analyzing-linux-system-artifacts

Featured

Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.

AI & Automation 64 stars 11 forks Updated yesterday MIT

Install

View on GitHub

Quality Score: 91/100

Stars 20%
60
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Analyzing Linux System Artifacts ## When to Use - When investigating a compromised Linux server or workstation - For identifying persistence mechanisms (cron, systemd, SSH keys) - When tracing user activity through shell history and authentication logs - During incident response to determine the scope of a Linux-based breach - For detecting rootkits, backdoors, and unauthorized modifications ## Prerequisites - Forensic image or live access to the Linux system (read-only) - Understanding of Linux file system hierarchy (FHS) - Knowledge of common Linux logging locations (/var/log/) - Tools: chkrootkit, rkhunter, AIDE, auditd logs - Familiarity with systemd, cron, and PAM configurations - Root access for complete artifact collection ## Workflow ### Step 1: Mount and Collect System Artifacts ```bash # Mount forensic image read-only mount -o ro,loop,offset=$((2048*512)) /cases/case-2024-001/images/linux_evidence.dd /mnt/evidence # Create collection directories mkdir -p /cases/case-2024-001/linux/{logs,config,users,persistence,network} # Collect authentication logs cp /mnt/evidence/var/log/auth.log* /cases/case-2024-001/linux/logs/ cp /mnt/evidence/var/log/secure* /cases/case-2024-001/linux/logs/ cp /mnt/evidence/var/log/syslog* /cases/case-2024-001/linux/logs/ cp /mnt/evidence/var/log/kern.log* /cases/case-2024-001/linux/logs/ cp /mnt/evidence/var/log/audit/audit.log* /cases/case-2024-001/linux/logs/ cp /mnt/evidence/var/log/wtmp /cases/case-2024-001/linux/logs/ cp /mnt/e...

Details

Author
26zl
Repository
26zl/cybersec-toolkit
Created
7 months ago
Last Updated
yesterday
Language
Python
License
MIT

Integrates with

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

DevOps & Infrastructure Listed

analyzing-linux-system-artifacts

Examine Linux system artifacts (auth logs, cron/systemd persistence, shell history, SSH keys, and system configuration) to uncover evidence of compromise, detect rootkits or backdoors, and reconstruct user/attacker activity. Use when investigating a compromised Linux server or workstation, hunting for persistence mechanisms, or scoping a Linux-based breach during incident response.

0 Updated today
anxious-phyllo879
AI & Automation Featured

analyzing-persistence-mechanisms-in-linux

Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring

61 Updated 1 weeks ago
adriannoes
Data & Documents Listed

log-forensics

Investigate an incident from logs: pick the Windows Security/System/PowerShell/Sysmon event IDs, Linux auth/audit/systemd/cron/shell-history artifacts, and web server or proxy logs that answer the question, normalize time zones, merge everything into one UTC super-timeline, pivot user to host to process to network, and preserve evidence properly. Use it whenever someone pastes or points at exported logs (CSV, JSON, EVTX exports, auth.log, access.log), asks "what happened on this host", "when did they get in", "what did this account do", "build a timeline", "which event IDs should I pull", or needs a forensic narrative for an incident report, even if they never say forensics.

0 Updated 1 weeks ago
ftrout