Skip to content

Guides

In-depth Linux forensics and incident response guides, from evidence acquisition to super-timelines.

05 · Filesystem & Timestamps

ext4 and XFS Timestamps, Inodes and Deleted Files

How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.

ext4xfstimestamps
06 · Memory Forensics

Linux Memory Forensics with LiME, AVML and Volatility 3

Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.

memory-forensicsvolatilitylime