Series
Linux log forensics fundamentals
6 posts in this series. Read them in order or jump to any one.
- Linux Log Forensics: auth.log, Journal, auditd and wtmp
How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.
- Collect Linux Logs for Forensics: tar, UAC, Velociraptor
What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.
- auth.log and secure Forensics: SSH, sudo and su
Read /var/log/auth.log and /var/log/secure in an investigation: SSH brute force and logins, sudo and su root shells, password and account changes, time formats.
- systemd Journal Forensics: Files, Seqnum Gaps, .journal~
systemd journal forensics without journalctl: the file format, trusted fields, compression, sequence-number gaps, dirty .journal~ files and time fields.
- auditd EXECVE Forensics: auid, ses and Hex Arguments
Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.
- wtmp, btmp and lastlog Forensics, wtmpdb and lastlog2
Linux login records in an investigation: struct utmp on x86_64 and aarch64, btmp failed logins, lastlog slots, wtmpdb and lastlog2 SQLite files, tampering.