Ir al contenido

Chuleta de artefactos de Linux

Todos los artefactos en una sola tabla, agrupados por categoría. Imprime en horizontal o guarda como PDF desde el navegador.

Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.

ArtefactoUbicaciónPruebaMarcas de tiempoAccesoRetenciónAnálisis
Ejecución
/tmp, /var/tmp and /dev/shmInglésDebian · RHEL · SUSE · Arch/tmp, /var/tmp, /dev/shm, /run/user/<uid>That files were dropped or run from world-writable locations, by which user and whenInode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM onlyAny user can write; root needed to read other users' files (mode 1777 with sticky bit)tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deletedfind, stat, debugfs, The Sleuth Kit, Velociraptor
Artefactos en vivo de /procDebian · RHEL · SUSE · Arch/proc/<pid>/Qué se está ejecutando ahora mismo, desde qué binario, con qué argumentos, archivos y conexiones de redSin marcas de tiempo de archivo útiles; hora de inicio del proceso en ticks de reloj desde el arranque (/proc/<pid>/stat campo 22)root para ver exe, environ, fd y maps de todos los procesos; los demás usuarios solo ven los suyosVolátil: desaparece al terminar el proceso o al reiniciarps, ss, lsof, Velociraptor, Volatility 3
Docker, containerd and Podman Artifacts on Linux HostsInglésDebian · RHEL · SUSE · Arch/var/lib/docker/containers/<id>/Which containers ran, from which image and command, with which privileges, what they printed and which files they changedRFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layersroot (or docker group, which is root-equivalent); rootless Podman data is owned by the userUntil the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file setcontainer-explorer, jq, docker, crictl, ctr
Historial de la shellDebian · RHEL · SUSE · Arch~/.bash_historyQué comandos se teclearon en una shell interactiva que se ejecutaba con una cuenta determinada, y a veces cuándoSegundos de época Unix (UTC) cuando se registran: bash solo con HISTTIMEFORMAT, zsh con EXTENDED_HISTORY, fish siempreCualquier usuario para sus propios archivos; root para los directorios personales de otros usuariosHasta que HISTFILESIZE/SAVEHIST lo recortan o se borraPlaso, Volatility 3, Velociraptor
Linux Crash Reports and Core DumpsInglésDebian · RHEL · SUSE · Arch/var/lib/systemd/coredump/, /var/crash/Which program crashed, when, as which user, with which command line, and what its memory held at that momentJournal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctimeroot; per-user cores readable by the owning user through coredumpctlsystemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 dayscoredumpctl, gdb, getfattr, apport-unpack, crash
Linux Memory AcquisitionInglésDebian · RHEL · SUSE · Arch/proc/kcore, /dev/crash, /dev/memRunning processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not showCapture time from your case log; in-memory structures carry their own times (process start as time since boot)root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEMVolatile: lost at power-off; changes continuously while the host runsVolatility 3, dwarf2json, AVML, LiME
Logs de sudoDebian · RHEL · SUSE · Arch/var/log/auth.log, /var/log/secureQué cuenta ejecutó qué comando como qué usuario de destino, desde qué terminal y directorio, y los intentos fallidosHora de syslog/journal del host (ver formatos de syslog); los logs de E/S guardan tiempos relativos por sesiónroot (o grupo adm para auth.log en Debian/Ubuntu)Sigue la rotación de auth.log/secure y los límites del journal; logs de E/S hasta su borradogrep/zgrep, journalctl, sudoreplay, ausearch, Plaso
Snap and Flatpak ArtifactsInglésDebian · RHEL · SUSE · Arch/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user dataRFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file timesroot for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each userInstalled apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journalsnap, flatpak, jq, journalctl, find
Persistencia
/etc/ld.so.preload y LD_PRELOADDebian · RHEL · SUSE · Arch/etc/ld.so.preloadSi se forzó la carga de una biblioteca compartida en los procesos enlazados dinámicamente, cuál y desde cuándomtime/ctime/crtime del archivo de precarga y de la biblioteca; sin marcas de tiempo internasroot para escribir; legible por todos; el propio rootkit puede ocultarlo a las herramientas en vivoHasta su borrado; LD_PRELOAD en el entorno de un proceso dura hasta que el proceso terminadebugfs, UAC, Volatility 3, Velociraptor
/etc/passwd, shadow and groupInglésDebian · RHEL · SUSE · Arch/etc/passwd, /etc/shadow, /etc/group, /etc/gshadowWhich local accounts and group memberships exist, which can log in, and when each password was last changedshadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal timepasswd and group: any user; shadow and gshadow: rootUntil changed; one backup generation (passwd-, shadow-, group-, gshadow-)awk, pwck -r, grpck -r, Velociraptor, ausearch
Artefactos SSHDebian · RHEL · SUSE · Arch~/.ssh/authorized_keysQué claves pueden iniciar sesión en una cuenta, a dónde se conectó un usuario y quién inició sesión por SSH y desde dóndeArchivos de claves: solo marcas de tiempo del sistema de archivos; logs: hora local de syslog o usec del journal desde la época Unix (UTC)root (o el titular de la cuenta para su propio ~/.ssh); grupo adm/systemd-journal para los logsArchivos de claves hasta su borrado; las líneas de log siguen la rotación de syslog y los límites del journalssh-keygen, Velociraptor, UAC, grep
Cron, anacron, at y timers de systemd en LinuxDebian · RHEL · SUSE · Arch/var/spool/cron/Qué comandos se programaron, con qué cuenta, y cuándo los lanzó por última vez cron, anacron o un timermtime/ctime de los archivos; hora de syslog o del journal para las ejecuciones; sellos de anacron como fecha local YYYYMMDDroot para todos los directorios de spool; cualquier usuario para su propio crontab con crontab -lHasta su borrado; las evidencias de ejecución siguen la rotación de syslog/journalVelociraptor, UAC, grep, systemctl
eBPF Programs and Pinned MapsInglésDebian · RHEL · SUSE · ArchKernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on diskWhich eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores thembpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file timesroot (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks othersPrograms live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on diskbpftool, Volatility 3, ss, ausearch, readelf, find
Linux Kernel ModulesInglésDebian · RHEL · SUSE · Arch/proc/modulesWhich kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernelKernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file timesroot; kernel addresses in /proc/modules are zeroed for unprivileged readersLoaded state and taint until reboot; config files until deleted; log lines per journal/syslog limitsVolatility 3, modinfo, Velociraptor, UAC
PAM Configuration and ModulesInglésDebian · RHEL · SUSE · Arch/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentialsFile system times of stack files and modules; PAM messages in auth logs and the journalroot to modify; configuration world-readable, modules readable by allPersistent until changed; package updates may overwrite a patched modulerpm, dpkg, debsums, authselect, find, grep / zgrep, strings
rc.local, SysV init.d and MOTD ScriptsInglésDebian · RHEL/etc/rc.localWhether a script was set to run as root at boot or at every login, and when it was placed thereFile mtime/ctime/crtime only; execution times from journal or syslogroot to write; world-readable on most systemsUntil deleted; execution evidence follows journal/syslog rotationUAC, Velociraptor, grep, journalctl
Shell Startup FilesInglésDebian · RHEL · SUSE · Arch/etc/profile.d/Whether code was set to run automatically each time a user or root starts or ends a shell sessionNone inside the files; use inode mtime/ctime/crtime (ext4, XFS v5)root for /etc files; any user for own dotfiles; root to read other users' homesUntil modified or deleted; package upgrades may replace /etc defaultsVelociraptor, debsums, rpm -V
SUID, SGID and File CapabilitiesInglésDebian · RHEL · SUSE · ArchInode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file systemWhich executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package managerSetting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or installReadable by any user with stat/getcap; root to setPersistent until the file is replaced or the bit removed; package updates reset package-owned filesfind, getcap, getfattr, stat, rpm, dpkg, debsums
sysctl, Boot Parameters and binfmt_misc on LinuxInglésDebian · RHEL · SUSE · Arch/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker codeFile system times of configuration files only; live values carry no timestamproot to change; most values world-readable in /proc/sysFiles persist; runtime changes via sysctl -w or /proc/sys writes are lost at rebootsysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg
Unidades systemdDebian · RHEL · SUSE · Arch/etc/systemd/system/Qué servicios y timers están configurados para arrancar, qué ejecutan y cuándo se instaló o modificó la unidadmtime/ctime/crtime de los archivos; entradas del journal en microsegundos desde la época Unix (UTC)root para las unidades del sistema; cualquier usuario para su propio ~/.config/systemd/userHasta su borrado; las unidades de /run se pierden al reiniciar; los eventos de arranque/parada siguen los límites del journalsystemctl, systemd-analyze, Velociraptor, UAC
Web Shells in the Web RootInglésDebian · RHEL · SUSE · Arch/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webappsThat a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can doFile system times (birth time on ext4/XFS v5 dates the drop); first request time in access logsRead as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or httpUntil deleted; deployments and CMS updates may overwrite or remove filesfind, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg
XDG Autostart .desktop EntriesInglésDebian · RHEL · SUSE · Arch~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktopWhich programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was writtenFile system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessionsAny user for their own entries; root for /etc/xdg/autostartUntil the .desktop file is deleted; launch records follow journal retentionfind, grep / zgrep, journalctl, systemctl, rpm, dpkg
Acceso a archivos
Linux Thumbnail CacheInglésDebian · RHEL · SUSE · Arch~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked likeThumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generatedAny user for their own cache (mode 0700 directories, 0600 files); root for other usersUntil the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by defaultExifTool, find, stat
Linux TrashInglésDebian · RHEL · SUSE · Arch~/.local/share/Trash/{files,info}/Which file or folder a user sent to the Trash through a desktop application, from which original path, and whenDeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo fileAny user for their own Trash (directories mode 0700); root for other usersUntil the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled)gio, trash-cli, find, stat
Marcas de tiempo de ext4, crtime y archivos borradosDebian · Arch/dev/<ext4-partition>Cuándo se creó, modificó, cambió y posiblemente se leyó o borró un archivo, y a veces qué conteníaSegundos de época Unix UTC más nanosegundos en los campos *_extra (inodos de 256 bytes); i_dtime en segundosCualquier usuario para stat sobre archivos accesibles; root o acceso al dispositivo en bruto para debugfs y los inodos borradosMarcas de tiempo hasta que se sobrescriben; inodos y bloques borrados hasta que se reutilizan; el journal es un pequeño log circulardebugfs, The Sleuth Kit, Plaso, ext4magic, stat
recently-used.xbelInglésDebian · RHEL · SUSE · Arch~/.local/share/recently-used.xbelWhich local or remote files a desktop user opened or saved through GUI applications, with which app and whenISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix secondsAny user for own file (GTK sets mode 0600); root for other usersGTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by defaultxmllint, Python ElementTree
Tracker / LocalSearch DBInglésDebian · RHEL · SUSE · Arch~/.cache/tracker3/files/Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexerUnix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be keptAny user for own cache; root for other usersMirrors the indexed tree; entries removed when the indexer processes a deletiontinysparql, sqlite3, localsearch
viminfo, ShaDa and lesshstInglésDebian · RHEL · SUSE · Arch~/.viminfoWhich files a user opened in vim or Neovim, and what they searched for or ran inside vim and lessUnix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshstAny user for own files (created mode 0600); root for other usersUntil deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100)Plaso, Neovim, python-msgpack
XFS ForensicsInglésRHEL · SUSE/dev/<xfs-volume>When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files containedSeconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystemsAny user for stat on accessible files; root or raw device access for xfs_dbTimestamps until overwritten; deleted inode extents and data blocks until reusedxfs_db, stat, libfsxfs, Plaso
Actividad del usuario
Browser Profiles on LinuxInglésDebian · RHEL · SUSE · Arch~/.mozilla/firefox/<profile>/places.sqliteWhich sites a user visited, what they downloaded and searched for, and whenFirefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC)Any user for own profile; root for other usersChrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pagesHindsight, Plaso, sqlite3
wtmp, btmp, utmp y lastlogDebian · RHEL · SUSE · Arch/var/log/wtmpQuién inició sesión, en qué terminal, desde qué host, cuándo terminó la sesión y cuándo se reinició el sistemaRegistros utmp: segundos de época Unix + microsegundos (campos de 32 bits), UTC. wtmpdb: microsegundos desde la épocaLegibles por todos para wtmp/utmp/lastlog; root (o grupo utmp) para btmplogrotate: mensual, 1 generación antigua para wtmp y btmp; lastlog hasta que se sobrescribelast, lastb, utmpdump, wtmpdb, Plaso, Velociraptor
Red
/etc/hosts, nsswitch.conf and resolv.conf on LinuxInglésDebian · RHEL · SUSE · Arch/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directoryWhere the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookupsFile system times only; systemd-resolved and NetworkManager log DNS server changes to the journalWorld-readable; root to modifyPersistent until edited; generated resolv.conf files are rewritten by the network stackgetent, resolvectl, grep / zgrep, rpm, dpkg, journalctl
Linux Firewall LogsInglésDebian · RHEL · SUSE · Arch/var/log/ufw.log, /var/log/kern.logWhich connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changedSyslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system timesroot (or adm group for /var/log files on Debian/Ubuntu)Follows syslog rotation and journal limits; rule files until changedgrep/zgrep, journalctl, nft, iptables-save, Plaso
NetworkManager Profiles and StateInglésDebian · RHEL · SUSE · Arch/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leasedUnix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode timesroot (profiles are root-only 0600); journal: root or systemd-journal groupProfiles until deleted; state files overwritten in place; journal per its limitsgrep, journalctl, nmcli (live), Plaso
USB y dispositivos
udev and USB Device History on LinuxInglésDebian · RHEL · SUSE · Arch/etc/udev/rules.d/, /var/log/kern.logWhich USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run codeJournal: UTC microseconds; syslog: host local time; dmesg: seconds since bootroot (or adm/systemd-journal group) for logs; rules readable by any userFollows journal and kern.log/messages rotation; rules until deletedjournalctl, zgrep, udevadm, Plaso
Antiforense
logrotate State and Log GapsInglésDebian · RHEL · SUSE · Arch/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tamperingState file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixesrootConfiguration persistent; the state file is rewritten at every run and keeps one line per loglogrotate, stat, find, grep / zgrep, journalctl, systemctl
Registros
Apache and Nginx LogsInglésDebian · RHEL/var/log/apache2/, /var/log/httpd/, /var/log/nginx/Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell useLocal time with numeric UTC offset, second precision (default combined format)root or adm group (Debian/Ubuntu); root (RHEL)Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 keptgrep/zgrep, awk, GoAccess, lnav, Plaso
AppArmor and SELinux DenialsInglésDebian · RHEL · SUSE/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journalWhich confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched offmsg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal timeroot (audit.log mode 0600; kernel log readable by adm or root depending on distro)Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retentionausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep
auditd audit.logDebian · RHEL · SUSE/var/log/audit/audit.logQué usuario de inicio de sesión ejecutó qué programa o tocó qué archivo vigilado, y cada autenticación y sesión PAMSegundos de época Unix con milisegundos en msg=audit(sec.msec:serial), UTCroot (log_group vale root por defecto)Por tamaño: valor por defecto de upstream 8 MiB x 5 archivos, rotados por auditdausearch, aureport, Plaso, Zircolite
auth.log, secure y syslogDebian · RHEL/var/log/auth.log, /var/log/secureQuién se autenticó, desde dónde y con qué método, y qué notificaron los servicios y el kernel, en texto planoTradicional: hora local, sin año ni zona. RFC 3339: hora local con desfase y microsegundosroot o grupo adm (Debian/Ubuntu); root (RHEL)logrotate: semanal, 4 generaciones en la configuración por defecto de Debian/Ubuntu y RHELgrep/zgrep, Plaso, lnav
cloud-init Logs and Instance DataInglésDebian · RHEL · SUSE/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts runLog lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished contentroot for user-data and sensitive instance data; logs usually root-readable only or adm groupLogs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at rebootcloud-init, jq, grep / zgrep, journalctl
dmesg, kern.log and the Kernel Ring Buffer on LinuxInglésDebian · RHEL · SUSE · Arch/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warningsRing buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTCRing buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm groupRing buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by sizedmesg, journalctl, grep / zgrep
dpkg, APT, RPM and DNF LogsInglésDebian · RHEL/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.logWhich packages were installed, upgraded or removed, when, with which command line and by which sudo userdpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC)dpkg.log and apt/history.log are world-readable; root for complete collectiondpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removedzgrep, sqlite3, rpm --root, dpkg --root, Plaso
Journal de systemdDebian · RHEL · SUSE · Arch/var/log/journal/<machine-id>/Lo que registraron los servicios, procesos, usuarios y el kernel, con PID/UID/ejecutable fiables y contexto de arranqueMicrosegundos desde la época Unix (UTC) para realtime; microsegundos desde el arranque para monotonicroot (o grupos systemd-journal, adm o wheel); cada usuario puede leer su propio journal user-UIDPor tamaño: 10 % del sistema de archivos con un máximo de 4G por defecto; la copia volátil se pierde al reiniciarjournalctl, Plaso, Velociraptor
MySQL, MariaDB and PostgreSQL LogsInglésDebian · RHEL/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the databaseMySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix secondsroot or the mysql/postgres service account; client history files owned by each userError logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by defaultmysqlbinlog, pgBadger, grep / zgrep, journalctl