Glossary
wtmp and btmp
wtmp and btmp are binary Linux login records: wtmp stores logins, logouts and reboots, while btmp stores failed login attempts for lastb.
/var/log/wtmp and /var/log/btmp are binary files made of fixed-size utmp records. wtmp keeps a history of successful logins, logouts, reboots and shutdowns, and is read with last. btmp keeps failed login attempts and is read with lastb. A third file, /run/utmp (often linked as /var/run/utmp), holds only the currently logged-in sessions and is what who and w read.
Each record contains the record type, terminal, user name, remote host, session ID and a timestamp. On an image, always point the tools at the evidence copy, and use utmpdump to view raw records, which is handy for spotting anomalies:
last -F -f /mnt/evidence/var/log/wtmp
lastb -F -f /mnt/evidence/var/log/btmp
utmpdump /mnt/evidence/var/log/wtmp
Pitfalls: the files rotate (typically monthly, as wtmp.1), btmp is readable only by root and may be absent, and because the format is simple, root can edit or zero out records. Gaps in time, zeroed entries or a wtmp smaller than expected are tampering indicators. Some recent distributions are moving to a database-backed replacement (wtmpdb) because of the 32-bit timestamp limit, so check which mechanism the host uses. Correlate with sshd lines in auth.log, secure or the journal. See Linux log forensics.