Skip to content

Linux artifacts cheat sheet

Every artifact on one table, grouped by category. Use your browser's print dialog (landscape) or save it as a PDF.

ArtifactLocationProvesTimestampsAccessRetentionParsers
Execution
/proc Live ArtifactsDebian · RHEL · SUSE · Arch/proc/<pid>/What is running right now, from which binary, with which arguments, files and network connectionsNo file timestamps of value; process start time in clock ticks since boot (/proc/<pid>/stat field 22)root to see every process's exe, environ, fd and maps; other users see only their ownVolatile: gone at process exit or rebootps, ss, lsof, Velociraptor, Volatility 3
/tmp, /var/tmp and /dev/shmDebian · RHEL · SUSE · Arch/tmp, /var/tmp, /dev/shm, /run/user/<uid>That files were dropped or run from world-writable locations, by which user and whenInode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM onlyAny user can write; root needed to read other users' files (mode 1777 with sticky bit)tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deletedfind, stat, debugfs, The Sleuth Kit, Velociraptor
Docker, containerd and Podman Artifacts on Linux HostsDebian · RHEL · SUSE · Arch/var/lib/docker/containers/<id>/Which containers ran, from which image and command, with which privileges, what they printed and which files they changedRFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layersroot (or docker group, which is root-equivalent); rootless Podman data is owned by the userUntil the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file setcontainer-explorer, jq, docker, crictl, ctr
Linux Crash Reports and Core DumpsDebian · RHEL · SUSE · Arch/var/lib/systemd/coredump/, /var/crash/Which program crashed, when, as which user, with which command line, and what its memory held at that momentJournal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctimeroot; per-user cores readable by the owning user through coredumpctlsystemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 dayscoredumpctl, gdb, getfattr, apport-unpack, crash
Linux Memory AcquisitionDebian · RHEL · SUSE · Arch/proc/kcore, /dev/crash, /dev/memRunning processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not showCapture time from your case log; in-memory structures carry their own times (process start as time since boot)root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEMVolatile: lost at power-off; changes continuously while the host runsVolatility 3, dwarf2json, AVML, LiME
Shell HistoryDebian · RHEL · SUSE · Arch~/.bash_historyWhich commands were typed in an interactive shell running as a given account, and sometimes whenUnix epoch seconds (UTC) when recorded: bash only with HISTTIMEFORMAT, zsh with EXTENDED_HISTORY, fish alwaysAny user for own files; root for other users' homesUntil truncated by HISTFILESIZE/SAVEHIST or deletedPlaso, Volatility 3, Velociraptor
Snap and Flatpak ArtifactsDebian · RHEL · SUSE · Arch/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user dataRFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file timesroot for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each userInstalled apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journalsnap, flatpak, jq, journalctl, find
sudo LogsDebian · RHEL · SUSE · Arch/var/log/auth.log, /var/log/secureWhich account ran which command as which target user, from which terminal and directory, and failed attemptsSyslog/journal time of the host (see syslog formats); I/O logs keep relative timing per sessionroot (or adm group for auth.log on Debian/Ubuntu)Follows auth.log/secure rotation and journal limits; I/O logs until deletedgrep/zgrep, journalctl, sudoreplay, ausearch, Plaso
Persistence
/etc/ld.so.preload and LD_PRELOADDebian · RHEL · SUSE · Arch/etc/ld.so.preloadWhether a shared library was forced into dynamically linked processes, which one, and since whenFile mtime/ctime/crtime of the preload file and the library; no internal timestampsroot to write; world-readable; may be hidden from live tools by the rootkit itselfUntil deleted; LD_PRELOAD in process environments lasts until the process exitsdebugfs, UAC, Volatility 3, Velociraptor
/etc/passwd, shadow and groupDebian · RHEL · SUSE · Arch/etc/passwd, /etc/shadow, /etc/group, /etc/gshadowWhich local accounts and group memberships exist, which can log in, and when each password was last changedshadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal timepasswd and group: any user; shadow and gshadow: rootUntil changed; one backup generation (passwd-, shadow-, group-, gshadow-)awk, pwck -r, grpck -r, Velociraptor, ausearch
Cron, Anacron, at and systemd TimersDebian · RHEL · SUSE · Arch/var/spool/cron/Which commands were scheduled to run, by which account, and when cron, anacron or a timer last fired themFile mtime/ctime; syslog or journal time for runs; anacron stamps as YYYYMMDD local dateroot for all spool directories; any user for their own crontab via crontab -lUntil deleted; execution evidence follows syslog/journal rotationVelociraptor, UAC, grep, systemctl
eBPF Programs and Pinned MapsDebian · RHEL · SUSE · ArchKernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on diskWhich eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores thembpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file timesroot (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks othersPrograms live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on diskbpftool, Volatility 3, ss, ausearch, readelf, find
Linux Kernel ModulesDebian · RHEL · SUSE · Arch/proc/modulesWhich kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernelKernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file timesroot; kernel addresses in /proc/modules are zeroed for unprivileged readersLoaded state and taint until reboot; config files until deleted; log lines per journal/syslog limitsVolatility 3, modinfo, Velociraptor, UAC
PAM Configuration and ModulesDebian · RHEL · SUSE · Arch/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentialsFile system times of stack files and modules; PAM messages in auth logs and the journalroot to modify; configuration world-readable, modules readable by allPersistent until changed; package updates may overwrite a patched modulerpm, dpkg, debsums, authselect, find, grep / zgrep, strings
rc.local, SysV init.d and MOTD ScriptsDebian · RHEL/etc/rc.localWhether a script was set to run as root at boot or at every login, and when it was placed thereFile mtime/ctime/crtime only; execution times from journal or syslogroot to write; world-readable on most systemsUntil deleted; execution evidence follows journal/syslog rotationUAC, Velociraptor, grep, journalctl
Shell Startup FilesDebian · RHEL · SUSE · Arch/etc/profile.d/Whether code was set to run automatically each time a user or root starts or ends a shell sessionNone inside the files; use inode mtime/ctime/crtime (ext4, XFS v5)root for /etc files; any user for own dotfiles; root to read other users' homesUntil modified or deleted; package upgrades may replace /etc defaultsVelociraptor, debsums, rpm -V
SSH ArtifactsDebian · RHEL · SUSE · Arch~/.ssh/authorized_keysWhich keys can log in to an account, where a user connected to, and who logged in over SSH from whereKey files: file system times only; logs: syslog local time or journal usec since Unix epoch (UTC)root (or the account owner for its own ~/.ssh); adm/systemd-journal group for logsKey files until deleted; log lines follow syslog rotation and journal limitsssh-keygen, Velociraptor, UAC, grep
SUID, SGID and File CapabilitiesDebian · RHEL · SUSE · ArchInode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file systemWhich executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package managerSetting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or installReadable by any user with stat/getcap; root to setPersistent until the file is replaced or the bit removed; package updates reset package-owned filesfind, getcap, getfattr, stat, rpm, dpkg, debsums
sysctl, Boot Parameters and binfmt_misc on LinuxDebian · RHEL · SUSE · Arch/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker codeFile system times of configuration files only; live values carry no timestamproot to change; most values world-readable in /proc/sysFiles persist; runtime changes via sysctl -w or /proc/sys writes are lost at rebootsysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg
systemd Unit FilesDebian · RHEL · SUSE · Arch/etc/systemd/system/Which services and timers are configured to start, what they execute, and when the unit was installed or changedFile mtime/ctime/crtime; journal entries in microseconds since Unix epoch (UTC)root for system units; any user for their own ~/.config/systemd/userUntil deleted; /run units are lost at reboot; start/stop events follow journal limitssystemctl, systemd-analyze, Velociraptor, UAC
Web Shells in the Web RootDebian · RHEL · SUSE · Arch/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webappsThat a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can doFile system times (birth time on ext4/XFS v5 dates the drop); first request time in access logsRead as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or httpUntil deleted; deployments and CMS updates may overwrite or remove filesfind, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg
XDG Autostart .desktop EntriesDebian · RHEL · SUSE · Arch~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktopWhich programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was writtenFile system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessionsAny user for their own entries; root for /etc/xdg/autostartUntil the .desktop file is deleted; launch records follow journal retentionfind, grep / zgrep, journalctl, systemctl, rpm, dpkg
File access
ext4 Timestamps, crtime and Deleted FilesDebian · Arch/dev/<ext4-partition>When a file was created, modified, changed and possibly read or deleted, and sometimes what it containedUnix epoch seconds UTC plus nanoseconds in *_extra fields (256-byte inodes); i_dtime in secondsAny user for stat on accessible files; root or raw device access for debugfs and deleted inodesTimestamps until overwritten; deleted inodes and blocks until reused; journal is a small circular logdebugfs, The Sleuth Kit, Plaso, ext4magic, stat
Linux Thumbnail CacheDebian · RHEL · SUSE · Arch~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked likeThumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generatedAny user for their own cache (mode 0700 directories, 0600 files); root for other usersUntil the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by defaultExifTool, find, stat
Linux TrashDebian · RHEL · SUSE · Arch~/.local/share/Trash/{files,info}/Which file or folder a user sent to the Trash through a desktop application, from which original path, and whenDeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo fileAny user for their own Trash (directories mode 0700); root for other usersUntil the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled)gio, trash-cli, find, stat
recently-used.xbelDebian · RHEL · SUSE · Arch~/.local/share/recently-used.xbelWhich local or remote files a desktop user opened or saved through GUI applications, with which app and whenISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix secondsAny user for own file (GTK sets mode 0600); root for other usersGTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by defaultxmllint, Python ElementTree
Tracker / LocalSearch DBDebian · RHEL · SUSE · Arch~/.cache/tracker3/files/Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexerUnix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be keptAny user for own cache; root for other usersMirrors the indexed tree; entries removed when the indexer processes a deletiontinysparql, sqlite3, localsearch
viminfo, ShaDa and lesshstDebian · RHEL · SUSE · Arch~/.viminfoWhich files a user opened in vim or Neovim, and what they searched for or ran inside vim and lessUnix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshstAny user for own files (created mode 0600); root for other usersUntil deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100)Plaso, Neovim, python-msgpack
XFS ForensicsRHEL · SUSE/dev/<xfs-volume>When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files containedSeconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystemsAny user for stat on accessible files; root or raw device access for xfs_dbTimestamps until overwritten; deleted inode extents and data blocks until reusedxfs_db, stat, libfsxfs, Plaso
User activity
Browser Profiles on LinuxDebian · RHEL · SUSE · Arch~/.mozilla/firefox/<profile>/places.sqliteWhich sites a user visited, what they downloaded and searched for, and whenFirefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC)Any user for own profile; root for other usersChrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pagesHindsight, Plaso, sqlite3
wtmp, btmp, utmp and lastlogDebian · RHEL · SUSE · Arch/var/log/wtmpWho logged in, on which terminal, from which host, when the session ended, and when the system rebootedutmp records: Unix epoch seconds + microseconds (32-bit fields), UTC. wtmpdb: microseconds since epochReadable by all for wtmp/utmp/lastlog; root (or utmp group) for btmplogrotate: monthly, 1 old generation for wtmp and btmp; lastlog until overwrittenlast, lastb, utmpdump, wtmpdb, Plaso, Velociraptor
Network
/etc/hosts, nsswitch.conf and resolv.conf on LinuxDebian · RHEL · SUSE · Arch/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directoryWhere the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookupsFile system times only; systemd-resolved and NetworkManager log DNS server changes to the journalWorld-readable; root to modifyPersistent until edited; generated resolv.conf files are rewritten by the network stackgetent, resolvectl, grep / zgrep, rpm, dpkg, journalctl
Linux Firewall LogsDebian · RHEL · SUSE · Arch/var/log/ufw.log, /var/log/kern.logWhich connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changedSyslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system timesroot (or adm group for /var/log files on Debian/Ubuntu)Follows syslog rotation and journal limits; rule files until changedgrep/zgrep, journalctl, nft, iptables-save, Plaso
NetworkManager Profiles and StateDebian · RHEL · SUSE · Arch/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leasedUnix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode timesroot (profiles are root-only 0600); journal: root or systemd-journal groupProfiles until deleted; state files overwritten in place; journal per its limitsgrep, journalctl, nmcli (live), Plaso
USB & devices
udev and USB Device History on LinuxDebian · RHEL · SUSE · Arch/etc/udev/rules.d/, /var/log/kern.logWhich USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run codeJournal: UTC microseconds; syslog: host local time; dmesg: seconds since bootroot (or adm/systemd-journal group) for logs; rules readable by any userFollows journal and kern.log/messages rotation; rules until deletedjournalctl, zgrep, udevadm, Plaso
Anti-forensics
logrotate State and Log GapsDebian · RHEL · SUSE · Arch/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tamperingState file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixesrootConfiguration persistent; the state file is rewritten at every run and keeps one line per loglogrotate, stat, find, grep / zgrep, journalctl, systemctl
Logs
Apache and Nginx LogsDebian · RHEL/var/log/apache2/, /var/log/httpd/, /var/log/nginx/Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell useLocal time with numeric UTC offset, second precision (default combined format)root or adm group (Debian/Ubuntu); root (RHEL)Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 keptgrep/zgrep, awk, GoAccess, lnav, Plaso
AppArmor and SELinux DenialsDebian · RHEL · SUSE/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journalWhich confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched offmsg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal timeroot (audit.log mode 0600; kernel log readable by adm or root depending on distro)Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retentionausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep
auditd audit.logDebian · RHEL · SUSE/var/log/audit/audit.logWhich login user ran which program or touched which watched file, and every PAM authentication and sessionUnix epoch seconds with milliseconds in msg=audit(sec.msec:serial), UTCroot (log_group defaults to root)Size based: upstream default 8 MiB x 5 files, rotated by auditdausearch, aureport, Plaso, Zircolite
auth.log, secure and syslogDebian · RHEL/var/log/auth.log, /var/log/secureWho authenticated, from where, with which method, and what services and the kernel reported, in plain textTraditional: local time, no year or zone. RFC 3339: local time with offset and microsecondsroot or adm group (Debian/Ubuntu); root (RHEL)logrotate: weekly, 4 generations on Debian/Ubuntu and RHEL defaultsgrep/zgrep, Plaso, lnav
cloud-init Logs and Instance DataDebian · RHEL · SUSE/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts runLog lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished contentroot for user-data and sensitive instance data; logs usually root-readable only or adm groupLogs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at rebootcloud-init, jq, grep / zgrep, journalctl
dmesg, kern.log and the Kernel Ring Buffer on LinuxDebian · RHEL · SUSE · Arch/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warningsRing buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTCRing buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm groupRing buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by sizedmesg, journalctl, grep / zgrep
dpkg, APT, RPM and DNF LogsDebian · RHEL/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.logWhich packages were installed, upgraded or removed, when, with which command line and by which sudo userdpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC)dpkg.log and apt/history.log are world-readable; root for complete collectiondpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removedzgrep, sqlite3, rpm --root, dpkg --root, Plaso
MySQL, MariaDB and PostgreSQL LogsDebian · RHEL/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the databaseMySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix secondsroot or the mysql/postgres service account; client history files owned by each userError logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by defaultmysqlbinlog, pgBadger, grep / zgrep, journalctl
systemd JournalDebian · RHEL · SUSE · Arch/var/log/journal/<machine-id>/What services, processes, users and the kernel logged, with trusted PID/UID/executable and boot contextMicroseconds since Unix epoch (UTC) for realtime; microseconds since boot for monotonicroot (or systemd-journal, adm or wheel group); users can read their own user-UID journalSize based: 10% of the file system capped at 4G by default; volatile copy lost at rebootjournalctl, Plaso, Velociraptor