Skip to content

Linux Artifacts

Where Linux records accounts, logins, commands, installed software, and persistence.

Why It Matters

Linux servers often run internet-facing services and rarely have the same endpoint monitoring as Windows workstations. The artifacts on the host are frequently the main evidence of how an attacker got in and what they did.

Reference

Accounts and Credentials

File Contents
/etc/passwd Every account, with UID, home directory, and shell
/etc/shadow Password hashes and password aging; readable only by root
/etc/group Group membership
/etc/sudoers, /etc/sudoers.d/ Who can run what with sudo
~/.ssh/authorized_keys Public keys allowed to log in as the user

Logs

Log Contents Read With
/var/log/auth.log (Debian/Ubuntu), /var/log/secure (RHEL) Authentication, sudo, SSH grep, less
/var/log/syslog (Debian/Ubuntu), /var/log/messages (RHEL) General system messages grep, less
/var/log/wtmp Logins and logouts last
/var/log/btmp Failed logins lastb
/var/log/lastlog Last login per user lastlog
/var/log/faillog Failed login counters faillog
/var/log/dpkg.log Packages installed or removed grep, less
/var/log/cron (RHEL), syslog (Debian/Ubuntu) Cron job activity grep
/var/log/apache2/access.log, /var/log/nginx/access.log Web requests See Web Server Logs
systemd journal All of the above on systemd systems journalctl

Installed Software

Distribution Command
Debian / Ubuntu dpkg -l, or grep Package /var/lib/dpkg/status
RHEL / Fedora rpm -qa

User Activity

Artifact Location
Bash history ~/.bash_history, /root/.bash_history
Shell startup files ~/.bashrc, ~/.profile
Trash ~/.local/share/Trash
User directories Desktop, Downloads, Documents
World-writable staging areas /tmp, /var/tmp, /dev/shm

Persistence Locations

Mechanism Location
Cron /etc/crontab, /etc/cron.*, /var/spool/cron/, crontab -l for each user
systemd services and timers /etc/systemd/system/, ~/.config/systemd/user/, systemctl list-timers
Shell startup files ~/.bashrc, ~/.profile, /etc/profile.d/
SSH keys ~/.ssh/authorized_keys
Legacy startup script /etc/rc.local

A missing history is evidence too

history -c clears the current shell's history, and attackers often unset HISTFILE or link .bash_history to /dev/null. An empty or missing history file on an active account is worth noting.

How I Use It

I start with auth.log or secure to see who logged in and from where, then last and lastb for login history, then bash history for the accounts involved. After that I check every persistence location in the table above, because attackers on Linux almost always leave a cron job, a systemd service, or an SSH key behind. Network state comes from ss -tunap and ss -tulnp.

Resources