Skip to content

NetworkUser activityPersistence

NetworkManager Profiles and State: Linux Network History

NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.

Location
/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/
Proves
Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leased
Timestamps
Unix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode times
Access
root (profiles are root-only 0600); journal: root or systemd-journal group
Retention
Profiles until deleted; state files overwritten in place; journal per its limits
Collection
UAC, Velociraptor, cp -a, journalctl
  • grep / zgrepCLI · built into Linux
  • journalctlCLI · built into Linux
  • nmcliCLI · built into Linux
  • PlasoCLI · open source

What it is

NetworkManager is the default network configuration service on Ubuntu Desktop, Fedora, RHEL 8 and later and most desktop distributions. It stores each network the machine is configured for as a connection profile and keeps small state databases of its own: when each profile was last active, which Wi-Fi access points (BSSIDs) were seen for it, and the last DHCP lease per interface. Its log messages in the journal narrate every activation, DHCP lease and disconnect.

For a laptop this is location and network history: home and office SSIDs, hotel Wi-Fi, phone hotspots, VPN profiles. For a server it shows added interfaces, VPN tunnels or static routes, and dispatcher scripts that run as root on network events.

Where it lives

ItemPathDistro notes
Connection profiles (keyfile)/etc/NetworkManager/system-connections/*.nmconnectionDefault format everywhere; RHEL 9 writes new profiles here
Vendor/runtime profiles/usr/lib/NetworkManager/system-connections/, /run/NetworkManager/system-connections//run is volatile
Legacy ifcfg profiles/etc/sysconfig/network-scripts/ifcfg-*RHEL 7/8 and upgraded RHEL 9 hosts (deprecated in RHEL 9)
Netplan-backed profiles/etc/netplan/90-NM-<uuid>.yamlUbuntu 23.10 and later: NetworkManager saves profiles through Netplan and generates ephemeral copies in /run/NetworkManager/system-connections/
Last activation times/var/lib/NetworkManager/timestampsKeyed by profile UUID
Seen access points/var/lib/NetworkManager/seen-bssidsKeyed by profile UUID
DHCP leases/var/lib/NetworkManager/internal-<uuid>-<iface>.lease, dhclient-<uuid>-<iface>.leaseInternal client (default) vs dhclient plugin; ...6- prefix for DHCPv6
Daemon config/etc/NetworkManager/NetworkManager.conf, conf.d/
Dispatcher scripts/etc/NetworkManager/dispatcher.d/ (and pre-up.d, pre-down.d, no-wait.d), /usr/lib/NetworkManager/dispatcher.d/Run as root on events
Related host config/etc/hosts, /etc/resolv.conf, /etc/network/interfaces (Debian ifupdown)

What it proves

  • Every network the host was configured to join: SSID, security type, bound interface or MAC, static addresses, DNS servers, VPN gateway.
  • When each profile was last fully activated (not first use, not every use).
  • Which access point MAC addresses were seen for a Wi-Fi profile, useful for geolocation through BSSID databases under proper legal basis.
  • The IPv4 address most recently leased on an interface for a given profile.
  • Which users may use a profile (permissions=user:alice;), which hints at who created it on multi-user desktops.
  • Journal messages prove each activation and disconnect time within journal retention.
  • It does not show traffic, and profiles created by other tools (systemd-networkd, ifupdown, ip commands) are not here.

Key fields

Keyfile profile (secrets redacted):

[connection]
id=Hotel-Guest
uuid=2b0d6e2a-8f5c-4b8e-9a52-0f1f4c9d7e11
type=wifi
interface-name=wlp2s0
permissions=user:alice;
timestamp=1789388551

[wifi]
mode=infrastructure
ssid=Hotel-Guest

[wifi-security]
key-mgmt=wpa-psk
psk=<redacted>

[ipv4]
method=auto
KeyMeaning
idHuman-readable profile name
uuidStable identifier; links to timestamps, seen-bssids, lease file names
typewifi (802-11-wireless), ethernet, vpn, wireguard, bridge, bond, ...
timestampLast successful full activation, epoch seconds (if written to the profile)
autoconnectfalse means the profile is only used on demand
permissionsUsers allowed to use it; empty = everyone
ssid, bssid, mac-address, hiddenWi-Fi identity, pinned AP, pinned adapter, hidden network
[vpn] service-type, dataVPN plugin and gateway settings

State files in /var/lib/NetworkManager are small key files:

# timestamps
[timestamps]
2b0d6e2a-8f5c-4b8e-9a52-0f1f4c9d7e11=1789388551

# seen-bssids
[seen-bssids]
2b0d6e2a-8f5c-4b8e-9a52-0f1f4c9d7e11=aa:bb:cc:11:22:33;aa:bb:cc:11:22:34;

Current NetworkManager keeps at most 30 BSSIDs per profile in seen-bssids. An internal DHCP lease file contains ADDRESS=192.168.20.117.

Journal messages (identifier NetworkManager):

<info>  [1789388540.8121] device (wlp2s0): Activation: starting connection 'Hotel-Guest' (2b0d6e2a-...)
<info>  [1789388549.2210] dhcp4 (wlp2s0): state changed new lease, address=192.168.20.117
<info>  [1789388551.0402] device (wlp2s0): Activation: successful, device activated.

Timestamps

  • timestamps values and a profile's timestamp= key are Unix epoch seconds (UTC). Current NetworkManager source writes the value when the connection finishes activating, when it is deactivated and when the daemon shuts down with the connection still active (the settings documentation also describes a periodic refresh), so it approximates the last time the profile was in use, not when it was first joined.
  • The bracketed number in NetworkManager log lines is also epoch seconds (with four decimals), independent of the syslog header.
  • Profile file birth time (ext4 crtime) approximates profile creation; mtime reflects the last edit. On Ubuntu 23.10+ look at the Netplan YAML file times as well.
date -u -d @1789388551

Retention

Profiles stay until deleted (nmcli connection delete removes the file). When a profile is deleted through NetworkManager, its timestamps and seen-bssids entries are removed too, so capture them early. Lease files are overwritten at each lease. Journal messages follow the journal size limits; on Debian/Ubuntu with rsyslog they also appear in /var/log/syslog.

Collection

UAC collects /var/lib/NetworkManager and /etc (profiles included) and runs nmcli connection show, nmcli device show and related commands in live response.

E=/mnt/evidence
tar -C "$E" -cpf /cases/2026-017/nm.tar etc/NetworkManager var/lib/NetworkManager \
  etc/netplan etc/sysconfig/network-scripts etc/network etc/hosts etc/resolv.conf 2>/dev/null
journalctl -D "$E/var/log/journal" --utc -o short-iso-precise SYSLOG_IDENTIFIER=NetworkManager > nm-journal.txt

Profiles contain Wi-Fi passphrases, VPN secrets and 802.1X credentials in plain text when stored system-wide. Treat the archive as sensitive, and redact psk=, password= and secrets values before sharing reports.

Parsing

# Profile inventory: file, name, type, SSID
grep -HE '^(id|type|ssid|interface-name|permissions|timestamp)=' etc/NetworkManager/system-connections/*.nmconnection
# Last activation per UUID, human readable
awk -F= 'NR>1 && NF==2 {cmd="date -u -d @"$2" +%FT%TZ"; cmd | getline t; close(cmd); print $1, t}' var/lib/NetworkManager/timestamps
# Activation history from the journal
grep -E "Activation: (starting connection|successful)|state changed new lease|disconnected" nm-journal.txt

Join the three sources on UUID: profile file for the name, timestamps for the last use, seen-bssids for AP MACs, lease file names for the interface.

Investigator tips

  • A new VPN or WireGuard profile, or a static route or DNS server in an existing profile, can be attacker infrastructure for tunnelling or traffic redirection; check file times against the incident window.
  • Dispatcher scripts run as root on up, down, dhcp4-change and other events. Scripts must be root-owned and not group or world writable; an extra script there is persistence, see hunting persistence.
  • Phone hotspot SSIDs (device names) on a workstation can reveal an attempt to bypass corporate network monitoring during data exfiltration.
  • Correlate activation times with browser history, SSH logins and firewall logs to place activity on a specific network.
  • On Ubuntu 23.10+, a profile deleted from NetworkManager also loses its 90-NM-*.yaml; check both locations and the journal.
  • /etc/resolv.conf is usually a symlink to a generated file (/run/systemd/resolve/stub-resolv.conf or NetworkManager's own); a regular, hand-written file with unusual nameservers deserves attention.

See also