Linux forensic artifacts
One page per artifact: where it lives on Debian, Ubuntu and RHEL-family systems, what it proves, how its timestamps work, how long it survives, and how to collect and parse it with open-source tools.
Execution
/proc Live Artifacts: Processes, Sockets and Deleted Files
The /proc pseudo-filesystem on a live Linux host: process command lines, environments, open files, memory maps, sockets and deleted binaries.
/proc/<pid>/
/tmp, /var/tmp and /dev/shm: Linux Staging Directories
World-writable Linux directories attackers use to stage tools: tmpfs versus disk, cleanup ages, noexec, memfd fileless execution and what survives reboot.
/tmp, /var/tmp, /dev/shm, /run/user/<uid>
Docker, containerd and Podman Artifacts on Linux Hosts
Container evidence on a Linux host: Docker config.v2.json and JSON logs, overlay2 upper layers, containerd snapshots, Podman storage and Kubernetes pod logs.
/var/lib/docker/containers/<id>/
Linux Crash Reports and Core Dumps: coredump, apport
systemd-coredump, Ubuntu apport, ABRT and kdump on Linux: where crash data lands and how it exposes failed exploits and unstable implants.
/var/lib/systemd/coredump/, /var/crash/
Linux Memory Acquisition: LiME, AVML and /proc/kcore
Capturing Linux RAM with LiME or AVML: memory sources, output formats, lockdown limits and the Volatility 3 symbol tables needed to analyse the image.
/proc/kcore, /dev/crash, /dev/mem
Shell History: Linux bash, zsh and fish Command Logs
Per-user command history written by bash, zsh and fish on Linux: what each file records, when timestamps exist and how history evasion shows up.
~/.bash_history
Snap and Flatpak Artifacts: Linux Sandboxed App Forensics
Snap and Flatpak evidence on Linux: snapd state.json change history, sideloaded snaps, Flatpak installations and remotes, and per-app data directories.
/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/
sudo Logs: Linux Privilege Use Records
How sudo records who ran what as root on Linux: syslog and journal lines, optional log files and I/O session recordings, plus sudoers policy files.
/var/log/auth.log, /var/log/secure
Persistence
/etc/ld.so.preload and LD_PRELOAD: Linux Linker Hijacking
The dynamic linker preload file, LD_PRELOAD and ld.so.conf: how userland rootkits inject libraries into every process and how to detect them.
/etc/ld.so.preload
/etc/passwd, shadow and group: Linux Local Accounts
Linux local account databases (passwd, shadow, group, gshadow and their backups) that reveal rogue accounts, UID 0 clones and password change dates.
/etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
Cron, Anacron, at and systemd Timers: Linux Scheduling
Linux scheduled task artifacts (crontabs, anacron stamps, at spool jobs, systemd timers) that reveal scheduled persistence and prove when jobs ran.
/var/spool/cron/
eBPF Programs and Pinned Maps: Linux Kernel Implants
Loaded eBPF programs, pinned objects in /sys/fs/bpf and their loaders on disk: how eBPF rootkits and BPF backdoors hide on Linux and how to find them.
Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk
Linux Kernel Modules: lsmod, Taint Flags and Boot Config
Loaded and configured Linux kernel modules (/proc/modules, /sys/module, modules-load.d, modprobe.d, taint flags) for spotting rootkits and module persistence.
/proc/modules
PAM Configuration and Modules: Linux Auth Backdoors
Linux PAM stacks in /etc/pam.d and the pam_*.so modules they load: where attackers plant password loggers and master passwords, and how to verify them.
/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)
rc.local, SysV init.d and MOTD Scripts: Linux Boot Hooks
Legacy Linux boot and login script locations (rc.local, /etc/init.d, rc?.d links, Upstart jobs, update-motd.d) and how they reveal persistence.
/etc/rc.local
Shell Startup Files: Linux bashrc and profile Persistence
System and per-user shell startup files (profile, bashrc, zshrc, logout) on Linux: load order, where attackers hide persistence and how to review them.
/etc/profile.d/
SSH Artifacts: authorized_keys, known_hosts and sshd Logs
OpenSSH artifacts on Linux (authorized_keys, known_hosts, configs, host keys, sshd logs) that prove remote access, key persistence and lateral movement.
~/.ssh/authorized_keys
SUID, SGID and File Capabilities: Linux Privilege Backdoors
SUID/SGID bits and file capabilities (security.capability) on Linux: how attackers plant root backdoors and how to baseline them against packages.
Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system
sysctl, Boot Parameters and binfmt_misc on Linux
Linux kernel settings in sysctl.d, /proc/sys and the boot command line: core_pattern and modprobe hijacks, weakened protections, ip_forward, binfmt_misc.
/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/
systemd Unit Files: Linux Service Persistence
systemd service, timer and drop-in files, enablement symlinks, generators and user lingering: where Linux services are defined and how they reveal persistence.
/etc/systemd/system/
Web Shells in the Web Root: Finding Them on Linux Servers
Where Linux web roots live per distro, how PHP, JSP and CGI web shells and .htaccess or module backdoors look on disk, and how to date and hunt them.
/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps
XDG Autostart .desktop Entries: Linux Desktop Persistence
XDG autostart entries in /etc/xdg/autostart and ~/.config/autostart that launch programs at every graphical login, plus KDE and X session hooks.
~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop
File access
ext4 Timestamps, crtime and Deleted Files
ext4 inode timestamps (atime, mtime, ctime, crtime, dtime) with nanoseconds, relatime, the jbd2 journal and what deleted-file recovery can still do.
/dev/<ext4-partition>
Linux Thumbnail Cache: ~/.cache/thumbnails Forensics
The freedesktop thumbnail cache on Linux: PNG previews named by the MD5 of the file URI, holding path and mtime, that outlive deleted files.
~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/
Linux Trash: freedesktop .trashinfo Files and Deleted Items
The freedesktop.org Trash on Linux desktops: .trashinfo records with original path and deletion time, the trashed files themselves and per-volume trash folders.
~/.local/share/Trash/{files,info}/
recently-used.xbel: GNOME and GTK Recent Files on Linux
The freedesktop recently-used.xbel file on Linux desktops: which files and URIs a user opened through GTK (and newer KDE) applications, with UTC times.
~/.local/share/recently-used.xbel
Tracker / LocalSearch DB: GNOME File Index on Linux
GNOME's Tracker and LocalSearch file index on Linux: SQLite databases listing indexed files, their timestamps and extracted content for a user's home.
~/.cache/tracker3/files/
viminfo, ShaDa and lesshst: Linux Editor and Pager History
Vim viminfo, Neovim ShaDa and less history files on Linux: which files a user edited, what they searched for and typed, often after shell history is wiped.
~/.viminfo
XFS Forensics: Inode Timestamps, crtime and Deleted Files
XFS on RHEL-family Linux: v5 inode timestamps with crtime, bigtime, xfs_db inspection, the metadata log, and what remains after a file is deleted.
/dev/<xfs-volume>
User activity
Browser Profiles on Linux: Firefox and Chrome History
Firefox and Chrome/Chromium profile databases on Linux, including snap and Flatpak paths: history, downloads, epochs and how to query them offline.
~/.mozilla/firefox/<profile>/places.sqlite
wtmp, btmp, utmp and lastlog: Linux Login Records
Binary Linux login records: wtmp session history, btmp failed logins, utmp live sessions, lastlog per-UID last login, and their wtmpdb/lastlog2 successors.
/var/log/wtmp
Network
/etc/hosts, nsswitch.conf and resolv.conf on Linux
Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.
/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory
Linux Firewall Logs: iptables, nftables, ufw, firewalld
Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.
/var/log/ufw.log, /var/log/kern.log
NetworkManager Profiles and State: Linux Network History
NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.
/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/
USB & devices
udev and USB Device History on Linux
Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.
/etc/udev/rules.d/, /var/log/kern.log
Anti-forensics
logrotate State and Log Gaps: Detecting Linux Log Tampering
logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.
/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)
Logs
Apache and Nginx Logs: Linux Web Server Forensics
Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.
/var/log/apache2/, /var/log/httpd/, /var/log/nginx/
AppArmor and SELinux Denials: Linux MAC Audit Logs
SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.
/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal
auditd audit.log: Linux Kernel Audit Trail
The Linux audit log written by auditd: PAM logins, syscalls, execve arguments and watched file access, each tied to the original login user (auid).
/var/log/audit/audit.log
auth.log, secure and syslog: Linux Text Logs
rsyslog text logs on Linux: auth.log and syslog on Debian/Ubuntu, secure and messages on RHEL, with rotation and timestamp format pitfalls.
/var/log/auth.log, /var/log/secure
cloud-init Logs and Instance Data: Linux Cloud VM Forensics
cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.
/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/
dmesg, kern.log and the Kernel Ring Buffer on Linux
The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.
/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)
dpkg, APT, RPM and DNF Logs: Linux Package History
Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.
/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log
MySQL, MariaDB and PostgreSQL Logs: Linux Database Forensics
Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.
/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)
systemd Journal: Linux Binary System Log
The systemd-journald binary log: structured entries with trusted process fields and microsecond UTC timestamps, often the only system log on modern Linux hosts.
/var/log/journal/<machine-id>/