<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linux Forensics — Blog</title>
    <link>https://www.linuxforensics.app/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:53:55 GMT</lastBuildDate>
    <atom:link href="https://www.linuxforensics.app/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts</title>
      <link>https://www.linuxforensics.app/en/blog/acquiring-linux-evidence</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/acquiring-linux-evidence</guid>
      <description>How to acquire Linux evidence soundly: order of volatility, live vs dead acquisition, dd/dc3dd/ewfacquire imaging, cloud snapshots and read-only mounts.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Container Forensics: Docker, containerd and Podman on Linux</title>
      <link>https://www.linuxforensics.app/en/blog/container-forensics-docker-containerd</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/container-forensics-docker-containerd</guid>
      <description>Investigate Docker, containerd and Podman hosts: container metadata, overlay2 upper layers, JSON logs, escape indicators and Kubernetes node log paths.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ext4 and XFS Timestamps, Inodes and Deleted Files</title>
      <link>https://www.linuxforensics.app/en/blog/ext4-xfs-timestamps-and-deleted-files</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/ext4-xfs-timestamps-and-deleted-files</guid>
      <description>How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Hunting Linux Persistence: Cron, systemd, SSH and More</title>
      <link>https://www.linuxforensics.app/en/blog/hunting-linux-persistence</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/hunting-linux-persistence</guid>
      <description>Where attackers hide persistence on Linux (cron, systemd units and timers, shell startup files, SSH keys, ld.so.preload, PAM, udev, modules) and how to find it.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Log Forensics: syslog, journald, wtmp and auditd</title>
      <link>https://www.linuxforensics.app/en/blog/linux-log-forensics-syslog-journald</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/linux-log-forensics-syslog-journald</guid>
      <description>How to analyse Linux logs in an investigation: rsyslog files, sshd and sudo lines, the journald binary journal, wtmp/btmp, auditd and tampering signs.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Memory Forensics with LiME, AVML and Volatility 3</title>
      <link>https://www.linuxforensics.app/en/blog/linux-memory-forensics-lime-volatility</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/linux-memory-forensics-lime-volatility</guid>
      <description>Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Building a Linux Super Timeline with Plaso and mactime</title>
      <link>https://www.linuxforensics.app/en/blog/linux-super-timeline-plaso</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/linux-super-timeline-plaso</guid>
      <description>Build a Linux forensic super timeline with TSK mactime and Plaso: log2timeline, psort and pinfo, Linux parsers, time slicing, UTC and Timesketch.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Live Response: Triage Through /proc and Volatile Data</title>
      <link>https://www.linuxforensics.app/en/blog/live-response-proc-triage</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/live-response-proc-triage</guid>
      <description>A practical Linux live response workflow: trusted binaries, logging your actions, and triaging processes, sockets and modules through /proc before shutdown.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Package Manager Forensics on Linux: dpkg, APT, RPM and DNF</title>
      <link>https://www.linuxforensics.app/en/blog/package-manager-forensics-dpkg-rpm</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/package-manager-forensics-dpkg-rpm</guid>
      <description>Use dpkg, APT, RPM and DNF logs and databases to date installs, verify file integrity and find binaries no package owns on a compromised Linux host.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Shell History and User Activity Forensics</title>
      <link>https://www.linuxforensics.app/en/blog/shell-history-and-user-activity</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/shell-history-and-user-activity</guid>
      <description>Reconstruct what a user did on a Linux host from bash, zsh and fish history, dotfiles, SSH files, sudo logs and account databases, and spot history evasion.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Triage Collection with UAC and Velociraptor</title>
      <link>https://www.linuxforensics.app/en/blog/triage-collection-uac-velociraptor</link>
      <guid isPermaLink="true">https://www.linuxforensics.app/en/blog/triage-collection-uac-velociraptor</guid>
      <description>Run fast, repeatable Linux triage with UAC profiles and Velociraptor Linux artifacts: what each collects, offline collectors, hunts and what to grab first.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>