Skip to content

Area 02

Logs & Journal

Logs are the backbone of most Linux investigations. This area explains where each distribution writes authentication and system events, how to query the binary systemd journal offline, how to read wtmp, btmp and lastlog, and how to spot gaps and tampering.

Key artifacts

  • /var/log/auth.log
  • /var/log/journal
  • wtmp / btmp

Guides in this area

Artifact cheat sheets

Where each artifact lives, what it proves, its timestamps and the tools to parse it.

All areas