Aller au contenu

Artefacts forensiques Linux

Une page par artefact : emplacement sur Debian, Ubuntu et la famille RHEL, ce qu'il prouve, format des horodatages, durée de conservation, collecte et analyse avec des outils open source.

Les artefacts les plus utilisés sont traduits. Les entrées marquées « Anglais » ouvrent la page en anglais.

Exécution

Persistance

Accès aux fichiers

Activité utilisateur

Réseau

  • /etc/hosts, nsswitch.conf and resolv.conf on LinuxAnglais

    Linux name resolution files as evidence: /etc/hosts redirects, resolv.conf and systemd-resolved DNS changes, and NSS module backdoors in nsswitch.conf.

    /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory

  • Linux Firewall Logs: iptables, nftables, ufw, firewalldAnglais

    Netfilter packet log lines from iptables, nftables, ufw and firewalld, plus firewall rule files that reveal tampering, on Debian, Ubuntu and RHEL hosts.

    /var/log/ufw.log, /var/log/kern.log

  • NetworkManager Profiles and State: Linux Network HistoryAnglais

    NetworkManager connection profiles, timestamps, seen BSSIDs and DHCP leases on Linux: which networks, VPNs and Wi-Fi a host joined and when.

    /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/

USB et périphériques

  • udev and USB Device History on LinuxAnglais

    Reconstruct USB device connections on Linux from kernel, udisks and USBGuard logs, and check udev rules used for RUN+= persistence.

    /etc/udev/rules.d/, /var/log/kern.log

Anti-forensique

  • logrotate State and Log Gaps: Detecting Linux Log TamperingAnglais

    logrotate configuration and state files on Linux: how rotation shapes what logs survive, how to tell normal rotation from deletion, and postrotate persistence.

    /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)

Journaux

  • Apache and Nginx Logs: Linux Web Server ForensicsAnglais

    Apache httpd and nginx access and error logs on Linux: log formats, paths per distro, rotation and how to hunt web shells and exploitation.

    /var/log/apache2/, /var/log/httpd/, /var/log/nginx/

  • AppArmor and SELinux Denials: Linux MAC Audit LogsAnglais

    SELinux AVC and AppArmor DENIED records on Linux: where they are logged, how to read them, and how they expose web shells, exploits and disabled enforcement.

    /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal

  • auditd audit.log : la piste d'audit du noyau Linux

    Le journal d'audit Linux écrit par auditd : connexions PAM, appels système, arguments execve et fichiers surveillés, liés à l'utilisateur d'origine (auid).

    /var/log/audit/audit.log

  • auth.log, secure et syslog : journaux texte Linux

    Journaux texte rsyslog : auth.log et syslog sous Debian/Ubuntu, secure et messages sous RHEL, avec les pièges de rotation et de format d'horodatage.

    /var/log/auth.log, /var/log/secure

  • cloud-init Logs and Instance Data: Linux Cloud VM ForensicsAnglais

    cloud-init on Linux cloud VMs: cloud-init.log, output log, user-data, per-instance state and boot scripts that record provisioning, SSH keys and persistence.

    /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/

  • dmesg, kern.log and the Kernel Ring Buffer on LinuxAnglais

    The Linux kernel log: dmesg ring buffer, kern.log, messages, journal and pstore, plus the segfault, OOM kill and promiscuous mode lines that matter.

    /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)

  • dpkg, APT, RPM and DNF Logs: Linux Package HistoryAnglais

    Linux package manager logs and databases (dpkg, APT, RPM, DNF, YUM) that date software installs and removals and record who ran them.

    /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log

  • Journal systemd : le journal binaire de Linux

    Le journal binaire systemd-journald : entrées structurées, champs processus fiables, horodatages UTC à la microseconde, souvent le seul journal système.

    /var/log/journal/<machine-id>/

  • MySQL, MariaDB and PostgreSQL Logs: Linux Database ForensicsAnglais

    Database server evidence on Linux: MySQL/MariaDB error, general and binary logs, PostgreSQL server logs, client history files and the plugins attackers abuse.

    /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)