Sitemap
Every page on Linux Forensics.
Home
Investigation areas
Guides
- Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts
- Container Forensics: Docker, containerd and Podman on Linux
- ext4 and XFS Timestamps, Inodes and Deleted Files
- Hunting Linux Persistence: Cron, systemd, SSH and More
- Linux Log Forensics: syslog, journald, wtmp and auditd
- Linux Memory Forensics with LiME, AVML and Volatility 3
- Building a Linux Super Timeline with Plaso and mactime
- Linux Live Response: Triage Through /proc and Volatile Data
- Package Manager Forensics on Linux: dpkg, APT, RPM and DNF
- Linux Shell History and User Activity Forensics
- Linux Triage Collection with UAC and Velociraptor
Artifacts
- /etc/hosts, nsswitch.conf and resolv.conf on Linux
- /etc/ld.so.preload and LD_PRELOAD: Linux Linker Hijacking
- /etc/passwd, shadow and group: Linux Local Accounts
- /proc Live Artifacts: Processes, Sockets and Deleted Files
- /tmp, /var/tmp and /dev/shm: Linux Staging Directories
- Apache and Nginx Logs: Linux Web Server Forensics
- AppArmor and SELinux Denials: Linux MAC Audit Logs
- auditd audit.log: Linux Kernel Audit Trail
- auth.log, secure and syslog: Linux Text Logs
- Browser Profiles on Linux: Firefox and Chrome History
- cloud-init Logs and Instance Data: Linux Cloud VM Forensics
- Cron, Anacron, at and systemd Timers: Linux Scheduling
- dmesg, kern.log and the Kernel Ring Buffer on Linux
- Docker, containerd and Podman Artifacts on Linux Hosts
- dpkg, APT, RPM and DNF Logs: Linux Package History
- eBPF Programs and Pinned Maps: Linux Kernel Implants
- ext4 Timestamps, crtime and Deleted Files
- Linux Crash Reports and Core Dumps: coredump, apport
- Linux Firewall Logs: iptables, nftables, ufw, firewalld
- Linux Kernel Modules: lsmod, Taint Flags and Boot Config
- Linux Memory Acquisition: LiME, AVML and /proc/kcore
- Linux Thumbnail Cache: ~/.cache/thumbnails Forensics
- Linux Trash: freedesktop .trashinfo Files and Deleted Items
- logrotate State and Log Gaps: Detecting Linux Log Tampering
- MySQL, MariaDB and PostgreSQL Logs: Linux Database Forensics
- NetworkManager Profiles and State: Linux Network History
- PAM Configuration and Modules: Linux Auth Backdoors
- rc.local, SysV init.d and MOTD Scripts: Linux Boot Hooks
- recently-used.xbel: GNOME and GTK Recent Files on Linux
- Shell History: Linux bash, zsh and fish Command Logs
- Shell Startup Files: Linux bashrc and profile Persistence
- Snap and Flatpak Artifacts: Linux Sandboxed App Forensics
- SSH Artifacts: authorized_keys, known_hosts and sshd Logs
- sudo Logs: Linux Privilege Use Records
- SUID, SGID and File Capabilities: Linux Privilege Backdoors
- sysctl, Boot Parameters and binfmt_misc on Linux
- systemd Journal: Linux Binary System Log
- systemd Unit Files: Linux Service Persistence
- Tracker / LocalSearch DB: GNOME File Index on Linux
- udev and USB Device History on Linux
- viminfo, ShaDa and lesshst: Linux Editor and Pager History
- Web Shells in the Web Root: Finding Them on Linux Servers
- wtmp, btmp, utmp and lastlog: Linux Login Records
- XDG Autostart .desktop Entries: Linux Desktop Persistence
- XFS Forensics: Inode Timestamps, crtime and Deleted Files