Skip to content

Series

Linux log forensics fundamentals

6 posts in this series. Read them in order or jump to any one.

  1. Linux Log Forensics: auth.log, Journal, auditd and wtmp

    How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.

  2. Collect Linux Logs for Forensics: tar, UAC, Velociraptor

    What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.

  3. auth.log and secure Forensics: SSH, sudo and su

    Read /var/log/auth.log and /var/log/secure in an investigation: SSH brute force and logins, sudo and su root shells, password and account changes, time formats.

  4. systemd Journal Forensics: Files, Seqnum Gaps, .journal~

    systemd journal forensics without journalctl: the file format, trusted fields, compression, sequence-number gaps, dirty .journal~ files and time fields.

  5. auditd EXECVE Forensics: auid, ses and Hex Arguments

    Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.

  6. wtmp, btmp and lastlog Forensics, wtmpdb and lastlog2

    Linux login records in an investigation: struct utmp on x86_64 and aarch64, btmp failed logins, lastlog slots, wtmpdb and lastlog2 SQLite files, tampering.

All posts in this series

How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.
What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.
Read /var/log/auth.log and /var/log/secure in an investigation: SSH brute force and logins, sudo and su root shells, password and account changes, time formats.
systemd journal forensics without journalctl: the file format, trusted fields, compression, sequence-number gaps, dirty .journal~ files and time fields.
Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.
Linux login records in an investigation: struct utmp on x86_64 and aarch64, btmp failed logins, lastlog slots, wtmpdb and lastlog2 SQLite files, tampering.