Linux Investigations
Section Introduction
Linux Artifacts: Passwd and Shadow
/etc/passwd
cat /etc/passwdroot:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
syslog:x:104:109::/home/syslog:/usr/sbin/nologin
jane.smith:x:1001:1001:Jane Smith:/home/jane.smith:/bin/bash/etc/shadow
Forensic Value
Linux Artifacts: /Var/Lib and /Var/Log
/var/lib
Installed Software and Packaging
/var/log
Operating System Logs
Web Server Logs
Linux Artifacts: User Files
Bash History
Location
Why is it Interesting?
Hidden Files
Clear Files
Steganography
Hiding ZIP Files Inside Images
Using Steghide to Hide and Retrieve Files
Hiding Strings in Metadata
Linux Artifacts: Memory
Creating a Memory Dump
Forensic Analysis
Last updated