Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts
How to acquire Linux evidence soundly: order of volatility, live vs dead acquisition, dd/dc3dd/ewfacquire imaging, cloud snapshots and read-only mounts.
Guides approfondis d'investigation et de réponse à incident Linux, de l'acquisition des preuves à la super-chronologie.
Ces guides sont pour l'instant publiés en anglais uniquement. Les liens ci-dessous ouvrent la version anglaise.
How to acquire Linux evidence soundly: order of volatility, live vs dead acquisition, dd/dc3dd/ewfacquire imaging, cloud snapshots and read-only mounts.
Investigate Docker, containerd and Podman hosts: container metadata, overlay2 upper layers, JSON logs, escape indicators and Kubernetes node log paths.
How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.
Where attackers hide persistence on Linux (cron, systemd units and timers, shell startup files, SSH keys, ld.so.preload, PAM, udev, modules) and how to find it.
How to analyse Linux logs in an investigation: rsyslog files, sshd and sudo lines, the journald binary journal, wtmp/btmp, auditd and tampering signs.
Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.
Build a Linux forensic super timeline with TSK mactime and Plaso: log2timeline, psort and pinfo, Linux parsers, time slicing, UTC and Timesketch.
A practical Linux live response workflow: trusted binaries, logging your actions, and triaging processes, sockets and modules through /proc before shutdown.
Use dpkg, APT, RPM and DNF logs and databases to date installs, verify file integrity and find binaries no package owns on a compromised Linux host.
Reconstruct what a user did on a Linux host from bash, zsh and fish history, dotfiles, SSH files, sudo logs and account databases, and spot history evasion.
Run fast, repeatable Linux triage with UAC profiles and Velociraptor Linux artifacts: what each collects, offline collectors, hunts and what to grab first.