Aide-mémoire des artefacts Linux
Tous les artefacts sur un seul tableau, regroupés par catégorie. Imprimez en paysage ou enregistrez en PDF depuis votre navigateur.
www.linuxforensics.app/fr/artifacts
Les artefacts les plus utilisés sont traduits. Les entrées marquées « Anglais » ouvrent la page en anglais.
| Artefact | Emplacement | Prouve | Horodatages | Accès | Rétention | Analyse |
|---|---|---|---|---|---|---|
| Exécution | ||||||
| /tmp, /var/tmp and /dev/shmAnglaisDebian · RHEL · SUSE · Arch | /tmp, /var/tmp, /dev/shm, /run/user/<uid> | That files were dropped or run from world-writable locations, by which user and when | Inode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM only | Any user can write; root needed to read other users' files (mode 1777 with sticky bit) | tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deleted | find, stat, debugfs, The Sleuth Kit, Velociraptor |
| Artefacts live de /procDebian · RHEL · SUSE · Arch | /proc/<pid>/ | Ce qui s'exécute en ce moment, depuis quel binaire, avec quels arguments, fichiers et connexions réseau | Aucun horodatage de fichier utile ; heure de démarrage du processus en ticks d'horloge depuis le boot (/proc/<pid>/stat champ 22) | root pour voir exe, environ, fd et maps de tous les processus ; les autres utilisateurs ne voient que les leurs | Volatile : disparaît à la fin du processus ou au redémarrage | ps, ss, lsof, Velociraptor, Volatility 3 |
| Docker, containerd and Podman Artifacts on Linux HostsAnglaisDebian · RHEL · SUSE · Arch | /var/lib/docker/containers/<id>/ | Which containers ran, from which image and command, with which privileges, what they printed and which files they changed | RFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layers | root (or docker group, which is root-equivalent); rootless Podman data is owned by the user | Until the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file set | container-explorer, jq, docker, crictl, ctr |
| Historique du shellDebian · RHEL · SUSE · Arch | ~/.bash_history | Quelles commandes ont été saisies dans un shell interactif sous un compte donné, et parfois quand | Secondes epoch Unix (UTC) si enregistrées : bash seulement avec HISTTIMEFORMAT, zsh avec EXTENDED_HISTORY, fish toujours | Tout utilisateur pour ses propres fichiers ; root pour les répertoires personnels des autres | Jusqu'à troncature par HISTFILESIZE/SAVEHIST ou suppression | Plaso, Volatility 3, Velociraptor |
| Journaux sudoDebian · RHEL · SUSE · Arch | /var/log/auth.log, /var/log/secure | Quel compte a exécuté quelle commande sous quel utilisateur cible, depuis quel terminal et quel répertoire, ainsi que les tentatives échouées | Heure syslog/journal de l'hôte (voir les formats syslog) ; les journaux I/O conservent une chronologie relative par session | root (ou groupe adm pour auth.log sous Debian/Ubuntu) | Suit la rotation d'auth.log/secure et les limites du journal ; journaux I/O jusqu'à suppression | grep/zgrep, journalctl, sudoreplay, ausearch, Plaso |
| Linux Crash Reports and Core DumpsAnglaisDebian · RHEL · SUSE · Arch | /var/lib/systemd/coredump/, /var/crash/ | Which program crashed, when, as which user, with which command line, and what its memory held at that moment | Journal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctime | root; per-user cores readable by the owning user through coredumpctl | systemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 days | coredumpctl, gdb, getfattr, apport-unpack, crash |
| Linux Memory AcquisitionAnglaisDebian · RHEL · SUSE · Arch | /proc/kcore, /dev/crash, /dev/mem | Running processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not show | Capture time from your case log; in-memory structures carry their own times (process start as time since boot) | root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEM | Volatile: lost at power-off; changes continuously while the host runs | Volatility 3, dwarf2json, AVML, LiME |
| Snap and Flatpak ArtifactsAnglaisDebian · RHEL · SUSE · Arch | /var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/ | Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user data | RFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file times | root for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each user | Installed apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journal | snap, flatpak, jq, journalctl, find |
| Persistance | ||||||
| /etc/ld.so.preload et LD_PRELOADDebian · RHEL · SUSE · Arch | /etc/ld.so.preload | Qu'une bibliothèque partagée a été imposée aux processus liés dynamiquement, laquelle, et depuis quand | mtime/ctime/crtime du fichier de préchargement et de la bibliothèque ; aucun horodatage interne | root pour écrire ; lisible par tous ; peut être masqué aux outils live par le rootkit lui-même | Jusqu'à suppression ; LD_PRELOAD dans l'environnement d'un processus disparaît à la fin du processus | debugfs, UAC, Volatility 3, Velociraptor |
| /etc/passwd, shadow and groupAnglaisDebian · RHEL · SUSE · Arch | /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow | Which local accounts and group memberships exist, which can log in, and when each password was last changed | shadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal time | passwd and group: any user; shadow and gshadow: root | Until changed; one backup generation (passwd-, shadow-, group-, gshadow-) | awk, pwck -r, grpck -r, Velociraptor, ausearch |
| Artefacts SSHDebian · RHEL · SUSE · Arch | ~/.ssh/authorized_keys | Quelles clés peuvent se connecter à un compte, vers où un utilisateur s'est connecté, et qui s'est connecté en SSH et d'où | Fichiers de clés : horodatages du système de fichiers uniquement ; journaux : heure locale syslog ou usec du journal depuis l'epoch Unix (UTC) | root (ou le titulaire du compte pour son propre ~/.ssh) ; groupe adm/systemd-journal pour les journaux | Fichiers de clés jusqu'à suppression ; lignes de journal selon la rotation syslog et les limites du journal | ssh-keygen, Velociraptor, UAC, grep |
| Cron, anacron, at et timers systemdDebian · RHEL · SUSE · Arch | /var/spool/cron/ | Quelles commandes étaient planifiées, par quel compte, et quand cron, anacron ou un timer les a lancées pour la dernière fois | mtime/ctime des fichiers ; heure syslog ou journal pour les exécutions ; horodatages anacron en date locale AAAAMMJJ | root pour tous les répertoires de spool ; tout utilisateur pour sa propre crontab via crontab -l | Jusqu'à suppression ; les preuves d'exécution suivent la rotation de syslog/du journal | Velociraptor, UAC, grep, systemctl |
| eBPF Programs and Pinned MapsAnglaisDebian · RHEL · SUSE · Arch | Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk | Which eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores them | bpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file times | root (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks others | Programs live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on disk | bpftool, Volatility 3, ss, ausearch, readelf, find |
| Linux Kernel ModulesAnglaisDebian · RHEL · SUSE · Arch | /proc/modules | Which kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernel | Kernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file times | root; kernel addresses in /proc/modules are zeroed for unprivileged readers | Loaded state and taint until reboot; config files until deleted; log lines per journal/syslog limits | Volatility 3, modinfo, Velociraptor, UAC |
| PAM Configuration and ModulesAnglaisDebian · RHEL · SUSE · Arch | /etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch) | How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentials | File system times of stack files and modules; PAM messages in auth logs and the journal | root to modify; configuration world-readable, modules readable by all | Persistent until changed; package updates may overwrite a patched module | rpm, dpkg, debsums, authselect, find, grep / zgrep, strings |
| rc.local, SysV init.d and MOTD ScriptsAnglaisDebian · RHEL | /etc/rc.local | Whether a script was set to run as root at boot or at every login, and when it was placed there | File mtime/ctime/crtime only; execution times from journal or syslog | root to write; world-readable on most systems | Until deleted; execution evidence follows journal/syslog rotation | UAC, Velociraptor, grep, journalctl |
| Shell Startup FilesAnglaisDebian · RHEL · SUSE · Arch | /etc/profile.d/ | Whether code was set to run automatically each time a user or root starts or ends a shell session | None inside the files; use inode mtime/ctime/crtime (ext4, XFS v5) | root for /etc files; any user for own dotfiles; root to read other users' homes | Until modified or deleted; package upgrades may replace /etc defaults | Velociraptor, debsums, rpm -V |
| SUID, SGID and File CapabilitiesAnglaisDebian · RHEL · SUSE · Arch | Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system | Which executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package manager | Setting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or install | Readable by any user with stat/getcap; root to set | Persistent until the file is replaced or the bit removed; package updates reset package-owned files | find, getcap, getfattr, stat, rpm, dpkg, debsums |
| sysctl, Boot Parameters and binfmt_misc on LinuxAnglaisDebian · RHEL · SUSE · Arch | /etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/ | Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker code | File system times of configuration files only; live values carry no timestamp | root to change; most values world-readable in /proc/sys | Files persist; runtime changes via sysctl -w or /proc/sys writes are lost at reboot | sysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg |
| Unités systemdDebian · RHEL · SUSE · Arch | /etc/systemd/system/ | Quels services et timers sont configurés pour démarrer, ce qu'ils exécutent, et quand l'unité a été installée ou modifiée | mtime/ctime/crtime des fichiers ; entrées du journal en microsecondes depuis l'epoch Unix (UTC) | root pour les unités système ; tout utilisateur pour son propre ~/.config/systemd/user | Jusqu'à suppression ; les unités de /run sont perdues au redémarrage ; les démarrages/arrêts suivent les limites du journal | systemctl, systemd-analyze, Velociraptor, UAC |
| Web Shells in the Web RootAnglaisDebian · RHEL · SUSE · Arch | /var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps | That a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can do | File system times (birth time on ext4/XFS v5 dates the drop); first request time in access logs | Read as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or http | Until deleted; deployments and CMS updates may overwrite or remove files | find, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg |
| XDG Autostart .desktop EntriesAnglaisDebian · RHEL · SUSE · Arch | ~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop | Which programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was written | File system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessions | Any user for their own entries; root for /etc/xdg/autostart | Until the .desktop file is deleted; launch records follow journal retention | find, grep / zgrep, journalctl, systemctl, rpm, dpkg |
| Accès aux fichiers | ||||||
| Horodatages ext4, crtime et fichiers supprimésDebian · Arch | /dev/<ext4-partition> | Quand un fichier a été créé, modifié, changé et éventuellement lu ou supprimé, et parfois ce qu'il contenait | Secondes epoch Unix UTC plus nanosecondes dans les champs *_extra (inodes de 256 octets) ; i_dtime en secondes | Tout utilisateur pour stat sur les fichiers accessibles ; root ou accès brut au périphérique pour debugfs et les inodes supprimés | Horodatages jusqu'à écrasement ; inodes et blocs supprimés jusqu'à réutilisation ; le journal est un petit journal circulaire | debugfs, The Sleuth Kit, Plaso, ext4magic, stat |
| Linux Thumbnail CacheAnglaisDebian · RHEL · SUSE · Arch | ~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/ | That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked like | Thumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generated | Any user for their own cache (mode 0700 directories, 0600 files); root for other users | Until the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by default | ExifTool, find, stat |
| Linux TrashAnglaisDebian · RHEL · SUSE · Arch | ~/.local/share/Trash/{files,info}/ | Which file or folder a user sent to the Trash through a desktop application, from which original path, and when | DeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo file | Any user for their own Trash (directories mode 0700); root for other users | Until the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled) | gio, trash-cli, find, stat |
| recently-used.xbelAnglaisDebian · RHEL · SUSE · Arch | ~/.local/share/recently-used.xbel | Which local or remote files a desktop user opened or saved through GUI applications, with which app and when | ISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix seconds | Any user for own file (GTK sets mode 0600); root for other users | GTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by default | xmllint, Python ElementTree |
| Tracker / LocalSearch DBAnglaisDebian · RHEL · SUSE · Arch | ~/.cache/tracker3/files/ | Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexer | Unix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be kept | Any user for own cache; root for other users | Mirrors the indexed tree; entries removed when the indexer processes a deletion | tinysparql, sqlite3, localsearch |
| viminfo, ShaDa and lesshstAnglaisDebian · RHEL · SUSE · Arch | ~/.viminfo | Which files a user opened in vim or Neovim, and what they searched for or ran inside vim and less | Unix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshst | Any user for own files (created mode 0600); root for other users | Until deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100) | Plaso, Neovim, python-msgpack |
| XFS ForensicsAnglaisRHEL · SUSE | /dev/<xfs-volume> | When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files contained | Seconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystems | Any user for stat on accessible files; root or raw device access for xfs_db | Timestamps until overwritten; deleted inode extents and data blocks until reused | xfs_db, stat, libfsxfs, Plaso |
| Activité utilisateur | ||||||
| Browser Profiles on LinuxAnglaisDebian · RHEL · SUSE · Arch | ~/.mozilla/firefox/<profile>/places.sqlite | Which sites a user visited, what they downloaded and searched for, and when | Firefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC) | Any user for own profile; root for other users | Chrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pages | Hindsight, Plaso, sqlite3 |
| wtmp, btmp, utmp et lastlogDebian · RHEL · SUSE · Arch | /var/log/wtmp | Qui s'est connecté, sur quel terminal, depuis quel hôte, quand la session s'est terminée et quand le système a redémarré | Enregistrements utmp : secondes epoch Unix + microsecondes (champs 32 bits), UTC. wtmpdb : microsecondes depuis l'epoch | Lisibles par tous pour wtmp/utmp/lastlog ; root (ou groupe utmp) pour btmp | logrotate : mensuelle, 1 ancienne génération pour wtmp et btmp ; lastlog jusqu'à écrasement | last, lastb, utmpdump, wtmpdb, Plaso, Velociraptor |
| Réseau | ||||||
| /etc/hosts, nsswitch.conf and resolv.conf on LinuxAnglaisDebian · RHEL · SUSE · Arch | /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory | Where the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookups | File system times only; systemd-resolved and NetworkManager log DNS server changes to the journal | World-readable; root to modify | Persistent until edited; generated resolv.conf files are rewritten by the network stack | getent, resolvectl, grep / zgrep, rpm, dpkg, journalctl |
| Linux Firewall LogsAnglaisDebian · RHEL · SUSE · Arch | /var/log/ufw.log, /var/log/kern.log | Which connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changed | Syslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system times | root (or adm group for /var/log files on Debian/Ubuntu) | Follows syslog rotation and journal limits; rule files until changed | grep/zgrep, journalctl, nft, iptables-save, Plaso |
| NetworkManager Profiles and StateAnglaisDebian · RHEL · SUSE · Arch | /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/ | Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leased | Unix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode times | root (profiles are root-only 0600); journal: root or systemd-journal group | Profiles until deleted; state files overwritten in place; journal per its limits | grep, journalctl, nmcli (live), Plaso |
| USB et périphériques | ||||||
| udev and USB Device History on LinuxAnglaisDebian · RHEL · SUSE · Arch | /etc/udev/rules.d/, /var/log/kern.log | Which USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run code | Journal: UTC microseconds; syslog: host local time; dmesg: seconds since boot | root (or adm/systemd-journal group) for logs; rules readable by any user | Follows journal and kern.log/messages rotation; rules until deleted | journalctl, zgrep, udevadm, Plaso |
| Anti-forensique | ||||||
| logrotate State and Log GapsAnglaisDebian · RHEL · SUSE · Arch | /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL) | When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tampering | State file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixes | root | Configuration persistent; the state file is rewritten at every run and keeps one line per log | logrotate, stat, find, grep / zgrep, journalctl, systemctl |
| Journaux | ||||||
| Apache and Nginx LogsAnglaisDebian · RHEL | /var/log/apache2/, /var/log/httpd/, /var/log/nginx/ | Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell use | Local time with numeric UTC offset, second precision (default combined format) | root or adm group (Debian/Ubuntu); root (RHEL) | Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 kept | grep/zgrep, awk, GoAccess, lnav, Plaso |
| AppArmor and SELinux DenialsAnglaisDebian · RHEL · SUSE | /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal | Which confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched off | msg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal time | root (audit.log mode 0600; kernel log readable by adm or root depending on distro) | Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retention | ausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep |
| auditd audit.logDebian · RHEL · SUSE | /var/log/audit/audit.log | Quel utilisateur connecté a exécuté quel programme ou touché quel fichier surveillé, ainsi que chaque authentification et session PAM | Secondes epoch Unix avec millisecondes dans msg=audit(sec.msec:serial), en UTC | root (log_group vaut root par défaut) | Selon la taille : 8 Mio x 5 fichiers par défaut en amont, rotation assurée par auditd | ausearch, aureport, Plaso, Zircolite |
| auth.log, secure et syslogDebian · RHEL | /var/log/auth.log, /var/log/secure | Qui s'est authentifié, d'où, par quelle méthode, et ce que les services et le noyau ont signalé, en texte clair | Traditionnel : heure locale, sans année ni fuseau. RFC 3339 : heure locale avec décalage et microsecondes | root ou groupe adm (Debian/Ubuntu) ; root (RHEL) | logrotate : hebdomadaire, 4 générations par défaut sous Debian/Ubuntu et RHEL | grep/zgrep, Plaso, lnav |
| cloud-init Logs and Instance DataAnglaisDebian · RHEL · SUSE | /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/ | How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts run | Log lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished content | root for user-data and sensitive instance data; logs usually root-readable only or adm group | Logs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at reboot | cloud-init, jq, grep / zgrep, journalctl |
| dmesg, kern.log and the Kernel Ring Buffer on LinuxAnglaisDebian · RHEL · SUSE · Arch | /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k) | Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warnings | Ring buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTC | Ring buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm group | Ring buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by size | dmesg, journalctl, grep / zgrep |
| dpkg, APT, RPM and DNF LogsAnglaisDebian · RHEL | /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log | Which packages were installed, upgraded or removed, when, with which command line and by which sudo user | dpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC) | dpkg.log and apt/history.log are world-readable; root for complete collection | dpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removed | zgrep, sqlite3, rpm --root, dpkg --root, Plaso |
| Journal systemdDebian · RHEL · SUSE · Arch | /var/log/journal/<machine-id>/ | Ce que les services, processus, utilisateurs et le noyau ont journalisé, avec PID/UID/exécutable fiables et contexte de démarrage | Microsecondes depuis l'epoch Unix (UTC) pour realtime ; microsecondes depuis le démarrage pour monotonic | root (ou groupes systemd-journal, adm ou wheel) ; un utilisateur peut lire son propre journal user-UID | Selon la taille : 10 % du système de fichiers plafonné à 4G par défaut ; la copie volatile est perdue au redémarrage | journalctl, Plaso, Velociraptor |
| MySQL, MariaDB and PostgreSQL LogsAnglaisDebian · RHEL | /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL) | Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the database | MySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix seconds | root or the mysql/postgres service account; client history files owned by each user | Error logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by default | mysqlbinlog, pgBadger, grep / zgrep, journalctl |