Aller au contenu

Guides

Guides approfondis d'investigation et de réponse à incident Linux, de l'acquisition des preuves à la super-chronologie.

Ces guides sont pour l'instant publiés en anglais uniquement. Les liens ci-dessous ouvrent la version anglaise.

05 · Système de fichiers & horodatagesAnglais

ext4 and XFS Timestamps, Inodes and Deleted Files

How to read MAC and birth timestamps on ext4 and XFS, spot timestomping through ctime, and understand the real limits of deleted file recovery on Linux.

ext4xfstimestamps
04 · PersistanceAnglais

Hunting Linux Persistence: Cron, systemd, SSH and More

Where attackers hide persistence on Linux (cron, systemd units and timers, shell startup files, SSH keys, ld.so.preload, PAM, udev, modules) and how to find it.

persistencecronsystemd
06 · Forensique mémoireAnglais

Linux Memory Forensics with LiME, AVML and Volatility 3

Acquire Linux RAM with LiME or AVML, build Volatility 3 symbol tables with dwarf2json, and find hidden processes, rootkit modules and bash history in memory.

memory-forensicsvolatilitylime
09 · Analyse chronologiqueAnglais

Building a Linux Super Timeline with Plaso and mactime

Build a Linux forensic super timeline with TSK mactime and Plaso: log2timeline, psort and pinfo, Linux parsers, time slicing, UTC and Timesketch.

timelineplasolog2timeline
03 · Activité utilisateurAnglais

Linux Shell History and User Activity Forensics

Reconstruct what a user did on a Linux host from bash, zsh and fish history, dotfiles, SSH files, sudo logs and account databases, and spot history evasion.

shell-historybashuser-activity
01 · Acquisition & triAnglais

Linux Triage Collection with UAC and Velociraptor

Run fast, repeatable Linux triage with UAC profiles and Velociraptor Linux artifacts: what each collects, offline collectors, hunts and what to grab first.

triageuacvelociraptor