man 7 dfir
Glossar
Verständliche Definitionen der Begriffe aus Linux-Forensik und Incident Response, die in den Leitfäden vorkommen.
Diese Leitfäden sind derzeit nur auf Englisch verfügbar. Die folgenden Links öffnen die englische Fassung.
- auditd (Linux Audit Daemon)
- auditd is the userspace daemon of the Linux Audit framework, writing kernel audit events such as syscalls, executions and logins to audit.log.
- ext4 crtime (Birth Time)
- ext4 crtime is the file creation timestamp stored in extended inode fields, shown as Birth by stat and readable with debugfs on disk images.
- Inode
- An inode is the on-disk structure that stores a Linux file's metadata, timestamps and pointers to its data blocks, separate from its file name.
- LD_PRELOAD and /etc/ld.so.preload
- LD_PRELOAD and /etc/ld.so.preload make the dynamic linker load a chosen shared library first, a hooking technique abused by userland rootkits.
- LiME (Linux Memory Extractor)
- LiME is a loadable Linux kernel module that dumps physical memory to a file or a TCP socket for later analysis with Volatility or other tools.
- Order of Volatility
- The principle of collecting digital evidence from the most short-lived source to the most persistent, from CPU state and RAM down to archived media.
- OverlayFS
- OverlayFS is the Linux union filesystem that stacks read-only lower layers under a writable upper layer, used by Docker and containerd for container images.
- Super Timeline
- A super timeline merges timestamps from filesystem metadata, logs and application artifacts into one chronological view, typically built with Plaso.
- systemd Journal (journald)
- The systemd journal is the binary, indexed log store written by systemd-journald, holding structured log entries with trusted metadata fields.
- UAC (Unix-like Artifacts Collector)
- UAC is an open source shell-script triage collector that gathers live-response data and forensic artifacts from Linux and other Unix-like systems.
- Volatility 3
- Volatility 3 is the open source Python 3 memory forensics framework used to analyse Linux, Windows and macOS RAM images through symbol-driven plugins.
- wtmp and btmp
- wtmp and btmp are binary Linux login records: wtmp stores logins, logouts and reboots, while btmp stores failed login attempts for lastb.