Plan du site
Toutes les pages de Linux Forensics.
Accueil
Domaines d'investigation
Guides
- Acquiring Linux Evidence: Disk Imaging and Read-Only Mounts
- Container Forensics: Docker, containerd and Podman on Linux
- ext4 and XFS Timestamps, Inodes and Deleted Files
- Hunting Linux Persistence: Cron, systemd, SSH and More
- Linux Log Forensics: syslog, journald, wtmp and auditd
- Linux Memory Forensics with LiME, AVML and Volatility 3
- Building a Linux Super Timeline with Plaso and mactime
- Linux Live Response: Triage Through /proc and Volatile Data
- Package Manager Forensics on Linux: dpkg, APT, RPM and DNF
- Linux Shell History and User Activity Forensics
- Linux Triage Collection with UAC and Velociraptor
Artefacts
- /etc/hosts, nsswitch.conf and resolv.conf on Linux
- /etc/ld.so.preload et LD_PRELOAD : détournement du linker
- /etc/passwd, shadow and group: Linux Local Accounts
- /tmp, /var/tmp and /dev/shm: Linux Staging Directories
- Apache and Nginx Logs: Linux Web Server Forensics
- AppArmor and SELinux Denials: Linux MAC Audit Logs
- Artefacts live de /proc : processus, sockets, suppressions
- Artefacts SSH : authorized_keys, known_hosts, logs sshd
- auditd audit.log : la piste d'audit du noyau Linux
- auth.log, secure et syslog : journaux texte Linux
- Browser Profiles on Linux: Firefox and Chrome History
- cloud-init Logs and Instance Data: Linux Cloud VM Forensics
- Cron, anacron, at et timers systemd : planification
- dmesg, kern.log and the Kernel Ring Buffer on Linux
- Docker, containerd and Podman Artifacts on Linux Hosts
- dpkg, APT, RPM and DNF Logs: Linux Package History
- eBPF Programs and Pinned Maps: Linux Kernel Implants
- Historique du shell : commandes bash, zsh et fish
- Horodatages ext4, crtime et fichiers supprimés
- Journal systemd : le journal binaire de Linux
- Journaux sudo : traces d'usage de privilèges Linux
- Linux Crash Reports and Core Dumps: coredump, apport
- Linux Firewall Logs: iptables, nftables, ufw, firewalld
- Linux Kernel Modules: lsmod, Taint Flags and Boot Config
- Linux Memory Acquisition: LiME, AVML and /proc/kcore
- Linux Thumbnail Cache: ~/.cache/thumbnails Forensics
- Linux Trash: freedesktop .trashinfo Files and Deleted Items
- logrotate State and Log Gaps: Detecting Linux Log Tampering
- MySQL, MariaDB and PostgreSQL Logs: Linux Database Forensics
- NetworkManager Profiles and State: Linux Network History
- PAM Configuration and Modules: Linux Auth Backdoors
- rc.local, SysV init.d and MOTD Scripts: Linux Boot Hooks
- recently-used.xbel: GNOME and GTK Recent Files on Linux
- Shell Startup Files: Linux bashrc and profile Persistence
- Snap and Flatpak Artifacts: Linux Sandboxed App Forensics
- SUID, SGID and File Capabilities: Linux Privilege Backdoors
- sysctl, Boot Parameters and binfmt_misc on Linux
- Tracker / LocalSearch DB: GNOME File Index on Linux
- udev and USB Device History on Linux
- Unités systemd : persistance des services Linux
- viminfo, ShaDa and lesshst: Linux Editor and Pager History
- Web Shells in the Web Root: Finding Them on Linux Servers
- wtmp, btmp, utmp et lastlog : connexions Linux
- XDG Autostart .desktop Entries: Linux Desktop Persistence
- XFS Forensics: Inode Timestamps, crtime and Deleted Files