02 · Logs & Journal
Linux Log Forensics: syslog, journald, wtmp and auditd
How to analyse Linux logs in an investigation: rsyslog files, sshd and sudo lines, the journald binary journal, wtmp/btmp, auditd and tampering signs.
logsjournaldsyslog
Area 02
Logs are the backbone of most Linux investigations. This area explains where each distribution writes authentication and system events, how to query the binary systemd journal offline, how to read wtmp, btmp and lastlog, and how to spot gaps and tampering.
Key artifacts
How to analyse Linux logs in an investigation: rsyslog files, sshd and sudo lines, the journald binary journal, wtmp/btmp, auditd and tampering signs.
Where each artifact lives, what it proves, its timestamps and the tools to parse it.