Aller au contenu

Aide-mémoire des artefacts Linux

Tous les artefacts sur un seul tableau, regroupés par catégorie. Imprimez en paysage ou enregistrez en PDF depuis votre navigateur.

Les artefacts les plus utilisés sont traduits. Les entrées marquées « Anglais » ouvrent la page en anglais.

ArtefactEmplacementProuveHorodatagesAccèsRétentionAnalyse
Exécution
/tmp, /var/tmp and /dev/shmAnglaisDebian · RHEL · SUSE · Arch/tmp, /var/tmp, /dev/shm, /run/user/<uid>That files were dropped or run from world-writable locations, by which user and whenInode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM onlyAny user can write; root needed to read other users' files (mode 1777 with sticky bit)tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deletedfind, stat, debugfs, The Sleuth Kit, Velociraptor
Artefacts live de /procDebian · RHEL · SUSE · Arch/proc/<pid>/Ce qui s'exécute en ce moment, depuis quel binaire, avec quels arguments, fichiers et connexions réseauAucun horodatage de fichier utile ; heure de démarrage du processus en ticks d'horloge depuis le boot (/proc/<pid>/stat champ 22)root pour voir exe, environ, fd et maps de tous les processus ; les autres utilisateurs ne voient que les leursVolatile : disparaît à la fin du processus ou au redémarrageps, ss, lsof, Velociraptor, Volatility 3
Docker, containerd and Podman Artifacts on Linux HostsAnglaisDebian · RHEL · SUSE · Arch/var/lib/docker/containers/<id>/Which containers ran, from which image and command, with which privileges, what they printed and which files they changedRFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layersroot (or docker group, which is root-equivalent); rootless Podman data is owned by the userUntil the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file setcontainer-explorer, jq, docker, crictl, ctr
Historique du shellDebian · RHEL · SUSE · Arch~/.bash_historyQuelles commandes ont été saisies dans un shell interactif sous un compte donné, et parfois quandSecondes epoch Unix (UTC) si enregistrées : bash seulement avec HISTTIMEFORMAT, zsh avec EXTENDED_HISTORY, fish toujoursTout utilisateur pour ses propres fichiers ; root pour les répertoires personnels des autresJusqu'à troncature par HISTFILESIZE/SAVEHIST ou suppressionPlaso, Volatility 3, Velociraptor
Journaux sudoDebian · RHEL · SUSE · Arch/var/log/auth.log, /var/log/secureQuel compte a exécuté quelle commande sous quel utilisateur cible, depuis quel terminal et quel répertoire, ainsi que les tentatives échouéesHeure syslog/journal de l'hôte (voir les formats syslog) ; les journaux I/O conservent une chronologie relative par sessionroot (ou groupe adm pour auth.log sous Debian/Ubuntu)Suit la rotation d'auth.log/secure et les limites du journal ; journaux I/O jusqu'à suppressiongrep/zgrep, journalctl, sudoreplay, ausearch, Plaso
Linux Crash Reports and Core DumpsAnglaisDebian · RHEL · SUSE · Arch/var/lib/systemd/coredump/, /var/crash/Which program crashed, when, as which user, with which command line, and what its memory held at that momentJournal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctimeroot; per-user cores readable by the owning user through coredumpctlsystemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 dayscoredumpctl, gdb, getfattr, apport-unpack, crash
Linux Memory AcquisitionAnglaisDebian · RHEL · SUSE · Arch/proc/kcore, /dev/crash, /dev/memRunning processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not showCapture time from your case log; in-memory structures carry their own times (process start as time since boot)root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEMVolatile: lost at power-off; changes continuously while the host runsVolatility 3, dwarf2json, AVML, LiME
Snap and Flatpak ArtifactsAnglaisDebian · RHEL · SUSE · Arch/var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user dataRFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file timesroot for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each userInstalled apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journalsnap, flatpak, jq, journalctl, find
Persistance
/etc/ld.so.preload et LD_PRELOADDebian · RHEL · SUSE · Arch/etc/ld.so.preloadQu'une bibliothèque partagée a été imposée aux processus liés dynamiquement, laquelle, et depuis quandmtime/ctime/crtime du fichier de préchargement et de la bibliothèque ; aucun horodatage interneroot pour écrire ; lisible par tous ; peut être masqué aux outils live par le rootkit lui-mêmeJusqu'à suppression ; LD_PRELOAD dans l'environnement d'un processus disparaît à la fin du processusdebugfs, UAC, Volatility 3, Velociraptor
/etc/passwd, shadow and groupAnglaisDebian · RHEL · SUSE · Arch/etc/passwd, /etc/shadow, /etc/group, /etc/gshadowWhich local accounts and group memberships exist, which can log in, and when each password was last changedshadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal timepasswd and group: any user; shadow and gshadow: rootUntil changed; one backup generation (passwd-, shadow-, group-, gshadow-)awk, pwck -r, grpck -r, Velociraptor, ausearch
Artefacts SSHDebian · RHEL · SUSE · Arch~/.ssh/authorized_keysQuelles clés peuvent se connecter à un compte, vers où un utilisateur s'est connecté, et qui s'est connecté en SSH et d'oùFichiers de clés : horodatages du système de fichiers uniquement ; journaux : heure locale syslog ou usec du journal depuis l'epoch Unix (UTC)root (ou le titulaire du compte pour son propre ~/.ssh) ; groupe adm/systemd-journal pour les journauxFichiers de clés jusqu'à suppression ; lignes de journal selon la rotation syslog et les limites du journalssh-keygen, Velociraptor, UAC, grep
Cron, anacron, at et timers systemdDebian · RHEL · SUSE · Arch/var/spool/cron/Quelles commandes étaient planifiées, par quel compte, et quand cron, anacron ou un timer les a lancées pour la dernière foismtime/ctime des fichiers ; heure syslog ou journal pour les exécutions ; horodatages anacron en date locale AAAAMMJJroot pour tous les répertoires de spool ; tout utilisateur pour sa propre crontab via crontab -lJusqu'à suppression ; les preuves d'exécution suivent la rotation de syslog/du journalVelociraptor, UAC, grep, systemctl
eBPF Programs and Pinned MapsAnglaisDebian · RHEL · SUSE · ArchKernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on diskWhich eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores thembpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file timesroot (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks othersPrograms live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on diskbpftool, Volatility 3, ss, ausearch, readelf, find
Linux Kernel ModulesAnglaisDebian · RHEL · SUSE · Arch/proc/modulesWhich kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernelKernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file timesroot; kernel addresses in /proc/modules are zeroed for unprivileged readersLoaded state and taint until reboot; config files until deleted; log lines per journal/syslog limitsVolatility 3, modinfo, Velociraptor, UAC
PAM Configuration and ModulesAnglaisDebian · RHEL · SUSE · Arch/etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch)How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentialsFile system times of stack files and modules; PAM messages in auth logs and the journalroot to modify; configuration world-readable, modules readable by allPersistent until changed; package updates may overwrite a patched modulerpm, dpkg, debsums, authselect, find, grep / zgrep, strings
rc.local, SysV init.d and MOTD ScriptsAnglaisDebian · RHEL/etc/rc.localWhether a script was set to run as root at boot or at every login, and when it was placed thereFile mtime/ctime/crtime only; execution times from journal or syslogroot to write; world-readable on most systemsUntil deleted; execution evidence follows journal/syslog rotationUAC, Velociraptor, grep, journalctl
Shell Startup FilesAnglaisDebian · RHEL · SUSE · Arch/etc/profile.d/Whether code was set to run automatically each time a user or root starts or ends a shell sessionNone inside the files; use inode mtime/ctime/crtime (ext4, XFS v5)root for /etc files; any user for own dotfiles; root to read other users' homesUntil modified or deleted; package upgrades may replace /etc defaultsVelociraptor, debsums, rpm -V
SUID, SGID and File CapabilitiesAnglaisDebian · RHEL · SUSE · ArchInode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file systemWhich executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package managerSetting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or installReadable by any user with stat/getcap; root to setPersistent until the file is replaced or the bit removed; package updates reset package-owned filesfind, getcap, getfattr, stat, rpm, dpkg, debsums
sysctl, Boot Parameters and binfmt_misc on LinuxAnglaisDebian · RHEL · SUSE · Arch/etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker codeFile system times of configuration files only; live values carry no timestamproot to change; most values world-readable in /proc/sysFiles persist; runtime changes via sysctl -w or /proc/sys writes are lost at rebootsysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg
Unités systemdDebian · RHEL · SUSE · Arch/etc/systemd/system/Quels services et timers sont configurés pour démarrer, ce qu'ils exécutent, et quand l'unité a été installée ou modifiéemtime/ctime/crtime des fichiers ; entrées du journal en microsecondes depuis l'epoch Unix (UTC)root pour les unités système ; tout utilisateur pour son propre ~/.config/systemd/userJusqu'à suppression ; les unités de /run sont perdues au redémarrage ; les démarrages/arrêts suivent les limites du journalsystemctl, systemd-analyze, Velociraptor, UAC
Web Shells in the Web RootAnglaisDebian · RHEL · SUSE · Arch/var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webappsThat a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can doFile system times (birth time on ext4/XFS v5 dates the drop); first request time in access logsRead as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or httpUntil deleted; deployments and CMS updates may overwrite or remove filesfind, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg
XDG Autostart .desktop EntriesAnglaisDebian · RHEL · SUSE · Arch~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktopWhich programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was writtenFile system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessionsAny user for their own entries; root for /etc/xdg/autostartUntil the .desktop file is deleted; launch records follow journal retentionfind, grep / zgrep, journalctl, systemctl, rpm, dpkg
Accès aux fichiers
Horodatages ext4, crtime et fichiers supprimésDebian · Arch/dev/<ext4-partition>Quand un fichier a été créé, modifié, changé et éventuellement lu ou supprimé, et parfois ce qu'il contenaitSecondes epoch Unix UTC plus nanosecondes dans les champs *_extra (inodes de 256 octets) ; i_dtime en secondesTout utilisateur pour stat sur les fichiers accessibles ; root ou accès brut au périphérique pour debugfs et les inodes supprimésHorodatages jusqu'à écrasement ; inodes et blocs supprimés jusqu'à réutilisation ; le journal est un petit journal circulairedebugfs, The Sleuth Kit, Plaso, ext4magic, stat
Linux Thumbnail CacheAnglaisDebian · RHEL · SUSE · Arch~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked likeThumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generatedAny user for their own cache (mode 0700 directories, 0600 files); root for other usersUntil the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by defaultExifTool, find, stat
Linux TrashAnglaisDebian · RHEL · SUSE · Arch~/.local/share/Trash/{files,info}/Which file or folder a user sent to the Trash through a desktop application, from which original path, and whenDeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo fileAny user for their own Trash (directories mode 0700); root for other usersUntil the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled)gio, trash-cli, find, stat
recently-used.xbelAnglaisDebian · RHEL · SUSE · Arch~/.local/share/recently-used.xbelWhich local or remote files a desktop user opened or saved through GUI applications, with which app and whenISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix secondsAny user for own file (GTK sets mode 0600); root for other usersGTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by defaultxmllint, Python ElementTree
Tracker / LocalSearch DBAnglaisDebian · RHEL · SUSE · Arch~/.cache/tracker3/files/Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexerUnix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be keptAny user for own cache; root for other usersMirrors the indexed tree; entries removed when the indexer processes a deletiontinysparql, sqlite3, localsearch
viminfo, ShaDa and lesshstAnglaisDebian · RHEL · SUSE · Arch~/.viminfoWhich files a user opened in vim or Neovim, and what they searched for or ran inside vim and lessUnix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshstAny user for own files (created mode 0600); root for other usersUntil deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100)Plaso, Neovim, python-msgpack
XFS ForensicsAnglaisRHEL · SUSE/dev/<xfs-volume>When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files containedSeconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystemsAny user for stat on accessible files; root or raw device access for xfs_dbTimestamps until overwritten; deleted inode extents and data blocks until reusedxfs_db, stat, libfsxfs, Plaso
Activité utilisateur
Browser Profiles on LinuxAnglaisDebian · RHEL · SUSE · Arch~/.mozilla/firefox/<profile>/places.sqliteWhich sites a user visited, what they downloaded and searched for, and whenFirefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC)Any user for own profile; root for other usersChrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pagesHindsight, Plaso, sqlite3
wtmp, btmp, utmp et lastlogDebian · RHEL · SUSE · Arch/var/log/wtmpQui s'est connecté, sur quel terminal, depuis quel hôte, quand la session s'est terminée et quand le système a redémarréEnregistrements utmp : secondes epoch Unix + microsecondes (champs 32 bits), UTC. wtmpdb : microsecondes depuis l'epochLisibles par tous pour wtmp/utmp/lastlog ; root (ou groupe utmp) pour btmplogrotate : mensuelle, 1 ancienne génération pour wtmp et btmp ; lastlog jusqu'à écrasementlast, lastb, utmpdump, wtmpdb, Plaso, Velociraptor
Réseau
/etc/hosts, nsswitch.conf and resolv.conf on LinuxAnglaisDebian · RHEL · SUSE · Arch/etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directoryWhere the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookupsFile system times only; systemd-resolved and NetworkManager log DNS server changes to the journalWorld-readable; root to modifyPersistent until edited; generated resolv.conf files are rewritten by the network stackgetent, resolvectl, grep / zgrep, rpm, dpkg, journalctl
Linux Firewall LogsAnglaisDebian · RHEL · SUSE · Arch/var/log/ufw.log, /var/log/kern.logWhich connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changedSyslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system timesroot (or adm group for /var/log files on Debian/Ubuntu)Follows syslog rotation and journal limits; rule files until changedgrep/zgrep, journalctl, nft, iptables-save, Plaso
NetworkManager Profiles and StateAnglaisDebian · RHEL · SUSE · Arch/etc/NetworkManager/system-connections/, /var/lib/NetworkManager/Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leasedUnix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode timesroot (profiles are root-only 0600); journal: root or systemd-journal groupProfiles until deleted; state files overwritten in place; journal per its limitsgrep, journalctl, nmcli (live), Plaso
USB et périphériques
udev and USB Device History on LinuxAnglaisDebian · RHEL · SUSE · Arch/etc/udev/rules.d/, /var/log/kern.logWhich USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run codeJournal: UTC microseconds; syslog: host local time; dmesg: seconds since bootroot (or adm/systemd-journal group) for logs; rules readable by any userFollows journal and kern.log/messages rotation; rules until deletedjournalctl, zgrep, udevadm, Plaso
Anti-forensique
logrotate State and Log GapsAnglaisDebian · RHEL · SUSE · Arch/etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL)When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tamperingState file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixesrootConfiguration persistent; the state file is rewritten at every run and keeps one line per loglogrotate, stat, find, grep / zgrep, journalctl, systemctl
Journaux
Apache and Nginx LogsAnglaisDebian · RHEL/var/log/apache2/, /var/log/httpd/, /var/log/nginx/Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell useLocal time with numeric UTC offset, second precision (default combined format)root or adm group (Debian/Ubuntu); root (RHEL)Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 keptgrep/zgrep, awk, GoAccess, lnav, Plaso
AppArmor and SELinux DenialsAnglaisDebian · RHEL · SUSE/var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journalWhich confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched offmsg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal timeroot (audit.log mode 0600; kernel log readable by adm or root depending on distro)Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retentionausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep
auditd audit.logDebian · RHEL · SUSE/var/log/audit/audit.logQuel utilisateur connecté a exécuté quel programme ou touché quel fichier surveillé, ainsi que chaque authentification et session PAMSecondes epoch Unix avec millisecondes dans msg=audit(sec.msec:serial), en UTCroot (log_group vaut root par défaut)Selon la taille : 8 Mio x 5 fichiers par défaut en amont, rotation assurée par auditdausearch, aureport, Plaso, Zircolite
auth.log, secure et syslogDebian · RHEL/var/log/auth.log, /var/log/secureQui s'est authentifié, d'où, par quelle méthode, et ce que les services et le noyau ont signalé, en texte clairTraditionnel : heure locale, sans année ni fuseau. RFC 3339 : heure locale avec décalage et microsecondesroot ou groupe adm (Debian/Ubuntu) ; root (RHEL)logrotate : hebdomadaire, 4 générations par défaut sous Debian/Ubuntu et RHELgrep/zgrep, Plaso, lnav
cloud-init Logs and Instance DataAnglaisDebian · RHEL · SUSE/var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts runLog lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished contentroot for user-data and sensitive instance data; logs usually root-readable only or adm groupLogs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at rebootcloud-init, jq, grep / zgrep, journalctl
dmesg, kern.log and the Kernel Ring Buffer on LinuxAnglaisDebian · RHEL · SUSE · Arch/dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k)Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warningsRing buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTCRing buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm groupRing buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by sizedmesg, journalctl, grep / zgrep
dpkg, APT, RPM and DNF LogsAnglaisDebian · RHEL/var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.logWhich packages were installed, upgraded or removed, when, with which command line and by which sudo userdpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC)dpkg.log and apt/history.log are world-readable; root for complete collectiondpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removedzgrep, sqlite3, rpm --root, dpkg --root, Plaso
Journal systemdDebian · RHEL · SUSE · Arch/var/log/journal/<machine-id>/Ce que les services, processus, utilisateurs et le noyau ont journalisé, avec PID/UID/exécutable fiables et contexte de démarrageMicrosecondes depuis l'epoch Unix (UTC) pour realtime ; microsecondes depuis le démarrage pour monotonicroot (ou groupes systemd-journal, adm ou wheel) ; un utilisateur peut lire son propre journal user-UIDSelon la taille : 10 % du système de fichiers plafonné à 4G par défaut ; la copie volatile est perdue au redémarragejournalctl, Plaso, Velociraptor
MySQL, MariaDB and PostgreSQL LogsAnglaisDebian · RHEL/var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL)Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the databaseMySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix secondsroot or the mysql/postgres service account; client history files owned by each userError logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by defaultmysqlbinlog, pgBadger, grep / zgrep, journalctl