Skip to content

Linux artifacts

Linux forensics reconstructs activity from logs, histories, cron, systemd units, and filesystem metadata. It’s common on compromised servers (web, cloud, containers), where the attacker usually leaves webshells, accounts, and persistence.

/var/log/auth.log | secure authentication (SSH, sudo, su) -> brute force, accesses
/var/log/syslog | messages general system events
/var/log/wtmp /var/log/btmp successful logins (last) and failed (lastb)
/var/run/utmp current sessions (who)
journald (journalctl) systemd logs (many modern distros)
/var/log/<service> apache/nginx (web access -> webshells), databases
cron /etc/crontab, /etc/cron.*, user crontabs (see linux-privesc)
systemd units and timers (.service/.timer) -> modern persistence
rc.local, shell profiles (.bashrc/.profile), /etc/ld.so.preload
accounts /etc/passwd and /etc/shadow (new users, extra UID 0, SSH keys)
authorized_keys SSH keys added by the attacker (~/.ssh/)
~/.bash_history (and zsh_history) executed commands (often cleared -> absence = signal)
sudo logs what was done with privileges
recent files, /tmp and /dev/shm staging of tools/payloads
timestamps (stat): atime/mtime/ctime; ext4 also crtime
- anomalous SUID/SGID files (persistence/privesc, see linux-privesc)
- modified binaries (compare against packages: debsums/rpm -V)
- live processes and connections if the system is still on (ps, ss, lsof, /proc)
- deleted files still open by a process (/proc/<pid>/fd) -> recoverable live
Triage/collection UAC (Unix-like Artifacts Collector), CyLR, Velociraptor
Analysis grep/awk over logs, apache-scalp for web logs, Volatility (Linux memory)
Rootkits chkrootkit, rkhunter; verify binary integrity
  • Collect with UAC/Velociraptor before the attacker or a reboot erases evidence.
  • Review auth.log/wtmp/btmp for accesses, and cron/systemd/authorized_keys for persistence.
  • The absence of history or logs is itself a signal (anti-forensic clearing).
  • Web server logs are key to finding webshells and the entry vector on servers.
  • Compromised web servers (e.g. Struts/Log4Shell exploitation) leave traces in access logs and webshells on the FS.
  • Persistence via systemd/cron/authorized_keys is a common TTP in Linux/cloud intrusions.
  • Linux rootkits and miners detected via binary integrity and anomalous processes/connections.
  • Collect artifacts (UAC/CyLR/Velociraptor) and memory if applicable
  • auth.log/secure + wtmp/btmp (accesses, brute force)
  • Persistence: cron, systemd, rc.local, profiles, authorized_keys
  • Accounts: passwd/shadow (extra UID 0, new users)
  • Shell and sudo history (and its absence)
  • Web service logs (webshells, entry vector)
  • SUID/SGID and modified binaries; rootkits
  • Integrate into the timeline (Timeline analysis) and map to ATT&CK