Linux Forensics

Linux comes in multiple disitributions, debian and redhat (RHEL) especially have different log file locations, some of these paths may not be valid for certain distributions


Quick Reference: Toolkit Suggestions (Dist. Depending)

Task Tools
Imaging dd, dcfldd, ewfacquire, guymager
Memory LiME, AVML, Volatility 3
Filesystem The Sleuth Kit (fls, icat, mactime), debugfs
Timeline Plaso / log2timeline, mactime
Carving foremost, scalpel, photorec
Malware yara, strings, readelf, rpm -Va, debsums
Live triage lsof, ss, ps, pstree, /proc

Key Log Locations (Dist. Depending)

Path Contents
/var/log/auth.log, /var/log/secure Authentication, sudo, SSH
/var/log/syslog, /var/log/messages General system
/var/log/kern.log Kernel
/var/log/audit/audit.log auditd
/var/log/wtmp, btmp, /run/utmp Login records (binary)
/var/log/apache2/, /var/log/nginx/ Web server
/var/log/journal/ systemd journal (binary)
journalctl --file /var/log/journal/*/system.journal
journalctl -o verbose --no-pager
utmpdump /var/log/wtmp
grep -Ei "accepted|failed|sudo|su:" /var/log/auth.log

Evidence Acquisition

Disk imaging

# Bit-for-bit image with hashing
dd if=/dev/sdX of=/mnt/evidence/disk.img bs=4M conv=noerror,sync status=progress
 
# Preferred forensic imager (EWF, embeds metadata + hashes)
ewfacquire /dev/sdX
 
# dcfldd (dd + built-in hashing)
dcfldd if=/dev/sdX of=disk.img hash=sha256 hashwindow=1G hashlog=disk.hashes

Hashing and integrity

sha256sum disk.img > disk.img.sha256
md5sum disk.img    > disk.img.md5
sha256sum -c disk.img.sha256

Memory acquisition

# LiME kernel module -> raw or lime format for Volatility
insmod lime.ko "path=/mnt/evidence/mem.lime format=lime"
 
# AVML (Microsoft, static binary, no build needed)
./avml /mnt/evidence/mem.raw

Mounting evidence read-only

mount -o ro,noexec,nodev,noload /dev/sdX1 /mnt/case
# Loop-mount an image (find partition offset with mmls first)
mmls disk.img
mount -o ro,loop,offset=$((2048*512)) disk.img /mnt/case

Timeline Analysis

The Sleuth Kit and timeline

mmls disk.img                       # partition layout
fsstat -o 2048 disk.img             # filesystem details
fls -r -m / -o 2048 disk.img > body.txt
mactime -b body.txt -d > timeline.csv

Plaso and log2timeline (super timeline)

log2timeline.py --storage-file case.plaso disk.img
psort.py -o l2tcsv -w timeline.csv case.plaso

File timestamps (MACB)

stat file                           # Access, Modify, Change, Birth
debugfs -R "stat <inode>" /dev/sdX1 # ext crtime

Filesystem and Deleted Data

# Carve files by signature
foremost -i disk.img -o carved/
scalpel disk.img -o carved/
 
# Recover deleted (ext)
extundelete /dev/sdX1 --restore-all
tsk_recover -e disk.img recovered/
 
# Inode / block inspection
istat -o 2048 disk.img <inode>
icat -o 2048 disk.img <inode> > recovered_file

Live System Triage

Processes

ps auxww
ps -eo pid,ppid,user,lstart,cmd
pstree -ap
ls -al /proc/<pid>/          # cwd, exe, fd, environ, maps
cat /proc/<pid>/cmdline | tr '\0' ' '
lsof -p <pid>

Network

ss -tulpanne
netstat -antup
lsof -i
ip -s link
cat /proc/net/tcp /proc/net/udp
iptables -L -n -v ; nft list ruleset

Loaded modules and kernel

lsmod
cat /proc/modules
dmesg -T

Open files & deleted-but-running binaries

lsof +L1                    # files with link count 0 (deleted, still open)
ls -al /proc/<pid>/exe      # points to (deleted) if binary removed

User and Authentication Artifacts

cat /etc/passwd /etc/shadow /etc/group
cat /etc/sudoers /etc/sudoers.d/*
last -Faiwx                 # login history (wtmp)
lastb                       # failed logins (btmp)
lastlog                     # last login per user
w ; who -a                  # current sessions (utmp)

Shell history and keys

cat ~/.bash_history ~/.zsh_history      # note: no timestamps unless HISTTIMEFORMAT set
ls -la ~/.ssh/
cat ~/.ssh/authorized_keys ~/.ssh/known_hosts
cat ~/.*_history /root/.*_history

Persistence Hunting

# Cron
ls -la /etc/cron* /var/spool/cron/crontabs/
for u in $(cut -f1 -d: /etc/passwd); do crontab -l -u $u 2>/dev/null; done
 
# systemd
systemctl list-unit-files --state=enabled
systemctl list-timers --all
ls -la /etc/systemd/system/ /lib/systemd/system/ ~/.config/systemd/user/
 
# Init / profile / rc
ls -la /etc/init.d/ /etc/rc*.d/
cat /etc/rc.local
cat /etc/profile /etc/bash.bashrc ~/.bashrc ~/.profile
 
# Loaders / preload
cat /etc/ld.so.preload
env | grep -i LD_

Memory Analysis (Volatility 3)

vol -f mem.raw linux.pslist
vol -f mem.raw linux.pstree
vol -f mem.raw linux.psaux
vol -f mem.raw linux.bash            # recovered bash history
vol -f mem.raw linux.lsof
vol -f mem.raw linux.sockstat
vol -f mem.raw linux.check_syscall   # syscall table hooks
vol -f mem.raw linux.check_modules
vol -f mem.raw linux.malfind         # injected code
vol -f mem.raw linux.elfs

Malware and IOC Triage

# Hashes for reputation lookup
sha256sum suspicious_file
 
# Static inspection
file suspicious_file
strings -a -n 8 suspicious_file
readelf -a suspicious_file
xxd suspicious_file | head
 
# YARA scanning
yara -r rules.yar /path/to/scan
 
# Compare against package DB (detect tampered binaries)
debsums -c                          # Debian/Ubuntu
rpm -Va                             # RHEL/CentOS
 
# SUID/SGID & recently modified
find / -perm -4000 -type f 2>/dev/null
find / -newermt "2024-01-01" -type f 2>/dev/null
find / -mmin -60 -type f 2>/dev/null


This site uses Just the Docs, a documentation theme for Jekyll.