Artefacts forensiques Linux
Une page par artefact : emplacement sur Debian, Ubuntu et la famille RHEL, ce qu'il prouve, format des horodatages, durée de conservation, collecte et analyse avec des outils open source.
Les artefacts les plus utilisés sont traduits. Les entrées marquées « Anglais » ouvrent la page en anglais.
Exécution
/tmp, /var/tmp and /dev/shm: Linux Staging DirectoriesAnglais
World-writable Linux directories attackers use to stage tools: tmpfs versus disk, cleanup ages, noexec, memfd fileless execution and what survives reboot.
/tmp, /var/tmp, /dev/shm, /run/user/<uid>
Artefacts live de /proc : processus, sockets, suppressions
Le pseudo-système /proc d'un hôte Linux live : lignes de commande, environnement, fichiers ouverts, mappages mémoire, sockets et binaires supprimés.
/proc/<pid>/
Docker, containerd and Podman Artifacts on Linux HostsAnglais
Container evidence on a Linux host: Docker config.v2.json and JSON logs, overlay2 upper layers, containerd snapshots, Podman storage and Kubernetes pod logs.
/var/lib/docker/containers/<id>/
Historique du shell : commandes bash, zsh et fish
Historique des commandes par utilisateur de bash, zsh et fish : contenu de chaque fichier, présence des horodatages et traces d'évasion de l'historique.
~/.bash_history
Journaux sudo : traces d'usage de privilèges Linux
Comment sudo enregistre qui a exécuté quoi en root sous Linux : lignes syslog et journal, fichier de log optionnel, sessions enregistrées et règles sudoers.
/var/log/auth.log, /var/log/secure
Linux Crash Reports and Core Dumps: coredump, apportAnglais
systemd-coredump, Ubuntu apport, ABRT and kdump on Linux: where crash data lands and how it exposes failed exploits and unstable implants.
/var/lib/systemd/coredump/, /var/crash/
Linux Memory Acquisition: LiME, AVML and /proc/kcoreAnglais
Capturing Linux RAM with LiME or AVML: memory sources, output formats, lockdown limits and the Volatility 3 symbol tables needed to analyse the image.
/proc/kcore, /dev/crash, /dev/mem
Snap and Flatpak Artifacts: Linux Sandboxed App ForensicsAnglais
Snap and Flatpak evidence on Linux: snapd state.json change history, sideloaded snaps, Flatpak installations and remotes, and per-app data directories.
/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/
Persistance
/etc/ld.so.preload et LD_PRELOAD : détournement du linker
Fichier de préchargement de l'éditeur de liens, LD_PRELOAD et ld.so.conf : comment les rootkits userland injectent des bibliothèques et comment les repérer.
/etc/ld.so.preload
/etc/passwd, shadow and group: Linux Local AccountsAnglais
Linux local account databases (passwd, shadow, group, gshadow and their backups) that reveal rogue accounts, UID 0 clones and password change dates.
/etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
Artefacts SSH : authorized_keys, known_hosts, logs sshd
Artefacts OpenSSH sous Linux (authorized_keys, known_hosts, configuration, clés d'hôte, logs sshd) : accès distant, persistance par clé et mouvement latéral.
~/.ssh/authorized_keys
Cron, anacron, at et timers systemd : planification
Artefacts de planification Linux (crontabs, horodatages anacron, tâches at, timers systemd) qui révèlent la persistance planifiée et prouvent les exécutions.
/var/spool/cron/
eBPF Programs and Pinned Maps: Linux Kernel ImplantsAnglais
Loaded eBPF programs, pinned objects in /sys/fs/bpf and their loaders on disk: how eBPF rootkits and BPF backdoors hide on Linux and how to find them.
Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk
Linux Kernel Modules: lsmod, Taint Flags and Boot ConfigAnglais
Loaded and configured Linux kernel modules (/proc/modules, /sys/module, modules-load.d, modprobe.d, taint flags) for spotting rootkits and module persistence.
/proc/modules
PAM Configuration and Modules: Linux Auth BackdoorsAnglais
Linux PAM stacks in /etc/pam.d and the pam_*.so modules they load: where attackers plant password loggers and master passwords, and how to verify them.
/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)
rc.local, SysV init.d and MOTD Scripts: Linux Boot HooksAnglais
Legacy Linux boot and login script locations (rc.local, /etc/init.d, rc?.d links, Upstart jobs, update-motd.d) and how they reveal persistence.
/etc/rc.local
Shell Startup Files: Linux bashrc and profile PersistenceAnglais
System and per-user shell startup files (profile, bashrc, zshrc, logout) on Linux: load order, where attackers hide persistence and how to review them.
/etc/profile.d/
SUID, SGID and File Capabilities: Linux Privilege BackdoorsAnglais
SUID/SGID bits and file capabilities (security.capability) on Linux: how attackers plant root backdoors and how to baseline them against packages.
Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system
sysctl, Boot Parameters and binfmt_misc on LinuxAnglais
Linux kernel settings in sysctl.d, /proc/sys and the boot command line: core_pattern and modprobe hijacks, weakened protections, ip_forward, binfmt_misc.
/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/
Unités systemd : persistance des services Linux
Fichiers service, timer et drop-in systemd, liens d'activation, générateurs et lingering : où sont définis les services Linux et comment repérer la persistance.
/etc/systemd/system/
Web Shells in the Web Root: Finding Them on Linux ServersAnglais
Where Linux web roots live per distro, how PHP, JSP and CGI web shells and .htaccess or module backdoors look on disk, and how to date and hunt them.
/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps
XDG Autostart .desktop Entries: Linux Desktop PersistenceAnglais
XDG autostart entries in /etc/xdg/autostart and ~/.config/autostart that launch programs at every graphical login, plus KDE and X session hooks.
~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop
Accès aux fichiers
Horodatages ext4, crtime et fichiers supprimés
Horodatages d'inode ext4 (atime, mtime, ctime, crtime, dtime) à la nanoseconde, relatime, journal jbd2 et limites de la récupération des fichiers supprimés.
/dev/<ext4-partition>
Linux Thumbnail Cache: ~/.cache/thumbnails ForensicsAnglais
The freedesktop thumbnail cache on Linux: PNG previews named by the MD5 of the file URI, holding path and mtime, that outlive deleted files.
~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/
Linux Trash: freedesktop .trashinfo Files and Deleted ItemsAnglais
The freedesktop.org Trash on Linux desktops: .trashinfo records with original path and deletion time, the trashed files themselves and per-volume trash folders.
~/.local/share/Trash/{files,info}/
recently-used.xbel: GNOME and GTK Recent Files on LinuxAnglais
The freedesktop recently-used.xbel file on Linux desktops: which files and URIs a user opened through GTK (and newer KDE) applications, with UTC times.
~/.local/share/recently-used.xbel
Tracker / LocalSearch DB: GNOME File Index on LinuxAnglais
GNOME's Tracker and LocalSearch file index on Linux: SQLite databases listing indexed files, their timestamps and extracted content for a user's home.
~/.cache/tracker3/files/
viminfo, ShaDa and lesshst: Linux Editor and Pager HistoryAnglais
Vim viminfo, Neovim ShaDa and less history files on Linux: which files a user edited, what they searched for and typed, often after shell history is wiped.
~/.viminfo
XFS Forensics: Inode Timestamps, crtime and Deleted FilesAnglais
XFS on RHEL-family Linux: v5 inode timestamps with crtime, bigtime, xfs_db inspection, the metadata log, and what remains after a file is deleted.
/dev/<xfs-volume>
Activité utilisateur
Browser Profiles on Linux: Firefox and Chrome HistoryAnglais
Firefox and Chrome/Chromium profile databases on Linux, including snap and Flatpak paths: history, downloads, epochs and how to query them offline.
~/.mozilla/firefox/<profile>/places.sqlite
wtmp, btmp, utmp et lastlog : connexions Linux
Enregistrements de connexion Linux : historique wtmp, échecs btmp, sessions en cours utmp, dernière connexion lastlog et leurs successeurs wtmpdb/lastlog2.
/var/log/wtmp
Réseau
/etc/hosts, nsswitch.conf and resolv.conf on LinuxAnglais
Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.
/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory
Linux Firewall Logs: iptables, nftables, ufw, firewalldAnglais
Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.
/var/log/ufw.log, /var/log/kern.log
NetworkManager Profiles and State: Linux Network HistoryAnglais
NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.
/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/
USB et périphériques
udev and USB Device History on LinuxAnglais
Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.
/etc/udev/rules.d/, /var/log/kern.log
Anti-forensique
logrotate State and Log Gaps: Detecting Linux Log TamperingAnglais
logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.
/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)
Journaux
Apache and Nginx Logs: Linux Web Server ForensicsAnglais
Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.
/var/log/apache2/, /var/log/httpd/, /var/log/nginx/
AppArmor and SELinux Denials: Linux MAC Audit LogsAnglais
SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.
/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal
auditd audit.log : la piste d'audit du noyau Linux
Le journal d'audit Linux écrit par auditd : connexions PAM, appels système, arguments execve et fichiers surveillés, liés à l'utilisateur d'origine (auid).
/var/log/audit/audit.log
auth.log, secure et syslog : journaux texte Linux
Journaux texte rsyslog : auth.log et syslog sous Debian/Ubuntu, secure et messages sous RHEL, avec les pièges de rotation et de format d'horodatage.
/var/log/auth.log, /var/log/secure
cloud-init Logs and Instance Data: Linux Cloud VM ForensicsAnglais
cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.
/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/
dmesg, kern.log and the Kernel Ring Buffer on LinuxAnglais
The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.
/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)
dpkg, APT, RPM and DNF Logs: Linux Package HistoryAnglais
Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.
/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log
Journal systemd : le journal binaire de Linux
Le journal binaire systemd-journald : entrées structurées, champs processus fiables, horodatages UTC à la microseconde, souvent le seul journal système.
/var/log/journal/<machine-id>/
MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsAnglais
Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.
/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)