Mapa del sitio
Todas las páginas de Linux Forensics.
Inicio
Áreas de investigación
Guías
- Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts
- Container Forensics: Docker, containerd and Podman on Linux
- ext4 and XFS Timestamps, Inodes and Deleted Files
- Hunting Linux Persistence: Cron, systemd, SSH and More
- Linux Log Forensics: syslog, journald, wtmp and auditd
- Linux Memory Forensics with LiME, AVML and Volatility 3
- Building a Linux Super Timeline with Plaso and mactime
- Linux Live Response: Triage Through /proc and Volatile Data
- Package Manager Forensics on Linux: dpkg, APT, RPM and DNF
- Linux Shell History and User Activity Forensics
- Linux Triage Collection with UAC and Velociraptor
Artefactos
- /etc/hosts, nsswitch.conf and resolv.conf on Linux
- /etc/ld.so.preload y LD_PRELOAD: secuestro del enlazador
- /etc/passwd, shadow and group: Linux Local Accounts
- /tmp, /var/tmp and /dev/shm: Linux Staging Directories
- Apache and Nginx Logs: Linux Web Server Forensics
- AppArmor and SELinux Denials: Linux MAC Audit Logs
- Artefactos en vivo de /proc: procesos, sockets y borrados
- Artefactos SSH: authorized_keys, known_hosts y logs
- auditd audit.log: registro de auditoría del kernel
- auth.log, secure y syslog: logs de texto de Linux
- Browser Profiles on Linux: Firefox and Chrome History
- cloud-init Logs and Instance Data: Linux Cloud VM Forensics
- Cron, anacron, at y timers de systemd en Linux
- dmesg, kern.log and the Kernel Ring Buffer on Linux
- Docker, containerd and Podman Artifacts on Linux Hosts
- dpkg, APT, RPM and DNF Logs: Linux Package History
- eBPF Programs and Pinned Maps: Linux Kernel Implants
- Historial de la shell: comandos de bash, zsh y fish
- Journal de systemd: el registro binario de Linux
- Linux Crash Reports and Core Dumps: coredump, apport
- Linux Firewall Logs: iptables, nftables, ufw, firewalld
- Linux Kernel Modules: lsmod, Taint Flags and Boot Config
- Linux Memory Acquisition: LiME, AVML and /proc/kcore
- Linux Thumbnail Cache: ~/.cache/thumbnails Forensics
- Linux Trash: freedesktop .trashinfo Files and Deleted Items
- logrotate State and Log Gaps: Detecting Linux Log Tampering
- Logs de sudo: uso de privilegios en Linux
- Marcas de tiempo de ext4, crtime y archivos borrados
- MySQL, MariaDB and PostgreSQL Logs: Linux Database Forensics
- NetworkManager Profiles and State: Linux Network History
- PAM Configuration and Modules: Linux Auth Backdoors
- rc.local, SysV init.d and MOTD Scripts: Linux Boot Hooks
- recently-used.xbel: GNOME and GTK Recent Files on Linux
- Shell Startup Files: Linux bashrc and profile Persistence
- Snap and Flatpak Artifacts: Linux Sandboxed App Forensics
- SUID, SGID and File Capabilities: Linux Privilege Backdoors
- sysctl, Boot Parameters and binfmt_misc on Linux
- Tracker / LocalSearch DB: GNOME File Index on Linux
- udev and USB Device History on Linux
- Unidades systemd: persistencia de servicios en Linux
- viminfo, ShaDa and lesshst: Linux Editor and Pager History
- Web Shells in the Web Root: Finding Them on Linux Servers
- wtmp, btmp, utmp y lastlog: registros de login en Linux
- XDG Autostart .desktop Entries: Linux Desktop Persistence
- XFS Forensics: Inode Timestamps, crtime and Deleted Files