Linux artifacts
Linux forensics reconstructs activity from logs, histories, cron, systemd units, and filesystem metadata. It’s common on compromised servers (web, cloud, containers), where the attacker usually leaves webshells, accounts, and persistence.
System logs
Section titled “System logs”/var/log/auth.log | secure authentication (SSH, sudo, su) -> brute force, accesses/var/log/syslog | messages general system events/var/log/wtmp /var/log/btmp successful logins (last) and failed (lastb)/var/run/utmp current sessions (who)journald (journalctl) systemd logs (many modern distros)/var/log/<service> apache/nginx (web access -> webshells), databasesPersistence (where to look)
Section titled “Persistence (where to look)”cron /etc/crontab, /etc/cron.*, user crontabs (see linux-privesc)systemd units and timers (.service/.timer) -> modern persistencerc.local, shell profiles (.bashrc/.profile), /etc/ld.so.preloadaccounts /etc/passwd and /etc/shadow (new users, extra UID 0, SSH keys)authorized_keys SSH keys added by the attacker (~/.ssh/)User activity
Section titled “User activity”~/.bash_history (and zsh_history) executed commands (often cleared -> absence = signal)sudo logs what was done with privilegesrecent files, /tmp and /dev/shm staging of tools/payloadstimestamps (stat): atime/mtime/ctime; ext4 also crtimeFilesystem and processes
Section titled “Filesystem and processes”- anomalous SUID/SGID files (persistence/privesc, see linux-privesc)- modified binaries (compare against packages: debsums/rpm -V)- live processes and connections if the system is still on (ps, ss, lsof, /proc)- deleted files still open by a process (/proc/<pid>/fd) -> recoverable liveTriage/collection UAC (Unix-like Artifacts Collector), CyLR, VelociraptorAnalysis grep/awk over logs, apache-scalp for web logs, Volatility (Linux memory)Rootkits chkrootkit, rkhunter; verify binary integrityBlue Team / DFIR
Section titled “Blue Team / DFIR”- Collect with UAC/Velociraptor before the attacker or a reboot erases evidence.
- Review auth.log/wtmp/btmp for accesses, and cron/systemd/authorized_keys for persistence.
- The absence of history or logs is itself a signal (anti-forensic clearing).
- Web server logs are key to finding webshells and the entry vector on servers.
Real-world cases
Section titled “Real-world cases”- Compromised web servers (e.g. Struts/Log4Shell exploitation) leave traces in access logs and webshells on the FS.
- Persistence via systemd/cron/authorized_keys is a common TTP in Linux/cloud intrusions.
- Linux rootkits and miners detected via binary integrity and anomalous processes/connections.
Testing checklist
Section titled “Testing checklist”- Collect artifacts (UAC/CyLR/Velociraptor) and memory if applicable
- auth.log/secure + wtmp/btmp (accesses, brute force)
- Persistence: cron, systemd, rc.local, profiles, authorized_keys
- Accounts: passwd/shadow (extra UID 0, new users)
- Shell and sudo history (and its absence)
- Web service logs (webshells, entry vector)
- SUID/SGID and modified binaries; rootkits
- Integrate into the timeline (Timeline analysis) and map to ATT&CK