Spickzettel Linux-Artefakte
Alle Artefakte in einer Tabelle, nach Kategorie gruppiert. Im Querformat drucken oder im Browser als PDF speichern.
www.linuxforensics.app/de/artifacts
Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.
| Artefakt | Speicherort | Belegt | Zeitstempel | Zugriff | Aufbewahrung | Auswertung |
|---|---|---|---|---|---|---|
| Ausführung | ||||||
| /proc-Live-ArtefakteDebian · RHEL · SUSE · Arch | /proc/<pid>/ | Was gerade läuft, aus welcher Programmdatei, mit welchen Argumenten, Dateien und Netzwerkverbindungen | Keine verwertbaren Dateizeitstempel; Prozessstart in Clock Ticks seit dem Boot (/proc/<pid>/stat, Feld 22) | root, um exe, environ, fd und maps aller Prozesse zu sehen; andere Benutzer sehen nur ihre eigenen | Flüchtig: weg bei Prozessende oder Neustart | ps, ss, lsof, Velociraptor, Volatility 3 |
| /tmp, /var/tmp and /dev/shmEnglischDebian · RHEL · SUSE · Arch | /tmp, /var/tmp, /dev/shm, /run/user/<uid> | That files were dropped or run from world-writable locations, by which user and when | Inode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM only | Any user can write; root needed to read other users' files (mode 1777 with sticky bit) | tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deleted | find, stat, debugfs, The Sleuth Kit, Velociraptor |
| Docker, containerd and Podman Artifacts on Linux HostsEnglischDebian · RHEL · SUSE · Arch | /var/lib/docker/containers/<id>/ | Which containers ran, from which image and command, with which privileges, what they printed and which files they changed | RFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layers | root (or docker group, which is root-equivalent); rootless Podman data is owned by the user | Until the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file set | container-explorer, jq, docker, crictl, ctr |
| Linux Crash Reports and Core DumpsEnglischDebian · RHEL · SUSE · Arch | /var/lib/systemd/coredump/, /var/crash/ | Which program crashed, when, as which user, with which command line, and what its memory held at that moment | Journal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctime | root; per-user cores readable by the owning user through coredumpctl | systemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 days | coredumpctl, gdb, getfattr, apport-unpack, crash |
| Linux Memory AcquisitionEnglischDebian · RHEL · SUSE · Arch | /proc/kcore, /dev/crash, /dev/mem | Running processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not show | Capture time from your case log; in-memory structures carry their own times (process start as time since boot) | root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEM | Volatile: lost at power-off; changes continuously while the host runs | Volatility 3, dwarf2json, AVML, LiME |
| Shell-HistoryDebian · RHEL · SUSE · Arch | ~/.bash_history | Welche Befehle in einer interaktiven Shell unter einem bestimmten Konto eingegeben wurden, manchmal auch wann | Sekunden seit der Unix-Epoche (UTC), sofern erfasst: bash nur mit HISTTIMEFORMAT, zsh mit EXTENDED_HISTORY, fish immer | Jeder Benutzer für die eigenen Dateien; root für die Home-Verzeichnisse anderer Benutzer | Bis zur Kürzung durch HISTFILESIZE/SAVEHIST oder bis zur Löschung | Plaso, Volatility 3, Velociraptor |
| Snap and Flatpak ArtifactsEnglischDebian · RHEL · SUSE · Arch | /var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/ | Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user data | RFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file times | root for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each user | Installed apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journal | snap, flatpak, jq, journalctl, find |
| sudo-LogsDebian · RHEL · SUSE · Arch | /var/log/auth.log, /var/log/secure | Welches Konto welchen Befehl als welcher Zielbenutzer von welchem Terminal und Verzeichnis ausgeführt hat, dazu fehlgeschlagene Versuche | syslog-/Journal-Zeit des Hosts (siehe Syslog-Formate); I/O-Logs speichern relative Zeiten pro Sitzung | root (oder Gruppe adm für auth.log unter Debian/Ubuntu) | Folgt der Rotation von auth.log/secure und den Journal-Limits; I/O-Logs bis zur Löschung | grep/zgrep, journalctl, sudoreplay, ausearch, Plaso |
| Persistenz | ||||||
| /etc/ld.so.preload und LD_PRELOADDebian · RHEL · SUSE · Arch | /etc/ld.so.preload | Ob eine Shared Library in dynamisch gelinkte Prozesse erzwungen wurde, welche und seit wann | mtime/ctime/crtime der Preload-Datei und der Bibliothek; keine internen Zeitstempel | root zum Schreiben; für alle lesbar; kann vom Rootkit selbst vor Live-Werkzeugen verborgen werden | Bis zur Löschung; LD_PRELOAD in Prozessumgebungen besteht, bis der Prozess endet | debugfs, UAC, Volatility 3, Velociraptor |
| /etc/passwd, shadow and groupEnglischDebian · RHEL · SUSE · Arch | /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow | Which local accounts and group memberships exist, which can log in, and when each password was last changed | shadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal time | passwd and group: any user; shadow and gshadow: root | Until changed; one backup generation (passwd-, shadow-, group-, gshadow-) | awk, pwck -r, grpck -r, Velociraptor, ausearch |
| Cron, Anacron, at und systemd-TimerDebian · RHEL · SUSE · Arch | /var/spool/cron/ | Welche Befehle von welchem Konto zur Ausführung geplant waren und wann cron, anacron oder ein Timer sie zuletzt ausgelöst hat | mtime/ctime der Dateien; Zeit in syslog oder Journal für Ausführungen; Anacron-Stempel als lokales Datum YYYYMMDD | root für alle Spool-Verzeichnisse; jeder Benutzer für die eigene Crontab über crontab -l | Bis zur Löschung; Ausführungsspuren folgen der Rotation von syslog/Journal | Velociraptor, UAC, grep, systemctl |
| eBPF Programs and Pinned MapsEnglischDebian · RHEL · SUSE · Arch | Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk | Which eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores them | bpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file times | root (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks others | Programs live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on disk | bpftool, Volatility 3, ss, ausearch, readelf, find |
| Linux Kernel ModulesEnglischDebian · RHEL · SUSE · Arch | /proc/modules | Which kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernel | Kernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file times | root; kernel addresses in /proc/modules are zeroed for unprivileged readers | Loaded state and taint until reboot; config files until deleted; log lines per journal/syslog limits | Volatility 3, modinfo, Velociraptor, UAC |
| PAM Configuration and ModulesEnglischDebian · RHEL · SUSE · Arch | /etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch) | How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentials | File system times of stack files and modules; PAM messages in auth logs and the journal | root to modify; configuration world-readable, modules readable by all | Persistent until changed; package updates may overwrite a patched module | rpm, dpkg, debsums, authselect, find, grep / zgrep, strings |
| rc.local, SysV init.d and MOTD ScriptsEnglischDebian · RHEL | /etc/rc.local | Whether a script was set to run as root at boot or at every login, and when it was placed there | File mtime/ctime/crtime only; execution times from journal or syslog | root to write; world-readable on most systems | Until deleted; execution evidence follows journal/syslog rotation | UAC, Velociraptor, grep, journalctl |
| Shell Startup FilesEnglischDebian · RHEL · SUSE · Arch | /etc/profile.d/ | Whether code was set to run automatically each time a user or root starts or ends a shell session | None inside the files; use inode mtime/ctime/crtime (ext4, XFS v5) | root for /etc files; any user for own dotfiles; root to read other users' homes | Until modified or deleted; package upgrades may replace /etc defaults | Velociraptor, debsums, rpm -V |
| SSH-ArtefakteDebian · RHEL · SUSE · Arch | ~/.ssh/authorized_keys | Welche Schlüssel sich an einem Konto anmelden können, wohin sich ein Benutzer verbunden hat und wer sich von wo per SSH angemeldet hat | Schlüsseldateien: nur Dateisystemzeiten; Logs: syslog-Ortszeit oder Journal in Mikrosekunden seit der Unix-Epoche (UTC) | root (oder der Kontoinhaber für das eigene ~/.ssh); Gruppe adm/systemd-journal für Logs | Schlüsseldateien bis zur Löschung; Logzeilen folgen der Syslog-Rotation und den Journal-Limits | ssh-keygen, Velociraptor, UAC, grep |
| SUID, SGID and File CapabilitiesEnglischDebian · RHEL · SUSE · Arch | Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system | Which executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package manager | Setting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or install | Readable by any user with stat/getcap; root to set | Persistent until the file is replaced or the bit removed; package updates reset package-owned files | find, getcap, getfattr, stat, rpm, dpkg, debsums |
| sysctl, Boot Parameters and binfmt_misc on LinuxEnglischDebian · RHEL · SUSE · Arch | /etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/ | Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker code | File system times of configuration files only; live values carry no timestamp | root to change; most values world-readable in /proc/sys | Files persist; runtime changes via sysctl -w or /proc/sys writes are lost at reboot | sysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg |
| systemd-Unit-DateienDebian · RHEL · SUSE · Arch | /etc/systemd/system/ | Welche Dienste und Timer zum Start konfiguriert sind, was sie ausführen und wann die Unit installiert oder geändert wurde | mtime/ctime/crtime der Dateien; Journal-Einträge in Mikrosekunden seit der Unix-Epoche (UTC) | root für System-Units; jeder Benutzer für das eigene ~/.config/systemd/user | Bis zur Löschung; Units unter /run gehen beim Neustart verloren; Start-/Stopp-Ereignisse folgen den Journal-Limits | systemctl, systemd-analyze, Velociraptor, UAC |
| Web Shells in the Web RootEnglischDebian · RHEL · SUSE · Arch | /var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps | That a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can do | File system times (birth time on ext4/XFS v5 dates the drop); first request time in access logs | Read as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or http | Until deleted; deployments and CMS updates may overwrite or remove files | find, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg |
| XDG Autostart .desktop EntriesEnglischDebian · RHEL · SUSE · Arch | ~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop | Which programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was written | File system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessions | Any user for their own entries; root for /etc/xdg/autostart | Until the .desktop file is deleted; launch records follow journal retention | find, grep / zgrep, journalctl, systemctl, rpm, dpkg |
| Dateizugriff | ||||||
| ext4-Zeitstempel, crtime und gelöschte DateienDebian · Arch | /dev/<ext4-partition> | Wann eine Datei erstellt, geändert, in den Metadaten verändert und möglicherweise gelesen oder gelöscht wurde, manchmal auch ihr Inhalt | Sekunden seit der Unix-Epoche (UTC) plus Nanosekunden in *_extra-Feldern (256-Byte-Inodes); i_dtime in Sekunden | Jeder Benutzer für stat auf zugänglichen Dateien; root oder Rohzugriff auf das Gerät für debugfs und gelöschte Inodes | Zeitstempel bis zum Überschreiben; gelöschte Inodes und Blöcke bis zur Wiederverwendung; das Journal ist ein kleines Ringprotokoll | debugfs, The Sleuth Kit, Plaso, ext4magic, stat |
| Linux Thumbnail CacheEnglischDebian · RHEL · SUSE · Arch | ~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/ | That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked like | Thumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generated | Any user for their own cache (mode 0700 directories, 0600 files); root for other users | Until the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by default | ExifTool, find, stat |
| Linux TrashEnglischDebian · RHEL · SUSE · Arch | ~/.local/share/Trash/{files,info}/ | Which file or folder a user sent to the Trash through a desktop application, from which original path, and when | DeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo file | Any user for their own Trash (directories mode 0700); root for other users | Until the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled) | gio, trash-cli, find, stat |
| recently-used.xbelEnglischDebian · RHEL · SUSE · Arch | ~/.local/share/recently-used.xbel | Which local or remote files a desktop user opened or saved through GUI applications, with which app and when | ISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix seconds | Any user for own file (GTK sets mode 0600); root for other users | GTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by default | xmllint, Python ElementTree |
| Tracker / LocalSearch DBEnglischDebian · RHEL · SUSE · Arch | ~/.cache/tracker3/files/ | Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexer | Unix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be kept | Any user for own cache; root for other users | Mirrors the indexed tree; entries removed when the indexer processes a deletion | tinysparql, sqlite3, localsearch |
| viminfo, ShaDa and lesshstEnglischDebian · RHEL · SUSE · Arch | ~/.viminfo | Which files a user opened in vim or Neovim, and what they searched for or ran inside vim and less | Unix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshst | Any user for own files (created mode 0600); root for other users | Until deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100) | Plaso, Neovim, python-msgpack |
| XFS ForensicsEnglischRHEL · SUSE | /dev/<xfs-volume> | When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files contained | Seconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystems | Any user for stat on accessible files; root or raw device access for xfs_db | Timestamps until overwritten; deleted inode extents and data blocks until reused | xfs_db, stat, libfsxfs, Plaso |
| Benutzeraktivität | ||||||
| Browser Profiles on LinuxEnglischDebian · RHEL · SUSE · Arch | ~/.mozilla/firefox/<profile>/places.sqlite | Which sites a user visited, what they downloaded and searched for, and when | Firefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC) | Any user for own profile; root for other users | Chrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pages | Hindsight, Plaso, sqlite3 |
| wtmp, btmp, utmp und lastlogDebian · RHEL · SUSE · Arch | /var/log/wtmp | Wer sich an welchem Terminal von welchem Host angemeldet hat, wann die Sitzung endete und wann das System neu gestartet wurde | utmp-Datensätze: Sekunden seit der Unix-Epoche + Mikrosekunden (32-Bit-Felder), UTC. wtmpdb: Mikrosekunden seit der Epoche | wtmp/utmp/lastlog für alle lesbar; btmp nur für root (oder die Gruppe utmp) | logrotate: monatlich, 1 alte Generation für wtmp und btmp; lastlog bis zum Überschreiben | last, lastb, utmpdump, wtmpdb, Plaso, Velociraptor |
| Netzwerk | ||||||
| /etc/hosts, nsswitch.conf and resolv.conf on LinuxEnglischDebian · RHEL · SUSE · Arch | /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory | Where the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookups | File system times only; systemd-resolved and NetworkManager log DNS server changes to the journal | World-readable; root to modify | Persistent until edited; generated resolv.conf files are rewritten by the network stack | getent, resolvectl, grep / zgrep, rpm, dpkg, journalctl |
| Linux Firewall LogsEnglischDebian · RHEL · SUSE · Arch | /var/log/ufw.log, /var/log/kern.log | Which connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changed | Syslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system times | root (or adm group for /var/log files on Debian/Ubuntu) | Follows syslog rotation and journal limits; rule files until changed | grep/zgrep, journalctl, nft, iptables-save, Plaso |
| NetworkManager Profiles and StateEnglischDebian · RHEL · SUSE · Arch | /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/ | Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leased | Unix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode times | root (profiles are root-only 0600); journal: root or systemd-journal group | Profiles until deleted; state files overwritten in place; journal per its limits | grep, journalctl, nmcli (live), Plaso |
| USB & Geräte | ||||||
| udev and USB Device History on LinuxEnglischDebian · RHEL · SUSE · Arch | /etc/udev/rules.d/, /var/log/kern.log | Which USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run code | Journal: UTC microseconds; syslog: host local time; dmesg: seconds since boot | root (or adm/systemd-journal group) for logs; rules readable by any user | Follows journal and kern.log/messages rotation; rules until deleted | journalctl, zgrep, udevadm, Plaso |
| Anti-Forensik | ||||||
| logrotate State and Log GapsEnglischDebian · RHEL · SUSE · Arch | /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL) | When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tampering | State file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixes | root | Configuration persistent; the state file is rewritten at every run and keeps one line per log | logrotate, stat, find, grep / zgrep, journalctl, systemctl |
| Logs | ||||||
| Apache and Nginx LogsEnglischDebian · RHEL | /var/log/apache2/, /var/log/httpd/, /var/log/nginx/ | Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell use | Local time with numeric UTC offset, second precision (default combined format) | root or adm group (Debian/Ubuntu); root (RHEL) | Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 kept | grep/zgrep, awk, GoAccess, lnav, Plaso |
| AppArmor and SELinux DenialsEnglischDebian · RHEL · SUSE | /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal | Which confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched off | msg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal time | root (audit.log mode 0600; kernel log readable by adm or root depending on distro) | Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retention | ausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep |
| auditd audit.logDebian · RHEL · SUSE | /var/log/audit/audit.log | Welcher Login-Benutzer welches Programm ausgeführt oder welche überwachte Datei berührt hat, dazu jede PAM-Authentifizierung und -Sitzung | Unix-Epoche in Sekunden mit Millisekunden in msg=audit(sec.msec:serial), UTC | root (log_group ist standardmäßig root) | Größenbasiert: Upstream-Standard 8 MiB x 5 Dateien, von auditd rotiert | ausearch, aureport, Plaso, Zircolite |
| auth.log, secure und syslogDebian · RHEL | /var/log/auth.log, /var/log/secure | Wer sich von wo mit welcher Methode authentifiziert hat und was Dienste und Kernel gemeldet haben, im Klartext | Traditionell: Ortszeit, ohne Jahr und Zeitzone. RFC 3339: Ortszeit mit Offset und Mikrosekunden | root oder Gruppe adm (Debian/Ubuntu); root (RHEL) | logrotate: wöchentlich, 4 Generationen in den Standardeinstellungen von Debian/Ubuntu und RHEL | grep/zgrep, Plaso, lnav |
| cloud-init Logs and Instance DataEnglischDebian · RHEL · SUSE | /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/ | How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts run | Log lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished content | root for user-data and sensitive instance data; logs usually root-readable only or adm group | Logs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at reboot | cloud-init, jq, grep / zgrep, journalctl |
| dmesg, kern.log and the Kernel Ring Buffer on LinuxEnglischDebian · RHEL · SUSE · Arch | /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k) | Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warnings | Ring buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTC | Ring buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm group | Ring buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by size | dmesg, journalctl, grep / zgrep |
| dpkg, APT, RPM and DNF LogsEnglischDebian · RHEL | /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log | Which packages were installed, upgraded or removed, when, with which command line and by which sudo user | dpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC) | dpkg.log and apt/history.log are world-readable; root for complete collection | dpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removed | zgrep, sqlite3, rpm --root, dpkg --root, Plaso |
| MySQL, MariaDB and PostgreSQL LogsEnglischDebian · RHEL | /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL) | Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the database | MySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix seconds | root or the mysql/postgres service account; client history files owned by each user | Error logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by default | mysqlbinlog, pgBadger, grep / zgrep, journalctl |
| systemd-JournalDebian · RHEL · SUSE · Arch | /var/log/journal/<machine-id>/ | Was Dienste, Prozesse, Benutzer und der Kernel protokolliert haben, mit vertrauenswürdiger PID/UID/Programmdatei und Boot-Kontext | Mikrosekunden seit der Unix-Epoche (UTC) für Realtime; Mikrosekunden seit dem Boot für Monotonic | root (oder Gruppe systemd-journal, adm bzw. wheel); Benutzer können ihr eigenes Journal (user-UID) lesen | Größenbasiert: standardmäßig 10 % des Dateisystems, höchstens 4G; die flüchtige Kopie geht beim Neustart verloren | journalctl, Plaso, Velociraptor |