← All cheat sheets

LINUX FORENSICS COMMANDS

Plain-text reference · 12 KB. Read it, search it (Ctrl-F) or print it.

Essential commands and procedures for Linux forensic analysis
and incident response. Always follow order of volatility.

ORDER OF VOLATILITY#

Collect evidence in this order (most volatile first):
  1. CPU registers, cache, running processes
  2. Memory (RAM)
  3. Network state (connections, routing, ARP)
  4. Running processes and open files
  5. Disk (filesystem, logs, files)
  6. Remote logging and monitoring data
  7. Physical configuration, network topology
  8. Archival media (backups, tapes)

VOLATILE DATA COLLECTION#

# System info and uptime
date && date -u
uname -a
hostname
uptime
cat /etc/os-release

# Current users and sessions
w
who
whoami
id
last -Faiwx | head -50

# Running processes
ps auxwwf
ps -eo pid,ppid,user,args --sort=start_time
pstree -apl
top -bn1

# Open files and file descriptors
lsof -nPl
lsof -i -nP
lsof +L1                     # deleted but open files (hidden data)

# Network connections
ss -tulnp                    # listening sockets with PIDs
ss -antp                     # all TCP connections
ss -anup                     # all UDP connections
netstat -tulnp               # alternative if ss unavailable
netstat -antp

# Network configuration
ip addr show
ip route show
ip neigh show                # ARP table
iptables -L -n -v            # firewall rules
cat /etc/resolv.conf
cat /etc/hosts

# Loaded kernel modules
lsmod
cat /proc/modules

# Mounted filesystems
mount
df -h
cat /etc/fstab
cat /proc/mounts

# Environment variables (for all users)
env
printenv
cat /proc/*/environ 2>/dev/null | tr '\0' '\n'

PROC FILESYSTEM ANALYSIS#

# Process details for PID
ls -la /proc/<PID>/
cat /proc/<PID>/cmdline | tr '\0' ' '     # command line
cat /proc/<PID>/environ | tr '\0' '\n'    # environment
ls -la /proc/<PID>/exe                     # link to binary
ls -la /proc/<PID>/cwd                     # working directory
ls -la /proc/<PID>/fd/                     # open file descriptors
cat /proc/<PID>/maps                       # memory mappings
cat /proc/<PID>/status                     # process status
cat /proc/<PID>/net/tcp                    # TCP connections (per PID namespace)

# Recover deleted binary still running in memory
cp /proc/<PID>/exe /evidence/recovered_binary

# System-wide proc info
cat /proc/version
cat /proc/cmdline              # kernel boot parameters
cat /proc/meminfo
cat /proc/cpuinfo
cat /proc/sys/net/ipv4/ip_forward   # IP forwarding status

# Detect hidden processes (compare)
ls /proc/ | grep -E '^[0-9]+$' | sort -n > /tmp/proc_pids
ps -eo pid --no-headers | sort -n > /tmp/ps_pids
diff /tmp/proc_pids /tmp/ps_pids

USER ACTIVITY AND LOGIN HISTORY#

# Login records
last -Faiwx                   # all login history from wtmp
lastb -Faiwx                  # failed login attempts from btmp
lastlog                       # last login for each user

# Currently logged in
who
w
finger                        # if installed

# Authentication logs
cat /var/log/auth.log         # Debian/Ubuntu
cat /var/log/secure           # RHEL/CentOS
journalctl -u sshd            # systemd SSH logs

# SSH specific
cat /var/log/auth.log | grep sshd
cat /var/log/auth.log | grep "Accepted\|Failed"
cat /var/log/auth.log | grep "session opened\|session closed"

# User accounts
cat /etc/passwd               # all accounts
cat /etc/shadow               # password hashes (need root)
cat /etc/group                # group memberships
cat /etc/sudoers              # sudo config
cat /etc/sudoers.d/*

# Check for unauthorized accounts
awk -F: '$3 == 0 {print $1}' /etc/passwd          # UID 0 accounts (should only be root)
awk -F: '$3 >= 1000 {print $1}' /etc/passwd        # regular user accounts
awk -F: '$7 !~ /nologin|false/ {print}' /etc/passwd # accounts with shell access
awk -F: '$2 == "" {print $1}' /etc/shadow           # accounts with no password

BASH HISTORY AND USER ARTIFACTS#

# History files (check all users)
cat /home/*/.bash_history
cat /root/.bash_history
cat /home/*/.zsh_history
cat /home/*/.python_history
cat /home/*/.mysql_history
cat /home/*/.psql_history

# History file timestamps (HISTTIMEFORMAT)
# If HISTTIMEFORMAT was set, history shows timestamps
HISTTIMEFORMAT="%F %T " history

# Recently accessed files per user
find /home -name ".*_history" -exec echo "=== {} ===" \; -exec cat {} \;

# SSH known hosts and authorized keys
cat /home/*/.ssh/known_hosts
cat /home/*/.ssh/authorized_keys
cat /root/.ssh/authorized_keys
cat /home/*/.ssh/config

# Recently modified user files
find /home -mtime -7 -type f -ls 2>/dev/null
find /root -mtime -7 -type f -ls 2>/dev/null

SCHEDULED TASKS AND PERSISTENCE#

# Crontabs
crontab -l                            # current user crontab
crontab -l -u <username>              # specific user crontab
cat /etc/crontab                      # system crontab
ls -la /etc/cron.d/                   # cron.d entries
ls -la /etc/cron.daily/
ls -la /etc/cron.hourly/
ls -la /etc/cron.weekly/
ls -la /etc/cron.monthly/
cat /var/spool/cron/crontabs/*        # all user crontabs

# Systemd timers
systemctl list-timers --all

# At jobs
atq
at -c <job_number>

# Startup and services
systemctl list-unit-files --type=service --state=enabled
systemctl list-units --type=service --state=running
ls -la /etc/init.d/
ls -la /etc/rc*.d/

# Other persistence mechanisms
cat /etc/rc.local
ls -la /etc/profile.d/
cat /etc/bash.bashrc
cat /home/*/.bashrc
cat /home/*/.bash_profile
cat /home/*/.profile
ls -la /etc/ld.so.preload             # LD_PRELOAD hijacking
cat /etc/ld.so.preload

LOG ANALYSIS#

# System logs
cat /var/log/syslog                   # general system (Debian/Ubuntu)
cat /var/log/messages                 # general system (RHEL/CentOS)
cat /var/log/kern.log                 # kernel messages
cat /var/log/dmesg                    # boot messages
cat /var/log/boot.log

# Authentication
cat /var/log/auth.log                 # Debian/Ubuntu
cat /var/log/secure                   # RHEL/CentOS

# Application logs
cat /var/log/apache2/access.log       # Apache
cat /var/log/apache2/error.log
cat /var/log/nginx/access.log         # Nginx
cat /var/log/nginx/error.log
cat /var/log/mysql/error.log          # MySQL

# Package management
cat /var/log/dpkg.log                 # Debian package installs
cat /var/log/yum.log                  # RHEL package installs
cat /var/log/apt/history.log          # APT history

# Journalctl (systemd)
journalctl --since "2 days ago"
journalctl -u sshd --since "1 week ago"
journalctl -p err                     # errors and above
journalctl _UID=0                     # root activity

# Search logs for indicators
grep -r "Failed password" /var/log/auth.log
grep -r "Accepted publickey\|Accepted password" /var/log/auth.log
grep -r "COMMAND" /var/log/auth.log   # sudo commands
grep -r "useradd\|userdel\|usermod" /var/log/auth.log
zgrep -r "pattern" /var/log/*.gz      # search rotated logs

FILE TIMELINE ANALYSIS#

# Files modified in last N days
find / -mtime -7 -type f -ls 2>/dev/null | sort -k9

# Files accessed in last N days
find / -atime -3 -type f -ls 2>/dev/null | sort -k9

# Files changed (metadata) in last N days
find / -ctime -2 -type f -ls 2>/dev/null | sort -k9

# Files modified in a specific time range
find / -newermt "2026-03-15" ! -newermt "2026-03-19" -type f -ls 2>/dev/null

# SUID/SGID files (privilege escalation check)
find / -perm -4000 -type f -ls 2>/dev/null    # SUID
find / -perm -2000 -type f -ls 2>/dev/null    # SGID

# World-writable files
find / -perm -o+w -type f -ls 2>/dev/null

# Files with no owner
find / -nouser -o -nogroup 2>/dev/null

# Recently installed packages as files
find /usr -mtime -7 -type f -ls 2>/dev/null

# Hidden files and directories
find / -name ".*" -type f -ls 2>/dev/null
find / -name ".. " -type d 2>/dev/null          # hidden dirs with spaces
find / -name "..." -type d 2>/dev/null

# Create a full timeline (mactime format) using find
find / -printf "%T+ %m %u %g %s %p\n" 2>/dev/null | sort > /evidence/timeline.txt

ROOTKIT DETECTION#

# chkrootkit
apt install chkrootkit        # or yum install chkrootkit
chkrootkit
chkrootkit -q                 # quiet mode (only infected)

# rkhunter
apt install rkhunter          # or yum install rkhunter
rkhunter --update
rkhunter --check --sk         # skip keypress prompts
rkhunter --check --rwo        # warnings only

# Manual rootkit indicators
# Compare process lists
ps aux > /tmp/ps_output
ls /proc | grep -E '^[0-9]+' > /tmp/proc_output
# Hidden processes won't appear in ps but will in /proc

# Check for kernel module rootkits
lsmod | sort
cat /proc/modules | sort
# Compare and look for discrepancies

# Check for library preloading
cat /etc/ld.so.preload
echo $LD_PRELOAD
ldd /bin/ls                   # check for injected libraries

# Check binary integrity
rpm -Va 2>/dev/null           # RHEL: verify all packages
debsums -c 2>/dev/null        # Debian: check changed files
dpkg --verify 2>/dev/null

# Unhide tool (finds hidden processes and ports)
apt install unhide
unhide proc
unhide sys
unhide-tcp

NETWORK FORENSICS#

# Active connections
ss -antp
ss -anup
lsof -i -nP

# DNS cache (if systemd-resolved)
resolvectl statistics
resolvectl query <domain>

# Capture live traffic
tcpdump -i any -w /evidence/capture.pcap -c 10000
tcpdump -i eth0 -nn port 443

# ARP cache
ip neigh show
arp -an

# Routing
ip route show
route -n

# Listening services
ss -tlnp
lsof -i -P -n | grep LISTEN

# IPtables/nftables rules (check for attacker modifications)
iptables -L -n -v --line-numbers
iptables -t nat -L -n -v
nft list ruleset

EVIDENCE PRESERVATION#

# Create forensic image of disk
dd if=/dev/sda of=/evidence/disk.img bs=4M status=progress
# or with hashing
dc3dd if=/dev/sda of=/evidence/disk.img hash=sha256 log=/evidence/dd.log

# Calculate hashes
sha256sum /evidence/disk.img > /evidence/disk.img.sha256
md5sum /evidence/disk.img > /evidence/disk.img.md5

# Hash individual files
sha256sum <file>
find /evidence -type f -exec sha256sum {} \; > /evidence/hashes.txt

# Memory acquisition
# LiME (Linux Memory Extractor)
insmod lime.ko "path=/evidence/memory.lime format=lime"

# Or use AVML (Acquire Volatile Memory for Linux)
./avml /evidence/memory.lime

# Mount evidence read-only
mount -o ro,noexec,noatime /dev/sdb1 /mnt/evidence

# Create timeline with Sleuth Kit
fls -r -m "/" /evidence/disk.img > /evidence/bodyfile.txt
mactime -b /evidence/bodyfile.txt -d > /evidence/timeline.csv

# Preserve log files
tar czf /evidence/var_log_$(date +%Y%m%d_%H%M%S).tar.gz /var/log/

# Chain of custody
echo "Evidence collected by: $(whoami)" > /evidence/chain_of_custody.txt
echo "Date: $(date -u)" >> /evidence/chain_of_custody.txt
echo "System: $(hostname)" >> /evidence/chain_of_custody.txt
echo "Hash: $(sha256sum /evidence/disk.img)" >> /evidence/chain_of_custody.txt

QUICK TRIAGE SCRIPT#

#!/bin/bash
# Run as root. Save output to evidence directory.
OUTDIR="/evidence/$(hostname)_$(date +%Y%m%d_%H%M%S)"
mkdir -p $OUTDIR

date -u > $OUTDIR/date.txt
uname -a > $OUTDIR/uname.txt
uptime > $OUTDIR/uptime.txt
w > $OUTDIR/w.txt
who > $OUTDIR/who.txt
ps auxwwf > $OUTDIR/ps.txt
ss -antp > $OUTDIR/ss_tcp.txt
ss -anup > $OUTDIR/ss_udp.txt
ip addr > $OUTDIR/ip_addr.txt
ip route > $OUTDIR/ip_route.txt
ip neigh > $OUTDIR/arp.txt
lsof -nPl > $OUTDIR/lsof.txt
lsmod > $OUTDIR/lsmod.txt
mount > $OUTDIR/mount.txt
last -Faiwx > $OUTDIR/last.txt
lastb -Faiwx > $OUTDIR/lastb.txt 2>/dev/null
cat /etc/passwd > $OUTDIR/passwd.txt
cat /etc/shadow > $OUTDIR/shadow.txt 2>/dev/null
crontab -l > $OUTDIR/crontab.txt 2>/dev/null
cat /etc/crontab > $OUTDIR/etc_crontab.txt
find / -mtime -3 -type f -ls > $OUTDIR/recent_files.txt 2>/dev/null
tar czf $OUTDIR/var_log.tar.gz /var/log/ 2>/dev/null

sha256sum $OUTDIR/* > $OUTDIR/hashes.txt
echo "Triage complete: $OUTDIR"

REFERENCES#

- SANS Linux Forensics Cheat Sheet
- The Sleuth Kit: https://www.sleuthkit.org/
- LiME: https://github.com/504ensicsLabs/LiME
- AVML: https://github.com/microsoft/avml
- Velociraptor: https://docs.velociraptor.app/

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.