Ir al contenido

man 7 dfir

Glosario

Definiciones claras de los términos de análisis forense y respuesta a incidentes en Linux que aparecen en las guías.

Por ahora estas guías solo están publicadas en inglés. Los enlaces siguientes abren la versión en inglés.

auditd (Linux Audit Daemon)
auditd is the userspace daemon of the Linux Audit framework, writing kernel audit events such as syscalls, executions and logins to audit.log.
ext4 crtime (Birth Time)
ext4 crtime is the file creation timestamp stored in extended inode fields, shown as Birth by stat and readable with debugfs on disk images.
Inode
An inode is the on-disk structure that stores a Linux file's metadata, timestamps and pointers to its data blocks, separate from its file name.
LD_PRELOAD and /etc/ld.so.preload
LD_PRELOAD and /etc/ld.so.preload make the dynamic linker load a chosen shared library first, a hooking technique abused by userland rootkits.
LiME (Linux Memory Extractor)
LiME is a loadable Linux kernel module that dumps physical memory to a file or a TCP socket for later analysis with Volatility or other tools.
Order of Volatility
The principle of collecting digital evidence from the most short-lived source to the most persistent, from CPU state and RAM down to archived media.
OverlayFS
OverlayFS is the Linux union filesystem that stacks read-only lower layers under a writable upper layer, used by Docker and containerd for container images.
Super Timeline
A super timeline merges timestamps from filesystem metadata, logs and application artifacts into one chronological view, typically built with Plaso.
systemd Journal (journald)
The systemd journal is the binary, indexed log store written by systemd-journald, holding structured log entries with trusted metadata fields.
UAC (Unix-like Artifacts Collector)
UAC is an open source shell-script triage collector that gathers live-response data and forensic artifacts from Linux and other Unix-like systems.
Volatility 3
Volatility 3 is the open source Python 3 memory forensics framework used to analyse Linux, Windows and macOS RAM images through symbol-driven plugins.
wtmp and btmp
wtmp and btmp are binary Linux login records: wtmp stores logins, logouts and reboots, while btmp stores failed login attempts for lastb.