filesfind, getcap, getfattr, stat, rpm, dpkg, debsums
sysctl, Boot Parameters and binfmt_misc on LinuxEnglischDebian · RHEL · SUSE · Arch/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker codeFile system times of configuration files only; live values carry no timestamproot to change; most values world-readable in /proc/sysFiles persist; runtime changes via sysctl -w or /proc/sys writes are lost at rebootsysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg
systemd-Unit-DateienDebian · RHEL · SUSE · Arch/etc/systemd/system/Welche Dienste und Timer zum Start konfiguriert sind, was sie ausführen und wann die Unit installiert oder geändert wurdemtime/ctime/crtime der Dateien; Journal-Einträge in Mikrosekunden seit der Unix-Epoche (UTC)root für System-Units; jeder Benutzer für das eigene ~/.config/systemd/userBis zur Löschung; Units unter /run gehen beim Neustart verloren; Start-/Stopp-Ereignisse folgen den Journal-Limitssystemctl, systemd-analyze, Velociraptor, UAC
Web Shells in the Web RootEnglischDebian · RHEL · SUSE · Arch/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webappsThat a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can doFile system times (birth time on ext4/XFS v5 dates the drop); first request time in access logsRead as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or httpUntil deleted; deployments and CMS updates may overwrite or remove filesfind, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg
XDG Autostart .desktop EntriesEnglischDebian · RHEL · SUSE · Arch~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktopWhich programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was writtenFile system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessionsAny user for their own entries; root for /etc/xdg/autostartUntil the .desktop file is deleted; launch records follow journal retentionfind, grep / zgrep, journalctl, systemctl, rpm, dpkg
Dateizugriff
ext4-Zeitstempel, crtime und gelöschte DateienDebian · Arch/dev/<ext4-partition>Wann eine Datei erstellt, geändert, in den Metadaten verändert und möglicherweise gelesen oder gelöscht wurde, manchmal auch ihr InhaltSekunden seit der Unix-Epoche (UTC) plus Nanosekunden in *_extra-Feldern (256-Byte-Inodes); i_dtime in SekundenJeder Benutzer für stat auf zugänglichen Dateien; root oder Rohzugriff auf das Gerät für debugfs und gelöschte InodesZeitstempel bis zum Überschreiben; gelöschte Inodes und Blöcke bis zur Wiederverwendung; das Journal ist ein kleines Ringprotokolldebugfs, The Sleuth Kit, Plaso, ext4magic, stat
Linux Thumbnail CacheEnglischDebian · RHEL · SUSE · Arch~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked likeThumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generatedAny user for their own cache (mode 0700 directories, 0600 files); root for other usersUntil the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by defaultExifTool, find, stat
Linux TrashEnglischDebian · RHEL · SUSE · Arch~/.local/share/Trash/{files,info}/Which file or folder a user sent to the Trash through a desktop application, from which original path, and whenDeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo fileAny user for their own Trash (directories mode 0700); root for other usersUntil the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled)gio, trash-cli, find, stat
recently-used.xbelEnglischDebian · RHEL · SUSE · Arch~/.local/share/recently-used.xbelWhich local or remote files a desktop user opened or saved through GUI applications, with which app and whenISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix secondsAny user for own file (GTK sets mode 0600); root for other usersGTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by defaultxmllint, Python ElementTree
Tracker / LocalSearch DBEnglischDebian · RHEL · SUSE · Arch~/.cache/tracker3/files/Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexerUnix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be keptAny user for own cache; root for other usersMirrors the indexed tree; entries removed when the indexer processes a deletiontinysparql, sqlite3, localsearch
viminfo, ShaDa and lesshstEnglischDebian · RHEL · SUSE · Arch~/.viminfoWhich files a user opened in vim or Neovim, and what they searched for or ran inside vim and lessUnix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshstAny user for own files (created mode 0600); root for other usersUntil deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100)Plaso, Neovim, python-msgpack
XFS ForensicsEnglischRHEL · SUSE/dev/<xfs-volume>When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files containedSeconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystemsAny user for stat on accessible files; root or raw device access for xfs_dbTimestamps until overwritten; deleted inode extents and data blocks until reusedxfs_db, stat, libfsxfs, Plaso
Benutzeraktivität
Browser Profiles on LinuxEnglischDebian · RHEL · SUSE · Arch~/.mozilla/firefox/<profile>/places.sqliteWhich sites a user visited, what they downloaded and searched for, and whenFirefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC)Any user for own profile; root for other usersChrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pagesHindsight, Plaso, sqlite3
wtmp, btmp, utmp und lastlogDebian · RHEL · SUSE · Arch/var/log/wtmpWer sich an welchem Terminal von welchem Host angemeldet hat, wann die Sitzung endete und wann das System neu gestartet wurdeutmp-Datensätze: Sekunden seit der Unix-Epoche + Mikrosekunden (32-Bit-Felder), UTC. wtmpdb: Mikrosekunden seit der Epochewtmp/utmp/lastlog für alle lesbar; btmp nur für root (oder die Gruppe utmp)logrotate: monatlich, 1 alte Generation für wtmp und btmp; lastlog bis zum Überschreibenlast, lastb, utmpdump, wtmpdb, Plaso, Velociraptor
Netzwerk
/etc/hosts, nsswitch.conf and resolv.conf on LinuxEnglischDebian · RHEL · SUSE · Arch/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directoryWhere the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookupsFile system times only; systemd-resolved and NetworkManager log DNS server changes to the journalWorld-readable; root to modifyPersistent until edited; generated resolv.conf files are rewritten by the network stackgetent, resolvectl, grep / zgrep, rpm, dpkg, journalctl
Linux Firewall LogsEnglischDebian · RHEL · SUSE · Arch/var/log/ufw.log, /var/log/kern.logWhich connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changedSyslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system timesroot (or adm group for /var/log files on Debian/Ubuntu)Follows syslog rotation and journal limits; rule files until changedgrep/zgrep, journalctl, nft, iptables-save, Plaso
NetworkManager Profiles and StateEnglischDebian · RHEL · SUSE · Arch/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leasedUnix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode timesroot (profiles are root-only 0600); journal: root or systemd-journal groupProfiles until deleted; state files overwritten in place; journal per its limitsgrep, journalctl, nmcli (live), Plaso
USB & Geräte
udev and USB Device History on LinuxEnglischDebian · RHEL · SUSE · Arch/etc/udev/rules.d/, /var/log/kern.logWhich USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run codeJournal: UTC microseconds; syslog: host local time; dmesg: seconds since bootroot (or adm/systemd-journal group) for logs; rules readable by any userFollows journal and kern.log/messages rotation; rules until deletedjournalctl, zgrep, udevadm, Plaso
Anti-Forensik
logrotate State and Log GapsEnglischDebian · RHEL · SUSE · Arch/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tamperingState file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixesrootConfiguration persistent; the state file is rewritten at every run and keeps one line per loglogrotate, stat, find, grep / zgrep, journalctl, systemctl
Logs
Apache and Nginx LogsEnglischDebian · RHEL/var/log/apache2/, /var/log/httpd/, /var/log/nginx/Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell useLocal time with numeric UTC offset, second precision (default combined format)root or adm group (Debian/Ubuntu); root (RHEL)Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 keptgrep/zgrep, awk, GoAccess, lnav, Plaso
AppArmor and SELinux DenialsEnglischDebian · RHEL · SUSE/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journalWhich confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched offmsg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal timeroot (audit.log mode 0600; kernel log readable by adm or root depending on distro)Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retentionausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep
auditd audit.logDebian · RHEL · SUSE/var/log/audit/audit.logWelcher Login-Benutzer welches Programm ausgeführt oder welche überwachte Datei berührt hat, dazu jede PAM-Authentifizierung und -SitzungUnix-Epoche in Sekunden mit Millisekunden in msg=audit(sec.msec:serial), UTCroot (log_group ist standardmäßig root)Größenbasiert: Upstream-Standard 8 MiB x 5 Dateien, von auditd rotiertausearch, aureport, Plaso, Zircolite
auth.log, secure und syslogDebian · RHEL/var/log/auth.log, /var/log/secureWer sich von wo mit welcher Methode authentifiziert hat und was Dienste und Kernel gemeldet haben, im KlartextTraditionell: Ortszeit, ohne Jahr und Zeitzone. RFC 3339: Ortszeit mit Offset und Mikrosekundenroot oder Gruppe adm (Debian/Ubuntu); root (RHEL)logrotate: wöchentlich, 4 Generationen in den Standardeinstellungen von Debian/Ubuntu und RHELgrep/zgrep, Plaso, lnav
cloud-init Logs and Instance DataEnglischDebian · RHEL · SUSE/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts runLog lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished contentroot for user-data and sensitive instance data; logs usually root-readable only or adm groupLogs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at rebootcloud-init, jq, grep / zgrep, journalctl
dmesg, kern.log and the Kernel Ring Buffer on LinuxEnglischDebian · RHEL · SUSE · Arch/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warningsRing buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTCRing buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm groupRing buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by sizedmesg, journalctl, grep / zgrep
dpkg, APT, RPM and DNF LogsEnglischDebian · RHEL/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.logWhich packages were installed, upgraded or removed, when, with which command line and by which sudo userdpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC)dpkg.log and apt/history.log are world-readable; root for complete collectiondpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removedzgrep, sqlite3, rpm --root, dpkg --root, Plaso
MySQL, MariaDB and PostgreSQL LogsEnglischDebian · RHEL/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the databaseMySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix secondsroot or the mysql/postgres service account; client history files owned by each userError logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by defaultmysqlbinlog, pgBadger, grep / zgrep, journalctl
systemd-JournalDebian · RHEL · SUSE · Arch/var/log/journal/<machine-id>/Was Dienste, Prozesse, Benutzer und der Kernel protokolliert haben, mit vertrauenswürdiger PID/UID/Programmdatei und Boot-KontextMikrosekunden seit der Unix-Epoche (UTC) für Realtime; Mikrosekunden seit dem Boot für Monotonicroot (oder Gruppe systemd-journal, adm bzw. wheel); Benutzer können ihr eigenes Journal (user-UID) lesenGrößenbasiert: standardmäßig 10 % des Dateisystems, höchstens 4G; die flüchtige Kopie geht beim Neustart verlorenjournalctl, Plaso, Velociraptor