Skip to content

Linux forensic artifacts

One page per artifact: where it lives on Debian, Ubuntu and RHEL-family systems, what it proves, how its timestamps work, how long it survives, and how to collect and parse it with open-source tools.

Execution

Persistence

File access

User activity

Network

  • /etc/hosts, nsswitch.conf and resolv.conf on Linux

    Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.

    /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory

  • Linux Firewall Logs: iptables, nftables, ufw, firewalld

    Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.

    /var/log/ufw.log, /var/log/kern.log

  • NetworkManager Profiles and State: Linux Network History

    NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.

    /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/

USB & devices

  • udev and USB Device History on Linux

    Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.

    /etc/udev/rules.d/, /var/log/kern.log

Anti-forensics

  • logrotate State and Log Gaps: Detecting Linux Log Tampering

    logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.

    /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)

Logs

  • Apache and Nginx Logs: Linux Web Server Forensics

    Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.

    /var/log/apache2/, /var/log/httpd/, /var/log/nginx/

  • AppArmor and SELinux Denials: Linux MAC Audit Logs

    SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.

    /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal

  • auditd audit.log: Linux Kernel Audit Trail

    The Linux audit log written by auditd: PAM logins, syscalls, execve arguments and watched file access, each tied to the original login user (auid).

    /var/log/audit/audit.log

  • auth.log, secure and syslog: Linux Text Logs

    rsyslog text logs on Linux: auth.log and syslog on Debian/Ubuntu, secure and messages on RHEL, with rotation and timestamp format pitfalls.

    /var/log/auth.log, /var/log/secure

  • cloud-init Logs and Instance Data: Linux Cloud VM Forensics

    cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.

    /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/

  • dmesg, kern.log and the Kernel Ring Buffer on Linux

    The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.

    /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)

  • dpkg, APT, RPM and DNF Logs: Linux Package History

    Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.

    /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log

  • MySQL, MariaDB and PostgreSQL Logs: Linux Database Forensics

    Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.

    /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)

  • systemd Journal: Linux Binary System Log

    The systemd-journald binary log: structured entries with trusted process fields and microsecond UTC timestamps, often the only system log on modern Linux hosts.

    /var/log/journal/<machine-id>/