Ir al contenido

Artefactos forenses de Linux

Una página por artefacto: dónde está en Debian, Ubuntu y la familia RHEL, qué prueba, cómo funcionan sus marcas de tiempo, cuánto se conserva y cómo adquirirlo y analizarlo con herramientas de código abierto.

Chuleta imprimible45 artefactos

Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.

Ejecución

Persistencia

  • /etc/ld.so.preload y LD_PRELOAD: secuestro del enlazador

    El archivo de precarga del enlazador dinámico, LD_PRELOAD y ld.so.conf: cómo los rootkits de usuario inyectan bibliotecas en cada proceso y cómo detectarlos.

    /etc/ld.so.preload

  • /etc/passwd, shadow and group: Linux Local AccountsInglés

    Linux local account databases (passwd, shadow, group, gshadow and their backups) that reveal rogue accounts, UID 0 clones and password change dates.

    /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow

  • Artefactos SSH: authorized_keys, known_hosts y logs

    Artefactos de OpenSSH en Linux (authorized_keys, known_hosts, configuración, claves de host, logs de sshd): accesos, persistencia y movimiento lateral.

    ~/.ssh/authorized_keys

  • Cron, anacron, at y timers de systemd en Linux

    Artefactos de tareas programadas en Linux (crontabs, sellos de anacron, trabajos at, timers de systemd) que revelan persistencia y prueban ejecuciones.

    /var/spool/cron/

  • eBPF Programs and Pinned Maps: Linux Kernel ImplantsInglés

    Loaded eBPF programs, pinned objects in /sys/fs/bpf and their loaders on disk: how eBPF rootkits and BPF backdoors hide on Linux and how to find them.

    Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk

  • Linux Kernel Modules: lsmod, Taint Flags and Boot ConfigInglés

    Loaded and configured Linux kernel modules (/proc/modules, /sys/module, modules-load.d, modprobe.d, taint flags) for spotting rootkits and module persistence.

    /proc/modules

  • PAM Configuration and Modules: Linux Auth BackdoorsInglés

    Linux PAM stacks in /etc/pam.d and the pam_*.so modules they load: where attackers plant password loggers and master passwords, and how to verify them.

    /etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)

  • rc.local, SysV init.d and MOTD Scripts: Linux Boot HooksInglés

    Legacy Linux boot and login script locations (rc.local, /etc/init.d, rc?.d links, Upstart jobs, update-motd.d) and how they reveal persistence.

    /etc/rc.local

  • Shell Startup Files: Linux bashrc and profile PersistenceInglés

    System and per-user shell startup files (profile, bashrc, zshrc, logout) on Linux: load order, where attackers hide persistence and how to review them.

    /etc/profile.d/

  • SUID, SGID and File Capabilities: Linux Privilege BackdoorsInglés

    SUID/SGID bits and file capabilities (security.capability) on Linux: how attackers plant root backdoors and how to baseline them against packages.

    Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system

  • sysctl, Boot Parameters and binfmt_misc on LinuxInglés

    Linux kernel settings in sysctl.d, /proc/sys and the boot command line: core_pattern and modprobe hijacks, weakened protections, ip_forward, binfmt_misc.

    /etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/

  • Unidades systemd: persistencia de servicios en Linux

    Servicios, timers y drop-ins de systemd, symlinks de activación, generadores y lingering: dónde se definen los servicios de Linux y cómo delatan persistencia.

    /etc/systemd/system/

  • Web Shells in the Web Root: Finding Them on Linux ServersInglés

    Where Linux web roots live per distro, how PHP, JSP and CGI web shells and .htaccess or module backdoors look on disk, and how to date and hunt them.

    /var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps

  • XDG Autostart .desktop Entries: Linux Desktop PersistenceInglés

    XDG autostart entries in /etc/xdg/autostart and ~/.config/autostart that launch programs at every graphical login, plus KDE and X session hooks.

    ~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop

Acceso a archivos

Actividad del usuario

Red

  • /etc/hosts, nsswitch.conf and resolv.conf on LinuxInglés

    Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.

    /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory

  • Linux Firewall Logs: iptables, nftables, ufw, firewalldInglés

    Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.

    /var/log/ufw.log, /var/log/kern.log

  • NetworkManager Profiles and State: Linux Network HistoryInglés

    NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.

    /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/

USB y dispositivos

  • udev and USB Device History on LinuxInglés

    Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.

    /etc/udev/rules.d/, /var/log/kern.log

Antiforense

  • logrotate State and Log Gaps: Detecting Linux Log TamperingInglés

    logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.

    /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)

Registros

  • Apache and Nginx Logs: Linux Web Server ForensicsInglés

    Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.

    /var/log/apache2/, /var/log/httpd/, /var/log/nginx/

  • AppArmor and SELinux Denials: Linux MAC Audit LogsInglés

    SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.

    /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal

  • auditd audit.log: registro de auditoría del kernel

    El log de auditoría de Linux escrito por auditd: logins PAM, syscalls, argumentos de execve y accesos vigilados, cada uno ligado al usuario original (auid).

    /var/log/audit/audit.log

  • auth.log, secure y syslog: logs de texto de Linux

    Logs de texto de rsyslog en Linux: auth.log y syslog en Debian/Ubuntu, secure y messages en RHEL, con las trampas de rotación y formato de fecha.

    /var/log/auth.log, /var/log/secure

  • cloud-init Logs and Instance Data: Linux Cloud VM ForensicsInglés

    cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.

    /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/

  • dmesg, kern.log and the Kernel Ring Buffer on LinuxInglés

    The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.

    /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)

  • dpkg, APT, RPM and DNF Logs: Linux Package HistoryInglés

    Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.

    /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log

  • Journal de systemd: el registro binario de Linux

    El registro binario de systemd-journald: entradas estructuradas, campos de proceso fiables y marcas de tiempo UTC en microsegundos, a menudo el único log.

    /var/log/journal/<machine-id>/

  • MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsInglés

    Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.

    /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)