Linux Forensics (for Non -Linux Folks) - Deer Run
Linux Forensics (for Non-Linux Folks)
Hal Pomeranz Deer Run Associates
What's Different About Linux?
? No registry
? Have to gather system info from scattered sources
? Different file system
? No file creation dates (until EXT4) ? Important metadata zeroed when files deleted
? Files/data are mostly plain text
? Good for string searching & interpreting data
Accessing the File System
? Can be complicated ? Encryption, RAID, Logical Volume Mgmt, ... ? Multiple partitions to mount
What Should We Look At?
/etc
[%SystemRoot%/System32/config]
? Primary system configuration directory
? Separate configuration files/dirs for each app
/var/log
[Windows event logs]
? Security logs, application logs, etc
? Logs normally kept for about 4-5 weeks
/home/$USER
[%USERPROFILE%]
? User data and user configuration information
Basic System Profiling
Linux distro name/version number:
/etc/*-release
Installation date:
Look at dates on /etc/ssh/ssh_host_*_key files
Computer name:
/etc/hostname (also log entries under /var/log)
IP address(es):
/etc/hosts
(static assignments)
/var/lib/dhclient, /var/log/* (DHCP)
................
................
In order to avoid copyright disputes, this page is only a partial summary.
To fulfill the demand for quickly locating and searching documents.
It is intelligent file search solution for home and business.
Related download
- linux forensics for non linux folks deer run
- how to configure crowdstrike to forward logs to eventtracker
- configuring linux os to forward logs to eventtracker netsurion
- instrumentation for linux event log analysis sourceforge
- integrating linux os with eventtracker
- estimating log generation for security information event solarwinds
- an analysis of microsoft event logs utica university
- eventlog analyzer requirement guide manageengine
- privilegemanagementforunixand linuxsudomanager22 2 administrationguide
- log management monitoring and making sense of logs schreuders
Related searches
- linux terminal for windows 10
- linux command for windows
- linux commands for windows 10
- download linux terminal for windows
- linux download for windows 10
- linux launcher for windows 10
- linux tools for windows 10
- download linux os for laptop
- best linux download for laptop
- best linux distro for security
- which linux distro for me
- best linux distro for desktop