Linux Forensics Linux comes in multiple disitributions, debian and redhat (RHEL) especially have different log file locations, some of these paths may not be valid for certain distributions
Task Tools Imaging dd, dcfldd, ewfacquire, guymager Memory LiME, AVML, Volatility 3 Filesystem The Sleuth Kit (fls, icat, mactime), debugfs Timeline Plaso / log2timeline, mactime Carving foremost, scalpel, photorec Malware yara, strings, readelf, rpm -Va, debsums Live triage lsof, ss, ps, pstree, /proc
Key Log Locations (Dist. Depending) Path Contents /var/log/auth.log, /var/log/secure Authentication, sudo, SSH /var/log/syslog, /var/log/messages General system /var/log/kern.log Kernel /var/log/audit/audit.log auditd /var/log/wtmp, btmp, /run/utmp Login records (binary) /var/log/apache2/, /var/log/nginx/ Web server /var/log/journal/ systemd journal (binary)
journalctl --file /var/log/journal/* /system.journal
journalctl -o verbose --no-pager
utmpdump /var/log/wtmp
grep -Ei "accepted|failed|sudo|su:" /var/log/auth.log
Evidence Acquisition Disk imaging # Bit-for-bit image with hashing
dd if = /dev/sdX of = /mnt/evidence/disk.img bs = 4M conv = noerror,sync status = progress
# Preferred forensic imager (EWF, embeds metadata + hashes)
ewfacquire /dev/sdX
# dcfldd (dd + built-in hashing)
dcfldd if = /dev/sdX of = disk.img hash = sha256 hashwindow = 1G hashlog = disk.hashes
Hashing and integrity sha256sum disk.img > disk.img.sha256
md5sum disk.img > disk.img.md5
sha256sum -c disk.img.sha256
Memory acquisition # LiME kernel module -> raw or lime format for Volatility
insmod lime.ko "path=/mnt/evidence/mem.lime format=lime"
# AVML (Microsoft, static binary, no build needed)
./avml /mnt/evidence/mem.raw
Mounting evidence read-only mount -o ro,noexec,nodev,noload /dev/sdX1 /mnt/case
# Loop-mount an image (find partition offset with mmls first)
mmls disk.img
mount -o ro,loop,offset= $(( 2048 * 512 )) disk.img /mnt/case
Timeline Analysis The Sleuth Kit and timeline mmls disk.img # partition layout
fsstat -o 2048 disk.img # filesystem details
fls -r -m / -o 2048 disk.img > body.txt
mactime -b body.txt -d > timeline.csv
Plaso and log2timeline (super timeline) log2timeline.py --storage-file case .plaso disk.img
psort.py -o l2tcsv -w timeline.csv case .plaso
File timestamps (MACB) stat file # Access, Modify, Change, Birth
debugfs -R "stat <inode>" /dev/sdX1 # ext crtime
Filesystem and Deleted Data # Carve files by signature
foremost -i disk.img -o carved/
scalpel disk.img -o carved/
# Recover deleted (ext)
extundelete /dev/sdX1 --restore-all
tsk_recover -e disk.img recovered/
# Inode / block inspection
istat -o 2048 disk.img <inode>
icat -o 2048 disk.img <inode> > recovered_file
Live System Triage Processes ps auxww
ps -eo pid,ppid,user,lstart,cmd
pstree -ap
ls -al /proc/<pid>/ # cwd, exe, fd, environ, maps
cat /proc/<pid>/cmdline | tr '\0' ' '
lsof -p <pid>
Network ss -tulpanne
netstat -antup
lsof -i
ip -s link
cat /proc/net/tcp /proc/net/udp
iptables -L -n -v ; nft list ruleset
Loaded modules and kernel lsmod
cat /proc/modules
dmesg -T
Open files & deleted-but-running binaries lsof +L1 # files with link count 0 (deleted, still open)
ls -al /proc/<pid>/exe # points to (deleted) if binary removed
User and Authentication Artifacts cat /etc/passwd /etc/shadow /etc/group
cat /etc/sudoers /etc/sudoers.d/*
last -Faiwx # login history (wtmp)
lastb # failed logins (btmp)
lastlog # last login per user
w ; who -a # current sessions (utmp)
Shell history and keys cat ~/.bash_history ~/.zsh_history # note: no timestamps unless HISTTIMEFORMAT set
ls -la ~/.ssh/
cat ~/.ssh/authorized_keys ~/.ssh/known_hosts
cat ~/.* _history /root/.* _history
Persistence Hunting # Cron
ls -la /etc/cron* /var/spool/cron/crontabs/
for u in $( cut -f1 -d : /etc/passwd) ; do crontab -l -u $u 2>/dev/null; done
# systemd
systemctl list-unit-files --state = enabled
systemctl list-timers --all
ls -la /etc/systemd/system/ /lib/systemd/system/ ~/.config/systemd/user/
# Init / profile / rc
ls -la /etc/init.d/ /etc/rc* .d/
cat /etc/rc.local
cat /etc/profile /etc/bash.bashrc ~/.bashrc ~/.profile
# Loaders / preload
cat /etc/ld.so.preload
env | grep -i LD_
Memory Analysis (Volatility 3) vol -f mem.raw linux.pslist
vol -f mem.raw linux.pstree
vol -f mem.raw linux.psaux
vol -f mem.raw linux.bash # recovered bash history
vol -f mem.raw linux.lsof
vol -f mem.raw linux.sockstat
vol -f mem.raw linux.check_syscall # syscall table hooks
vol -f mem.raw linux.check_modules
vol -f mem.raw linux.malfind # injected code
vol -f mem.raw linux.elfs
Malware and IOC Triage # Hashes for reputation lookup
sha256sum suspicious_file
# Static inspection
file suspicious_file
strings -a -n 8 suspicious_file
readelf -a suspicious_file
xxd suspicious_file | head
# YARA scanning
yara -r rules.yar /path/to/scan
# Compare against package DB (detect tampered binaries)
debsums -c # Debian/Ubuntu
rpm -Va # RHEL/CentOS
# SUID/SGID & recently modified
find / -perm -4000 -type f 2>/dev/null
find / -newermt "2024-01-01" -type f 2>/dev/null
find / -mmin -60 -type f 2>/dev/null