<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linux Log Parser — Blog</title>
    <link>https://www.linuxlogparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:49 GMT</lastBuildDate>
    <atom:link href="https://www.linuxlogparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>auditd EXECVE Forensics: auid, ses and Hex Arguments</title>
      <link>https://www.linuxlogparser.com/en/blog/auditd-execve-forensics</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/auditd-execve-forensics</guid>
      <description>Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>auth.log and secure Forensics: SSH, sudo and su</title>
      <link>https://www.linuxlogparser.com/en/blog/auth-log-forensics-ssh-sudo</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/auth-log-forensics-ssh-sudo</guid>
      <description>Read /var/log/auth.log and /var/log/secure in an investigation: SSH brute force and logins, sudo and su root shells, password and account changes, time formats.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Collect Linux Logs for Forensics: tar, UAC, Velociraptor</title>
      <link>https://www.linuxlogparser.com/en/blog/collect-linux-logs-for-forensics</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/collect-linux-logs-for-forensics</guid>
      <description>What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Detecting Linux Log Tampering: Gaps, Blanks and Stops</title>
      <link>https://www.linuxlogparser.com/en/blog/detect-linux-log-tampering</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/detect-linux-log-tampering</guid>
      <description>How to prove Linux logs were edited or deleted: journal seqnum gaps, lines missing from auth.log, blanked wtmp records, stopped daemons and clearing commands.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Intrusion Investigation: A Log Walkthrough</title>
      <link>https://www.linuxlogparser.com/en/blog/linux-intrusion-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/linux-intrusion-investigation-walkthrough</guid>
      <description>A worked Linux log investigation on a synthetic jump host: SSH password guessing, a login from a new IP, sudo -i, cron and systemd persistence, log tampering.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Linux Log Forensics: auth.log, Journal, auditd and wtmp</title>
      <link>https://www.linuxlogparser.com/en/blog/linux-log-forensics-timeline</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/linux-log-forensics-timeline</guid>
      <description>How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>systemd Journal Forensics: Files, Seqnum Gaps, .journal~</title>
      <link>https://www.linuxlogparser.com/en/blog/systemd-journal-forensics</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/systemd-journal-forensics</guid>
      <description>systemd journal forensics without journalctl: the file format, trusted fields, compression, sequence-number gaps, dirty .journal~ files and time fields.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>wtmp, btmp and lastlog Forensics, wtmpdb and lastlog2</title>
      <link>https://www.linuxlogparser.com/en/blog/wtmp-btmp-lastlog-forensics</link>
      <guid isPermaLink="true">https://www.linuxlogparser.com/en/blog/wtmp-btmp-lastlog-forensics</guid>
      <description>Linux login records in an investigation: struct utmp on x86_64 and aarch64, btmp failed logins, lastlog slots, wtmpdb and lastlog2 SQLite files, tampering.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>