LINUX FORENSICS COMMANDS
Essential commands and procedures for Linux forensic analysis and incident response. Always follow order of volatility.
ORDER OF VOLATILITY#
Collect evidence in this order (most volatile first): 1. CPU registers, cache, running processes 2. Memory (RAM) 3. Network state (connections, routing, ARP) 4. Running processes and open files 5. Disk (filesystem, logs, files) 6. Remote logging and monitoring data 7. Physical configuration, network topology 8. Archival media (backups, tapes)
VOLATILE DATA COLLECTION#
# System info and uptime date && date -u uname -a hostname uptime cat /etc/os-release # Current users and sessions w who whoami id last -Faiwx | head -50 # Running processes ps auxwwf ps -eo pid,ppid,user,args --sort=start_time pstree -apl top -bn1 # Open files and file descriptors lsof -nPl lsof -i -nP lsof +L1 # deleted but open files (hidden data) # Network connections ss -tulnp # listening sockets with PIDs ss -antp # all TCP connections ss -anup # all UDP connections netstat -tulnp # alternative if ss unavailable netstat -antp # Network configuration ip addr show ip route show ip neigh show # ARP table iptables -L -n -v # firewall rules cat /etc/resolv.conf cat /etc/hosts # Loaded kernel modules lsmod cat /proc/modules # Mounted filesystems mount df -h cat /etc/fstab cat /proc/mounts # Environment variables (for all users) env printenv cat /proc/*/environ 2>/dev/null | tr '\0' '\n'
PROC FILESYSTEM ANALYSIS#
# Process details for PID ls -la /proc/<PID>/ cat /proc/<PID>/cmdline | tr '\0' ' ' # command line cat /proc/<PID>/environ | tr '\0' '\n' # environment ls -la /proc/<PID>/exe # link to binary ls -la /proc/<PID>/cwd # working directory ls -la /proc/<PID>/fd/ # open file descriptors cat /proc/<PID>/maps # memory mappings cat /proc/<PID>/status # process status cat /proc/<PID>/net/tcp # TCP connections (per PID namespace) # Recover deleted binary still running in memory cp /proc/<PID>/exe /evidence/recovered_binary # System-wide proc info cat /proc/version cat /proc/cmdline # kernel boot parameters cat /proc/meminfo cat /proc/cpuinfo cat /proc/sys/net/ipv4/ip_forward # IP forwarding status # Detect hidden processes (compare) ls /proc/ | grep -E '^[0-9]+$' | sort -n > /tmp/proc_pids ps -eo pid --no-headers | sort -n > /tmp/ps_pids diff /tmp/proc_pids /tmp/ps_pids
USER ACTIVITY AND LOGIN HISTORY#
# Login records
last -Faiwx # all login history from wtmp
lastb -Faiwx # failed login attempts from btmp
lastlog # last login for each user
# Currently logged in
who
w
finger # if installed
# Authentication logs
cat /var/log/auth.log # Debian/Ubuntu
cat /var/log/secure # RHEL/CentOS
journalctl -u sshd # systemd SSH logs
# SSH specific
cat /var/log/auth.log | grep sshd
cat /var/log/auth.log | grep "Accepted\|Failed"
cat /var/log/auth.log | grep "session opened\|session closed"
# User accounts
cat /etc/passwd # all accounts
cat /etc/shadow # password hashes (need root)
cat /etc/group # group memberships
cat /etc/sudoers # sudo config
cat /etc/sudoers.d/*
# Check for unauthorized accounts
awk -F: '$3 == 0 {print $1}' /etc/passwd # UID 0 accounts (should only be root)
awk -F: '$3 >= 1000 {print $1}' /etc/passwd # regular user accounts
awk -F: '$7 !~ /nologin|false/ {print}' /etc/passwd # accounts with shell access
awk -F: '$2 == "" {print $1}' /etc/shadow # accounts with no password
BASH HISTORY AND USER ARTIFACTS#
# History files (check all users)
cat /home/*/.bash_history
cat /root/.bash_history
cat /home/*/.zsh_history
cat /home/*/.python_history
cat /home/*/.mysql_history
cat /home/*/.psql_history
# History file timestamps (HISTTIMEFORMAT)
# If HISTTIMEFORMAT was set, history shows timestamps
HISTTIMEFORMAT="%F %T " history
# Recently accessed files per user
find /home -name ".*_history" -exec echo "=== {} ===" \; -exec cat {} \;
# SSH known hosts and authorized keys
cat /home/*/.ssh/known_hosts
cat /home/*/.ssh/authorized_keys
cat /root/.ssh/authorized_keys
cat /home/*/.ssh/config
# Recently modified user files
find /home -mtime -7 -type f -ls 2>/dev/null
find /root -mtime -7 -type f -ls 2>/dev/null
SCHEDULED TASKS AND PERSISTENCE#
# Crontabs crontab -l # current user crontab crontab -l -u <username> # specific user crontab cat /etc/crontab # system crontab ls -la /etc/cron.d/ # cron.d entries ls -la /etc/cron.daily/ ls -la /etc/cron.hourly/ ls -la /etc/cron.weekly/ ls -la /etc/cron.monthly/ cat /var/spool/cron/crontabs/* # all user crontabs # Systemd timers systemctl list-timers --all # At jobs atq at -c <job_number> # Startup and services systemctl list-unit-files --type=service --state=enabled systemctl list-units --type=service --state=running ls -la /etc/init.d/ ls -la /etc/rc*.d/ # Other persistence mechanisms cat /etc/rc.local ls -la /etc/profile.d/ cat /etc/bash.bashrc cat /home/*/.bashrc cat /home/*/.bash_profile cat /home/*/.profile ls -la /etc/ld.so.preload # LD_PRELOAD hijacking cat /etc/ld.so.preload
LOG ANALYSIS#
# System logs cat /var/log/syslog # general system (Debian/Ubuntu) cat /var/log/messages # general system (RHEL/CentOS) cat /var/log/kern.log # kernel messages cat /var/log/dmesg # boot messages cat /var/log/boot.log # Authentication cat /var/log/auth.log # Debian/Ubuntu cat /var/log/secure # RHEL/CentOS # Application logs cat /var/log/apache2/access.log # Apache cat /var/log/apache2/error.log cat /var/log/nginx/access.log # Nginx cat /var/log/nginx/error.log cat /var/log/mysql/error.log # MySQL # Package management cat /var/log/dpkg.log # Debian package installs cat /var/log/yum.log # RHEL package installs cat /var/log/apt/history.log # APT history # Journalctl (systemd) journalctl --since "2 days ago" journalctl -u sshd --since "1 week ago" journalctl -p err # errors and above journalctl _UID=0 # root activity # Search logs for indicators grep -r "Failed password" /var/log/auth.log grep -r "Accepted publickey\|Accepted password" /var/log/auth.log grep -r "COMMAND" /var/log/auth.log # sudo commands grep -r "useradd\|userdel\|usermod" /var/log/auth.log zgrep -r "pattern" /var/log/*.gz # search rotated logs
FILE TIMELINE ANALYSIS#
# Files modified in last N days find / -mtime -7 -type f -ls 2>/dev/null | sort -k9 # Files accessed in last N days find / -atime -3 -type f -ls 2>/dev/null | sort -k9 # Files changed (metadata) in last N days find / -ctime -2 -type f -ls 2>/dev/null | sort -k9 # Files modified in a specific time range find / -newermt "2026-03-15" ! -newermt "2026-03-19" -type f -ls 2>/dev/null # SUID/SGID files (privilege escalation check) find / -perm -4000 -type f -ls 2>/dev/null # SUID find / -perm -2000 -type f -ls 2>/dev/null # SGID # World-writable files find / -perm -o+w -type f -ls 2>/dev/null # Files with no owner find / -nouser -o -nogroup 2>/dev/null # Recently installed packages as files find /usr -mtime -7 -type f -ls 2>/dev/null # Hidden files and directories find / -name ".*" -type f -ls 2>/dev/null find / -name ".. " -type d 2>/dev/null # hidden dirs with spaces find / -name "..." -type d 2>/dev/null # Create a full timeline (mactime format) using find find / -printf "%T+ %m %u %g %s %p\n" 2>/dev/null | sort > /evidence/timeline.txt
ROOTKIT DETECTION#
# chkrootkit apt install chkrootkit # or yum install chkrootkit chkrootkit chkrootkit -q # quiet mode (only infected) # rkhunter apt install rkhunter # or yum install rkhunter rkhunter --update rkhunter --check --sk # skip keypress prompts rkhunter --check --rwo # warnings only # Manual rootkit indicators # Compare process lists ps aux > /tmp/ps_output ls /proc | grep -E '^[0-9]+' > /tmp/proc_output # Hidden processes won't appear in ps but will in /proc # Check for kernel module rootkits lsmod | sort cat /proc/modules | sort # Compare and look for discrepancies # Check for library preloading cat /etc/ld.so.preload echo $LD_PRELOAD ldd /bin/ls # check for injected libraries # Check binary integrity rpm -Va 2>/dev/null # RHEL: verify all packages debsums -c 2>/dev/null # Debian: check changed files dpkg --verify 2>/dev/null # Unhide tool (finds hidden processes and ports) apt install unhide unhide proc unhide sys unhide-tcp
NETWORK FORENSICS#
# Active connections ss -antp ss -anup lsof -i -nP # DNS cache (if systemd-resolved) resolvectl statistics resolvectl query <domain> # Capture live traffic tcpdump -i any -w /evidence/capture.pcap -c 10000 tcpdump -i eth0 -nn port 443 # ARP cache ip neigh show arp -an # Routing ip route show route -n # Listening services ss -tlnp lsof -i -P -n | grep LISTEN # IPtables/nftables rules (check for attacker modifications) iptables -L -n -v --line-numbers iptables -t nat -L -n -v nft list ruleset
EVIDENCE PRESERVATION#
# Create forensic image of disk
dd if=/dev/sda of=/evidence/disk.img bs=4M status=progress
# or with hashing
dc3dd if=/dev/sda of=/evidence/disk.img hash=sha256 log=/evidence/dd.log
# Calculate hashes
sha256sum /evidence/disk.img > /evidence/disk.img.sha256
md5sum /evidence/disk.img > /evidence/disk.img.md5
# Hash individual files
sha256sum <file>
find /evidence -type f -exec sha256sum {} \; > /evidence/hashes.txt
# Memory acquisition
# LiME (Linux Memory Extractor)
insmod lime.ko "path=/evidence/memory.lime format=lime"
# Or use AVML (Acquire Volatile Memory for Linux)
./avml /evidence/memory.lime
# Mount evidence read-only
mount -o ro,noexec,noatime /dev/sdb1 /mnt/evidence
# Create timeline with Sleuth Kit
fls -r -m "/" /evidence/disk.img > /evidence/bodyfile.txt
mactime -b /evidence/bodyfile.txt -d > /evidence/timeline.csv
# Preserve log files
tar czf /evidence/var_log_$(date +%Y%m%d_%H%M%S).tar.gz /var/log/
# Chain of custody
echo "Evidence collected by: $(whoami)" > /evidence/chain_of_custody.txt
echo "Date: $(date -u)" >> /evidence/chain_of_custody.txt
echo "System: $(hostname)" >> /evidence/chain_of_custody.txt
echo "Hash: $(sha256sum /evidence/disk.img)" >> /evidence/chain_of_custody.txt
QUICK TRIAGE SCRIPT#
#!/bin/bash # Run as root. Save output to evidence directory. OUTDIR="/evidence/$(hostname)_$(date +%Y%m%d_%H%M%S)" mkdir -p $OUTDIR date -u > $OUTDIR/date.txt uname -a > $OUTDIR/uname.txt uptime > $OUTDIR/uptime.txt w > $OUTDIR/w.txt who > $OUTDIR/who.txt ps auxwwf > $OUTDIR/ps.txt ss -antp > $OUTDIR/ss_tcp.txt ss -anup > $OUTDIR/ss_udp.txt ip addr > $OUTDIR/ip_addr.txt ip route > $OUTDIR/ip_route.txt ip neigh > $OUTDIR/arp.txt lsof -nPl > $OUTDIR/lsof.txt lsmod > $OUTDIR/lsmod.txt mount > $OUTDIR/mount.txt last -Faiwx > $OUTDIR/last.txt lastb -Faiwx > $OUTDIR/lastb.txt 2>/dev/null cat /etc/passwd > $OUTDIR/passwd.txt cat /etc/shadow > $OUTDIR/shadow.txt 2>/dev/null crontab -l > $OUTDIR/crontab.txt 2>/dev/null cat /etc/crontab > $OUTDIR/etc_crontab.txt find / -mtime -3 -type f -ls > $OUTDIR/recent_files.txt 2>/dev/null tar czf $OUTDIR/var_log.tar.gz /var/log/ 2>/dev/null sha256sum $OUTDIR/* > $OUTDIR/hashes.txt echo "Triage complete: $OUTDIR"
REFERENCES#
- SANS Linux Forensics Cheat Sheet - The Sleuth Kit: https://www.sleuthkit.org/ - LiME: https://github.com/504ensicsLabs/LiME - AVML: https://github.com/microsoft/avml - Velociraptor: https://docs.velociraptor.app/
LINUX FORENSICS COMMANDS
=========================
Source: https://cheatsheet.johlem.net
Essential commands and procedures for Linux forensic analysis
and incident response. Always follow order of volatility.
ORDER OF VOLATILITY
--------------------
Collect evidence in this order (most volatile first):
1. CPU registers, cache, running processes
2. Memory (RAM)
3. Network state (connections, routing, ARP)
4. Running processes and open files
5. Disk (filesystem, logs, files)
6. Remote logging and monitoring data
7. Physical configuration, network topology
8. Archival media (backups, tapes)
VOLATILE DATA COLLECTION
--------------------------
# System info and uptime
date && date -u
uname -a
hostname
uptime
cat /etc/os-release
# Current users and sessions
w
who
whoami
id
last -Faiwx | head -50
# Running processes
ps auxwwf
ps -eo pid,ppid,user,args --sort=start_time
pstree -apl
top -bn1
# Open files and file descriptors
lsof -nPl
lsof -i -nP
lsof +L1 # deleted but open files (hidden data)
# Network connections
ss -tulnp # listening sockets with PIDs
ss -antp # all TCP connections
ss -anup # all UDP connections
netstat -tulnp # alternative if ss unavailable
netstat -antp
# Network configuration
ip addr show
ip route show
ip neigh show # ARP table
iptables -L -n -v # firewall rules
cat /etc/resolv.conf
cat /etc/hosts
# Loaded kernel modules
lsmod
cat /proc/modules
# Mounted filesystems
mount
df -h
cat /etc/fstab
cat /proc/mounts
# Environment variables (for all users)
env
printenv
cat /proc/*/environ 2>/dev/null | tr '\0' '\n'
PROC FILESYSTEM ANALYSIS
--------------------------
# Process details for PID
ls -la /proc/<PID>/
cat /proc/<PID>/cmdline | tr '\0' ' ' # command line
cat /proc/<PID>/environ | tr '\0' '\n' # environment
ls -la /proc/<PID>/exe # link to binary
ls -la /proc/<PID>/cwd # working directory
ls -la /proc/<PID>/fd/ # open file descriptors
cat /proc/<PID>/maps # memory mappings
cat /proc/<PID>/status # process status
cat /proc/<PID>/net/tcp # TCP connections (per PID namespace)
# Recover deleted binary still running in memory
cp /proc/<PID>/exe /evidence/recovered_binary
# System-wide proc info
cat /proc/version
cat /proc/cmdline # kernel boot parameters
cat /proc/meminfo
cat /proc/cpuinfo
cat /proc/sys/net/ipv4/ip_forward # IP forwarding status
# Detect hidden processes (compare)
ls /proc/ | grep -E '^[0-9]+$' | sort -n > /tmp/proc_pids
ps -eo pid --no-headers | sort -n > /tmp/ps_pids
diff /tmp/proc_pids /tmp/ps_pids
USER ACTIVITY AND LOGIN HISTORY
---------------------------------
# Login records
last -Faiwx # all login history from wtmp
lastb -Faiwx # failed login attempts from btmp
lastlog # last login for each user
# Currently logged in
who
w
finger # if installed
# Authentication logs
cat /var/log/auth.log # Debian/Ubuntu
cat /var/log/secure # RHEL/CentOS
journalctl -u sshd # systemd SSH logs
# SSH specific
cat /var/log/auth.log | grep sshd
cat /var/log/auth.log | grep "Accepted\|Failed"
cat /var/log/auth.log | grep "session opened\|session closed"
# User accounts
cat /etc/passwd # all accounts
cat /etc/shadow # password hashes (need root)
cat /etc/group # group memberships
cat /etc/sudoers # sudo config
cat /etc/sudoers.d/*
# Check for unauthorized accounts
awk -F: '$3 == 0 {print $1}' /etc/passwd # UID 0 accounts (should only be root)
awk -F: '$3 >= 1000 {print $1}' /etc/passwd # regular user accounts
awk -F: '$7 !~ /nologin|false/ {print}' /etc/passwd # accounts with shell access
awk -F: '$2 == "" {print $1}' /etc/shadow # accounts with no password
BASH HISTORY AND USER ARTIFACTS
---------------------------------
# History files (check all users)
cat /home/*/.bash_history
cat /root/.bash_history
cat /home/*/.zsh_history
cat /home/*/.python_history
cat /home/*/.mysql_history
cat /home/*/.psql_history
# History file timestamps (HISTTIMEFORMAT)
# If HISTTIMEFORMAT was set, history shows timestamps
HISTTIMEFORMAT="%F %T " history
# Recently accessed files per user
find /home -name ".*_history" -exec echo "=== {} ===" \; -exec cat {} \;
# SSH known hosts and authorized keys
cat /home/*/.ssh/known_hosts
cat /home/*/.ssh/authorized_keys
cat /root/.ssh/authorized_keys
cat /home/*/.ssh/config
# Recently modified user files
find /home -mtime -7 -type f -ls 2>/dev/null
find /root -mtime -7 -type f -ls 2>/dev/null
SCHEDULED TASKS AND PERSISTENCE
---------------------------------
# Crontabs
crontab -l # current user crontab
crontab -l -u <username> # specific user crontab
cat /etc/crontab # system crontab
ls -la /etc/cron.d/ # cron.d entries
ls -la /etc/cron.daily/
ls -la /etc/cron.hourly/
ls -la /etc/cron.weekly/
ls -la /etc/cron.monthly/
cat /var/spool/cron/crontabs/* # all user crontabs
# Systemd timers
systemctl list-timers --all
# At jobs
atq
at -c <job_number>
# Startup and services
systemctl list-unit-files --type=service --state=enabled
systemctl list-units --type=service --state=running
ls -la /etc/init.d/
ls -la /etc/rc*.d/
# Other persistence mechanisms
cat /etc/rc.local
ls -la /etc/profile.d/
cat /etc/bash.bashrc
cat /home/*/.bashrc
cat /home/*/.bash_profile
cat /home/*/.profile
ls -la /etc/ld.so.preload # LD_PRELOAD hijacking
cat /etc/ld.so.preload
LOG ANALYSIS
-------------
# System logs
cat /var/log/syslog # general system (Debian/Ubuntu)
cat /var/log/messages # general system (RHEL/CentOS)
cat /var/log/kern.log # kernel messages
cat /var/log/dmesg # boot messages
cat /var/log/boot.log
# Authentication
cat /var/log/auth.log # Debian/Ubuntu
cat /var/log/secure # RHEL/CentOS
# Application logs
cat /var/log/apache2/access.log # Apache
cat /var/log/apache2/error.log
cat /var/log/nginx/access.log # Nginx
cat /var/log/nginx/error.log
cat /var/log/mysql/error.log # MySQL
# Package management
cat /var/log/dpkg.log # Debian package installs
cat /var/log/yum.log # RHEL package installs
cat /var/log/apt/history.log # APT history
# Journalctl (systemd)
journalctl --since "2 days ago"
journalctl -u sshd --since "1 week ago"
journalctl -p err # errors and above
journalctl _UID=0 # root activity
# Search logs for indicators
grep -r "Failed password" /var/log/auth.log
grep -r "Accepted publickey\|Accepted password" /var/log/auth.log
grep -r "COMMAND" /var/log/auth.log # sudo commands
grep -r "useradd\|userdel\|usermod" /var/log/auth.log
zgrep -r "pattern" /var/log/*.gz # search rotated logs
FILE TIMELINE ANALYSIS
------------------------
# Files modified in last N days
find / -mtime -7 -type f -ls 2>/dev/null | sort -k9
# Files accessed in last N days
find / -atime -3 -type f -ls 2>/dev/null | sort -k9
# Files changed (metadata) in last N days
find / -ctime -2 -type f -ls 2>/dev/null | sort -k9
# Files modified in a specific time range
find / -newermt "2026-03-15" ! -newermt "2026-03-19" -type f -ls 2>/dev/null
# SUID/SGID files (privilege escalation check)
find / -perm -4000 -type f -ls 2>/dev/null # SUID
find / -perm -2000 -type f -ls 2>/dev/null # SGID
# World-writable files
find / -perm -o+w -type f -ls 2>/dev/null
# Files with no owner
find / -nouser -o -nogroup 2>/dev/null
# Recently installed packages as files
find /usr -mtime -7 -type f -ls 2>/dev/null
# Hidden files and directories
find / -name ".*" -type f -ls 2>/dev/null
find / -name ".. " -type d 2>/dev/null # hidden dirs with spaces
find / -name "..." -type d 2>/dev/null
# Create a full timeline (mactime format) using find
find / -printf "%T+ %m %u %g %s %p\n" 2>/dev/null | sort > /evidence/timeline.txt
ROOTKIT DETECTION
------------------
# chkrootkit
apt install chkrootkit # or yum install chkrootkit
chkrootkit
chkrootkit -q # quiet mode (only infected)
# rkhunter
apt install rkhunter # or yum install rkhunter
rkhunter --update
rkhunter --check --sk # skip keypress prompts
rkhunter --check --rwo # warnings only
# Manual rootkit indicators
# Compare process lists
ps aux > /tmp/ps_output
ls /proc | grep -E '^[0-9]+' > /tmp/proc_output
# Hidden processes won't appear in ps but will in /proc
# Check for kernel module rootkits
lsmod | sort
cat /proc/modules | sort
# Compare and look for discrepancies
# Check for library preloading
cat /etc/ld.so.preload
echo $LD_PRELOAD
ldd /bin/ls # check for injected libraries
# Check binary integrity
rpm -Va 2>/dev/null # RHEL: verify all packages
debsums -c 2>/dev/null # Debian: check changed files
dpkg --verify 2>/dev/null
# Unhide tool (finds hidden processes and ports)
apt install unhide
unhide proc
unhide sys
unhide-tcp
NETWORK FORENSICS
------------------
# Active connections
ss -antp
ss -anup
lsof -i -nP
# DNS cache (if systemd-resolved)
resolvectl statistics
resolvectl query <domain>
# Capture live traffic
tcpdump -i any -w /evidence/capture.pcap -c 10000
tcpdump -i eth0 -nn port 443
# ARP cache
ip neigh show
arp -an
# Routing
ip route show
route -n
# Listening services
ss -tlnp
lsof -i -P -n | grep LISTEN
# IPtables/nftables rules (check for attacker modifications)
iptables -L -n -v --line-numbers
iptables -t nat -L -n -v
nft list ruleset
EVIDENCE PRESERVATION
----------------------
# Create forensic image of disk
dd if=/dev/sda of=/evidence/disk.img bs=4M status=progress
# or with hashing
dc3dd if=/dev/sda of=/evidence/disk.img hash=sha256 log=/evidence/dd.log
# Calculate hashes
sha256sum /evidence/disk.img > /evidence/disk.img.sha256
md5sum /evidence/disk.img > /evidence/disk.img.md5
# Hash individual files
sha256sum <file>
find /evidence -type f -exec sha256sum {} \; > /evidence/hashes.txt
# Memory acquisition
# LiME (Linux Memory Extractor)
insmod lime.ko "path=/evidence/memory.lime format=lime"
# Or use AVML (Acquire Volatile Memory for Linux)
./avml /evidence/memory.lime
# Mount evidence read-only
mount -o ro,noexec,noatime /dev/sdb1 /mnt/evidence
# Create timeline with Sleuth Kit
fls -r -m "/" /evidence/disk.img > /evidence/bodyfile.txt
mactime -b /evidence/bodyfile.txt -d > /evidence/timeline.csv
# Preserve log files
tar czf /evidence/var_log_$(date +%Y%m%d_%H%M%S).tar.gz /var/log/
# Chain of custody
echo "Evidence collected by: $(whoami)" > /evidence/chain_of_custody.txt
echo "Date: $(date -u)" >> /evidence/chain_of_custody.txt
echo "System: $(hostname)" >> /evidence/chain_of_custody.txt
echo "Hash: $(sha256sum /evidence/disk.img)" >> /evidence/chain_of_custody.txt
QUICK TRIAGE SCRIPT
---------------------
#!/bin/bash
# Run as root. Save output to evidence directory.
OUTDIR="/evidence/$(hostname)_$(date +%Y%m%d_%H%M%S)"
mkdir -p $OUTDIR
date -u > $OUTDIR/date.txt
uname -a > $OUTDIR/uname.txt
uptime > $OUTDIR/uptime.txt
w > $OUTDIR/w.txt
who > $OUTDIR/who.txt
ps auxwwf > $OUTDIR/ps.txt
ss -antp > $OUTDIR/ss_tcp.txt
ss -anup > $OUTDIR/ss_udp.txt
ip addr > $OUTDIR/ip_addr.txt
ip route > $OUTDIR/ip_route.txt
ip neigh > $OUTDIR/arp.txt
lsof -nPl > $OUTDIR/lsof.txt
lsmod > $OUTDIR/lsmod.txt
mount > $OUTDIR/mount.txt
last -Faiwx > $OUTDIR/last.txt
lastb -Faiwx > $OUTDIR/lastb.txt 2>/dev/null
cat /etc/passwd > $OUTDIR/passwd.txt
cat /etc/shadow > $OUTDIR/shadow.txt 2>/dev/null
crontab -l > $OUTDIR/crontab.txt 2>/dev/null
cat /etc/crontab > $OUTDIR/etc_crontab.txt
find / -mtime -3 -type f -ls > $OUTDIR/recent_files.txt 2>/dev/null
tar czf $OUTDIR/var_log.tar.gz /var/log/ 2>/dev/null
sha256sum $OUTDIR/* > $OUTDIR/hashes.txt
echo "Triage complete: $OUTDIR"
REFERENCES
----------
- SANS Linux Forensics Cheat Sheet
- The Sleuth Kit: https://www.sleuthkit.org/
- LiME: https://github.com/504ensicsLabs/LiME
- AVML: https://github.com/microsoft/avml
- Velociraptor: https://docs.velociraptor.app/
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.