Artefactos forenses de Linux
Una página por artefacto: dónde está en Debian, Ubuntu y la familia RHEL, qué prueba, cómo funcionan sus marcas de tiempo, cuánto se conserva y cómo adquirirlo y analizarlo con herramientas de código abierto.
Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.
Ejecución
/tmp, /var/tmp and /dev/shm: Linux Staging DirectoriesInglés
World-writable Linux directories attackers use to stage tools: tmpfs versus disk, cleanup ages, noexec, memfd fileless execution and what survives reboot.
/tmp, /var/tmp, /dev/shm, /run/user/<uid>
Artefactos en vivo de /proc: procesos, sockets y borrados
El pseudosistema de archivos /proc en un host Linux en vivo: líneas de comando, entornos, archivos abiertos, mapas de memoria, sockets y binarios borrados.
/proc/<pid>/
Docker, containerd and Podman Artifacts on Linux HostsInglés
Container evidence on a Linux host: Docker config.v2.json and JSON logs, overlay2 upper layers, containerd snapshots, Podman storage and Kubernetes pod logs.
/var/lib/docker/containers/<id>/
Historial de la shell: comandos de bash, zsh y fish
Historial de comandos por usuario de bash, zsh y fish en Linux: qué registra cada archivo, cuándo hay marcas de tiempo y cómo se delata la evasión.
~/.bash_history
Linux Crash Reports and Core Dumps: coredump, apportInglés
systemd-coredump, Ubuntu apport, ABRT and kdump on Linux: where crash data lands and how it exposes failed exploits and unstable implants.
/var/lib/systemd/coredump/, /var/crash/
Linux Memory Acquisition: LiME, AVML and /proc/kcoreInglés
Capturing Linux RAM with LiME or AVML: memory sources, output formats, lockdown limits and the Volatility 3 symbol tables needed to analyse the image.
/proc/kcore, /dev/crash, /dev/mem
Logs de sudo: uso de privilegios en Linux
Cómo registra sudo quién ejecutó qué como root en Linux: líneas de syslog y del journal, archivos de log opcionales, grabaciones de E/S y archivos sudoers.
/var/log/auth.log, /var/log/secure
Snap and Flatpak Artifacts: Linux Sandboxed App ForensicsInglés
Snap and Flatpak evidence on Linux: snapd state.json change history, sideloaded snaps, Flatpak installations and remotes, and per-app data directories.
/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/
Persistencia
/etc/ld.so.preload y LD_PRELOAD: secuestro del enlazador
El archivo de precarga del enlazador dinámico, LD_PRELOAD y ld.so.conf: cómo los rootkits de usuario inyectan bibliotecas en cada proceso y cómo detectarlos.
/etc/ld.so.preload
/etc/passwd, shadow and group: Linux Local AccountsInglés
Linux local account databases (passwd, shadow, group, gshadow and their backups) that reveal rogue accounts, UID 0 clones and password change dates.
/etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
Artefactos SSH: authorized_keys, known_hosts y logs
Artefactos de OpenSSH en Linux (authorized_keys, known_hosts, configuración, claves de host, logs de sshd): accesos, persistencia y movimiento lateral.
~/.ssh/authorized_keys
Cron, anacron, at y timers de systemd en Linux
Artefactos de tareas programadas en Linux (crontabs, sellos de anacron, trabajos at, timers de systemd) que revelan persistencia y prueban ejecuciones.
/var/spool/cron/
eBPF Programs and Pinned Maps: Linux Kernel ImplantsInglés
Loaded eBPF programs, pinned objects in /sys/fs/bpf and their loaders on disk: how eBPF rootkits and BPF backdoors hide on Linux and how to find them.
Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk
Linux Kernel Modules: lsmod, Taint Flags and Boot ConfigInglés
Loaded and configured Linux kernel modules (/proc/modules, /sys/module, modules-load.d, modprobe.d, taint flags) for spotting rootkits and module persistence.
/proc/modules
PAM Configuration and Modules: Linux Auth BackdoorsInglés
Linux PAM stacks in /etc/pam.d and the pam_*.so modules they load: where attackers plant password loggers and master passwords, and how to verify them.
/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)
rc.local, SysV init.d and MOTD Scripts: Linux Boot HooksInglés
Legacy Linux boot and login script locations (rc.local, /etc/init.d, rc?.d links, Upstart jobs, update-motd.d) and how they reveal persistence.
/etc/rc.local
Shell Startup Files: Linux bashrc and profile PersistenceInglés
System and per-user shell startup files (profile, bashrc, zshrc, logout) on Linux: load order, where attackers hide persistence and how to review them.
/etc/profile.d/
SUID, SGID and File Capabilities: Linux Privilege BackdoorsInglés
SUID/SGID bits and file capabilities (security.capability) on Linux: how attackers plant root backdoors and how to baseline them against packages.
Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system
sysctl, Boot Parameters and binfmt_misc on LinuxInglés
Linux kernel settings in sysctl.d, /proc/sys and the boot command line: core_pattern and modprobe hijacks, weakened protections, ip_forward, binfmt_misc.
/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/
Unidades systemd: persistencia de servicios en Linux
Servicios, timers y drop-ins de systemd, symlinks de activación, generadores y lingering: dónde se definen los servicios de Linux y cómo delatan persistencia.
/etc/systemd/system/
Web Shells in the Web Root: Finding Them on Linux ServersInglés
Where Linux web roots live per distro, how PHP, JSP and CGI web shells and .htaccess or module backdoors look on disk, and how to date and hunt them.
/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps
XDG Autostart .desktop Entries: Linux Desktop PersistenceInglés
XDG autostart entries in /etc/xdg/autostart and ~/.config/autostart that launch programs at every graphical login, plus KDE and X session hooks.
~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop
Acceso a archivos
Linux Thumbnail Cache: ~/.cache/thumbnails ForensicsInglés
The freedesktop thumbnail cache on Linux: PNG previews named by the MD5 of the file URI, holding path and mtime, that outlive deleted files.
~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/
Linux Trash: freedesktop .trashinfo Files and Deleted ItemsInglés
The freedesktop.org Trash on Linux desktops: .trashinfo records with original path and deletion time, the trashed files themselves and per-volume trash folders.
~/.local/share/Trash/{files,info}/
Marcas de tiempo de ext4, crtime y archivos borrados
Marcas de tiempo de los inodos ext4 (atime, mtime, ctime, crtime, dtime) con nanosegundos, relatime, el journal jbd2 y qué se puede recuperar de lo borrado.
/dev/<ext4-partition>
recently-used.xbel: GNOME and GTK Recent Files on LinuxInglés
The freedesktop recently-used.xbel file on Linux desktops: which files and URIs a user opened through GTK (and newer KDE) applications, with UTC times.
~/.local/share/recently-used.xbel
Tracker / LocalSearch DB: GNOME File Index on LinuxInglés
GNOME's Tracker and LocalSearch file index on Linux: SQLite databases listing indexed files, their timestamps and extracted content for a user's home.
~/.cache/tracker3/files/
viminfo, ShaDa and lesshst: Linux Editor and Pager HistoryInglés
Vim viminfo, Neovim ShaDa and less history files on Linux: which files a user edited, what they searched for and typed, often after shell history is wiped.
~/.viminfo
XFS Forensics: Inode Timestamps, crtime and Deleted FilesInglés
XFS on RHEL-family Linux: v5 inode timestamps with crtime, bigtime, xfs_db inspection, the metadata log, and what remains after a file is deleted.
/dev/<xfs-volume>
Actividad del usuario
Browser Profiles on Linux: Firefox and Chrome HistoryInglés
Firefox and Chrome/Chromium profile databases on Linux, including snap and Flatpak paths: history, downloads, epochs and how to query them offline.
~/.mozilla/firefox/<profile>/places.sqlite
wtmp, btmp, utmp y lastlog: registros de login en Linux
Registros binarios de login en Linux: historial wtmp, logins fallidos en btmp, sesiones activas en utmp, lastlog por UID y sus sucesores wtmpdb/lastlog2.
/var/log/wtmp
Red
/etc/hosts, nsswitch.conf and resolv.conf on LinuxInglés
Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.
/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory
Linux Firewall Logs: iptables, nftables, ufw, firewalldInglés
Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.
/var/log/ufw.log, /var/log/kern.log
NetworkManager Profiles and State: Linux Network HistoryInglés
NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.
/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/
USB y dispositivos
udev and USB Device History on LinuxInglés
Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.
/etc/udev/rules.d/, /var/log/kern.log
Antiforense
logrotate State and Log Gaps: Detecting Linux Log TamperingInglés
logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.
/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)
Registros
Apache and Nginx Logs: Linux Web Server ForensicsInglés
Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.
/var/log/apache2/, /var/log/httpd/, /var/log/nginx/
AppArmor and SELinux Denials: Linux MAC Audit LogsInglés
SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.
/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal
auditd audit.log: registro de auditoría del kernel
El log de auditoría de Linux escrito por auditd: logins PAM, syscalls, argumentos de execve y accesos vigilados, cada uno ligado al usuario original (auid).
/var/log/audit/audit.log
auth.log, secure y syslog: logs de texto de Linux
Logs de texto de rsyslog en Linux: auth.log y syslog en Debian/Ubuntu, secure y messages en RHEL, con las trampas de rotación y formato de fecha.
/var/log/auth.log, /var/log/secure
cloud-init Logs and Instance Data: Linux Cloud VM ForensicsInglés
cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.
/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/
dmesg, kern.log and the Kernel Ring Buffer on LinuxInglés
The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.
/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)
dpkg, APT, RPM and DNF Logs: Linux Package HistoryInglés
Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.
/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log
Journal de systemd: el registro binario de Linux
El registro binario de systemd-journald: entradas estructuradas, campos de proceso fiables y marcas de tiempo UTC en microsegundos, a menudo el único log.
/var/log/journal/<machine-id>/
MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsInglés
Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.
/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)