Linux artifacts cheat sheet
Every artifact on one table, grouped by category. Use your browser's print dialog (landscape) or save it as a PDF.
www.linuxforensics.app/en/artifacts
| Artifact | Location | Proves | Timestamps | Access | Retention | Parsers |
|---|---|---|---|---|---|---|
| Execution | ||||||
| /proc Live ArtifactsDebian · RHEL · SUSE · Arch | /proc/<pid>/ | What is running right now, from which binary, with which arguments, files and network connections | No file timestamps of value; process start time in clock ticks since boot (/proc/<pid>/stat field 22) | root to see every process's exe, environ, fd and maps; other users see only their own | Volatile: gone at process exit or reboot | ps, ss, lsof, Velociraptor, Volatility 3 |
| /tmp, /var/tmp and /dev/shmDebian · RHEL · SUSE · Arch | /tmp, /var/tmp, /dev/shm, /run/user/<uid> | That files were dropped or run from world-writable locations, by which user and when | Inode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM only | Any user can write; root needed to read other users' files (mode 1777 with sticky bit) | tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deleted | find, stat, debugfs, The Sleuth Kit, Velociraptor |
| Docker, containerd and Podman Artifacts on Linux HostsDebian · RHEL · SUSE · Arch | /var/lib/docker/containers/<id>/ | Which containers ran, from which image and command, with which privileges, what they printed and which files they changed | RFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layers | root (or docker group, which is root-equivalent); rootless Podman data is owned by the user | Until the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file set | container-explorer, jq, docker, crictl, ctr |
| Linux Crash Reports and Core DumpsDebian · RHEL · SUSE · Arch | /var/lib/systemd/coredump/, /var/crash/ | Which program crashed, when, as which user, with which command line, and what its memory held at that moment | Journal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctime | root; per-user cores readable by the owning user through coredumpctl | systemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 days | coredumpctl, gdb, getfattr, apport-unpack, crash |
| Linux Memory AcquisitionDebian · RHEL · SUSE · Arch | /proc/kcore, /dev/crash, /dev/mem | Running processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not show | Capture time from your case log; in-memory structures carry their own times (process start as time since boot) | root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEM | Volatile: lost at power-off; changes continuously while the host runs | Volatility 3, dwarf2json, AVML, LiME |
| Shell HistoryDebian · RHEL · SUSE · Arch | ~/.bash_history | Which commands were typed in an interactive shell running as a given account, and sometimes when | Unix epoch seconds (UTC) when recorded: bash only with HISTTIMEFORMAT, zsh with EXTENDED_HISTORY, fish always | Any user for own files; root for other users' homes | Until truncated by HISTFILESIZE/SAVEHIST or deleted | Plaso, Volatility 3, Velociraptor |
| Snap and Flatpak ArtifactsDebian · RHEL · SUSE · Arch | /var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/ | Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user data | RFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file times | root for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each user | Installed apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journal | snap, flatpak, jq, journalctl, find |
| sudo LogsDebian · RHEL · SUSE · Arch | /var/log/auth.log, /var/log/secure | Which account ran which command as which target user, from which terminal and directory, and failed attempts | Syslog/journal time of the host (see syslog formats); I/O logs keep relative timing per session | root (or adm group for auth.log on Debian/Ubuntu) | Follows auth.log/secure rotation and journal limits; I/O logs until deleted | grep/zgrep, journalctl, sudoreplay, ausearch, Plaso |
| Persistence | ||||||
| /etc/ld.so.preload and LD_PRELOADDebian · RHEL · SUSE · Arch | /etc/ld.so.preload | Whether a shared library was forced into dynamically linked processes, which one, and since when | File mtime/ctime/crtime of the preload file and the library; no internal timestamps | root to write; world-readable; may be hidden from live tools by the rootkit itself | Until deleted; LD_PRELOAD in process environments lasts until the process exits | debugfs, UAC, Volatility 3, Velociraptor |
| /etc/passwd, shadow and groupDebian · RHEL · SUSE · Arch | /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow | Which local accounts and group memberships exist, which can log in, and when each password was last changed | shadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal time | passwd and group: any user; shadow and gshadow: root | Until changed; one backup generation (passwd-, shadow-, group-, gshadow-) | awk, pwck -r, grpck -r, Velociraptor, ausearch |
| Cron, Anacron, at and systemd TimersDebian · RHEL · SUSE · Arch | /var/spool/cron/ | Which commands were scheduled to run, by which account, and when cron, anacron or a timer last fired them | File mtime/ctime; syslog or journal time for runs; anacron stamps as YYYYMMDD local date | root for all spool directories; any user for their own crontab via crontab -l | Until deleted; execution evidence follows syslog/journal rotation | Velociraptor, UAC, grep, systemctl |
| eBPF Programs and Pinned MapsDebian · RHEL · SUSE · Arch | Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk | Which eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores them | bpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file times | root (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks others | Programs live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on disk | bpftool, Volatility 3, ss, ausearch, readelf, find |
| Linux Kernel ModulesDebian · RHEL · SUSE · Arch | /proc/modules | Which kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernel | Kernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file times | root; kernel addresses in /proc/modules are zeroed for unprivileged readers | Loaded state and taint until reboot; config files until deleted; log lines per journal/syslog limits | Volatility 3, modinfo, Velociraptor, UAC |
| PAM Configuration and ModulesDebian · RHEL · SUSE · Arch | /etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch) | How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentials | File system times of stack files and modules; PAM messages in auth logs and the journal | root to modify; configuration world-readable, modules readable by all | Persistent until changed; package updates may overwrite a patched module | rpm, dpkg, debsums, authselect, find, grep / zgrep, strings |
| rc.local, SysV init.d and MOTD ScriptsDebian · RHEL | /etc/rc.local | Whether a script was set to run as root at boot or at every login, and when it was placed there | File mtime/ctime/crtime only; execution times from journal or syslog | root to write; world-readable on most systems | Until deleted; execution evidence follows journal/syslog rotation | UAC, Velociraptor, grep, journalctl |
| Shell Startup FilesDebian · RHEL · SUSE · Arch | /etc/profile.d/ | Whether code was set to run automatically each time a user or root starts or ends a shell session | None inside the files; use inode mtime/ctime/crtime (ext4, XFS v5) | root for /etc files; any user for own dotfiles; root to read other users' homes | Until modified or deleted; package upgrades may replace /etc defaults | Velociraptor, debsums, rpm -V |
| SSH ArtifactsDebian · RHEL · SUSE · Arch | ~/.ssh/authorized_keys | Which keys can log in to an account, where a user connected to, and who logged in over SSH from where | Key files: file system times only; logs: syslog local time or journal usec since Unix epoch (UTC) | root (or the account owner for its own ~/.ssh); adm/systemd-journal group for logs | Key files until deleted; log lines follow syslog rotation and journal limits | ssh-keygen, Velociraptor, UAC, grep |
| SUID, SGID and File CapabilitiesDebian · RHEL · SUSE · Arch | Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system | Which executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package manager | Setting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or install | Readable by any user with stat/getcap; root to set | Persistent until the file is replaced or the bit removed; package updates reset package-owned files | find, getcap, getfattr, stat, rpm, dpkg, debsums |
| sysctl, Boot Parameters and binfmt_misc on LinuxDebian · RHEL · SUSE · Arch | /etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/ | Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker code | File system times of configuration files only; live values carry no timestamp | root to change; most values world-readable in /proc/sys | Files persist; runtime changes via sysctl -w or /proc/sys writes are lost at reboot | sysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg |
| systemd Unit FilesDebian · RHEL · SUSE · Arch | /etc/systemd/system/ | Which services and timers are configured to start, what they execute, and when the unit was installed or changed | File mtime/ctime/crtime; journal entries in microseconds since Unix epoch (UTC) | root for system units; any user for their own ~/.config/systemd/user | Until deleted; /run units are lost at reboot; start/stop events follow journal limits | systemctl, systemd-analyze, Velociraptor, UAC |
| Web Shells in the Web RootDebian · RHEL · SUSE · Arch | /var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps | That a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can do | File system times (birth time on ext4/XFS v5 dates the drop); first request time in access logs | Read as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or http | Until deleted; deployments and CMS updates may overwrite or remove files | find, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg |
| XDG Autostart .desktop EntriesDebian · RHEL · SUSE · Arch | ~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop | Which programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was written | File system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessions | Any user for their own entries; root for /etc/xdg/autostart | Until the .desktop file is deleted; launch records follow journal retention | find, grep / zgrep, journalctl, systemctl, rpm, dpkg |
| File access | ||||||
| ext4 Timestamps, crtime and Deleted FilesDebian · Arch | /dev/<ext4-partition> | When a file was created, modified, changed and possibly read or deleted, and sometimes what it contained | Unix epoch seconds UTC plus nanoseconds in *_extra fields (256-byte inodes); i_dtime in seconds | Any user for stat on accessible files; root or raw device access for debugfs and deleted inodes | Timestamps until overwritten; deleted inodes and blocks until reused; journal is a small circular log | debugfs, The Sleuth Kit, Plaso, ext4magic, stat |
| Linux Thumbnail CacheDebian · RHEL · SUSE · Arch | ~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/ | That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked like | Thumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generated | Any user for their own cache (mode 0700 directories, 0600 files); root for other users | Until the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by default | ExifTool, find, stat |
| Linux TrashDebian · RHEL · SUSE · Arch | ~/.local/share/Trash/{files,info}/ | Which file or folder a user sent to the Trash through a desktop application, from which original path, and when | DeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo file | Any user for their own Trash (directories mode 0700); root for other users | Until the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled) | gio, trash-cli, find, stat |
| recently-used.xbelDebian · RHEL · SUSE · Arch | ~/.local/share/recently-used.xbel | Which local or remote files a desktop user opened or saved through GUI applications, with which app and when | ISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix seconds | Any user for own file (GTK sets mode 0600); root for other users | GTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by default | xmllint, Python ElementTree |
| Tracker / LocalSearch DBDebian · RHEL · SUSE · Arch | ~/.cache/tracker3/files/ | Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexer | Unix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be kept | Any user for own cache; root for other users | Mirrors the indexed tree; entries removed when the indexer processes a deletion | tinysparql, sqlite3, localsearch |
| viminfo, ShaDa and lesshstDebian · RHEL · SUSE · Arch | ~/.viminfo | Which files a user opened in vim or Neovim, and what they searched for or ran inside vim and less | Unix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshst | Any user for own files (created mode 0600); root for other users | Until deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100) | Plaso, Neovim, python-msgpack |
| XFS ForensicsRHEL · SUSE | /dev/<xfs-volume> | When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files contained | Seconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystems | Any user for stat on accessible files; root or raw device access for xfs_db | Timestamps until overwritten; deleted inode extents and data blocks until reused | xfs_db, stat, libfsxfs, Plaso |
| User activity | ||||||
| Browser Profiles on LinuxDebian · RHEL · SUSE · Arch | ~/.mozilla/firefox/<profile>/places.sqlite | Which sites a user visited, what they downloaded and searched for, and when | Firefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC) | Any user for own profile; root for other users | Chrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pages | Hindsight, Plaso, sqlite3 |
| wtmp, btmp, utmp and lastlogDebian · RHEL · SUSE · Arch | /var/log/wtmp | Who logged in, on which terminal, from which host, when the session ended, and when the system rebooted | utmp records: Unix epoch seconds + microseconds (32-bit fields), UTC. wtmpdb: microseconds since epoch | Readable by all for wtmp/utmp/lastlog; root (or utmp group) for btmp | logrotate: monthly, 1 old generation for wtmp and btmp; lastlog until overwritten | last, lastb, utmpdump, wtmpdb, Plaso, Velociraptor |
| Network | ||||||
| /etc/hosts, nsswitch.conf and resolv.conf on LinuxDebian · RHEL · SUSE · Arch | /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory | Where the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookups | File system times only; systemd-resolved and NetworkManager log DNS server changes to the journal | World-readable; root to modify | Persistent until edited; generated resolv.conf files are rewritten by the network stack | getent, resolvectl, grep / zgrep, rpm, dpkg, journalctl |
| Linux Firewall LogsDebian · RHEL · SUSE · Arch | /var/log/ufw.log, /var/log/kern.log | Which connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changed | Syslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system times | root (or adm group for /var/log files on Debian/Ubuntu) | Follows syslog rotation and journal limits; rule files until changed | grep/zgrep, journalctl, nft, iptables-save, Plaso |
| NetworkManager Profiles and StateDebian · RHEL · SUSE · Arch | /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/ | Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leased | Unix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode times | root (profiles are root-only 0600); journal: root or systemd-journal group | Profiles until deleted; state files overwritten in place; journal per its limits | grep, journalctl, nmcli (live), Plaso |
| USB & devices | ||||||
| udev and USB Device History on LinuxDebian · RHEL · SUSE · Arch | /etc/udev/rules.d/, /var/log/kern.log | Which USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run code | Journal: UTC microseconds; syslog: host local time; dmesg: seconds since boot | root (or adm/systemd-journal group) for logs; rules readable by any user | Follows journal and kern.log/messages rotation; rules until deleted | journalctl, zgrep, udevadm, Plaso |
| Anti-forensics | ||||||
| logrotate State and Log GapsDebian · RHEL · SUSE · Arch | /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL) | When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tampering | State file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixes | root | Configuration persistent; the state file is rewritten at every run and keeps one line per log | logrotate, stat, find, grep / zgrep, journalctl, systemctl |
| Logs | ||||||
| Apache and Nginx LogsDebian · RHEL | /var/log/apache2/, /var/log/httpd/, /var/log/nginx/ | Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell use | Local time with numeric UTC offset, second precision (default combined format) | root or adm group (Debian/Ubuntu); root (RHEL) | Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 kept | grep/zgrep, awk, GoAccess, lnav, Plaso |
| AppArmor and SELinux DenialsDebian · RHEL · SUSE | /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal | Which confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched off | msg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal time | root (audit.log mode 0600; kernel log readable by adm or root depending on distro) | Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retention | ausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep |
| auditd audit.logDebian · RHEL · SUSE | /var/log/audit/audit.log | Which login user ran which program or touched which watched file, and every PAM authentication and session | Unix epoch seconds with milliseconds in msg=audit(sec.msec:serial), UTC | root (log_group defaults to root) | Size based: upstream default 8 MiB x 5 files, rotated by auditd | ausearch, aureport, Plaso, Zircolite |
| auth.log, secure and syslogDebian · RHEL | /var/log/auth.log, /var/log/secure | Who authenticated, from where, with which method, and what services and the kernel reported, in plain text | Traditional: local time, no year or zone. RFC 3339: local time with offset and microseconds | root or adm group (Debian/Ubuntu); root (RHEL) | logrotate: weekly, 4 generations on Debian/Ubuntu and RHEL defaults | grep/zgrep, Plaso, lnav |
| cloud-init Logs and Instance DataDebian · RHEL · SUSE | /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/ | How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts run | Log lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished content | root for user-data and sensitive instance data; logs usually root-readable only or adm group | Logs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at reboot | cloud-init, jq, grep / zgrep, journalctl |
| dmesg, kern.log and the Kernel Ring Buffer on LinuxDebian · RHEL · SUSE · Arch | /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k) | Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warnings | Ring buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTC | Ring buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm group | Ring buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by size | dmesg, journalctl, grep / zgrep |
| dpkg, APT, RPM and DNF LogsDebian · RHEL | /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log | Which packages were installed, upgraded or removed, when, with which command line and by which sudo user | dpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC) | dpkg.log and apt/history.log are world-readable; root for complete collection | dpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removed | zgrep, sqlite3, rpm --root, dpkg --root, Plaso |
| MySQL, MariaDB and PostgreSQL LogsDebian · RHEL | /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL) | Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the database | MySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix seconds | root or the mysql/postgres service account; client history files owned by each user | Error logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by default | mysqlbinlog, pgBadger, grep / zgrep, journalctl |
| systemd JournalDebian · RHEL · SUSE · Arch | /var/log/journal/<machine-id>/ | What services, processes, users and the kernel logged, with trusted PID/UID/executable and boot context | Microseconds since Unix epoch (UTC) for realtime; microseconds since boot for monotonic | root (or systemd-journal, adm or wheel group); users can read their own user-UID journal | Size based: 10% of the file system capped at 4G by default; volatile copy lost at reboot | journalctl, Plaso, Velociraptor |