#linuxforensics — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #linuxforensics, aggregated by home.social.
-
Analyze Linux process arguments and environment directly from kernel memory using Volatility 3's linux.psaux.PsAux plugin. It walks task_struct to access mm_struct and reads user-space stack strings—more reliable than /proc/[pid]/cmdline during live analysis. #volatility #linuxforensics #memoryforensics
https://www.valtersit.com/vault/analyze-linux-process-arguments-and-environment-from-kernel--cdbc4a/
-
If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.
#DFIR #LinuxForensics #SIEM #CSIRT
https://kostas-ts.medium.com/telemetry-on-linux-vs-windows-a-comparative-analysis-849f6b43ef8e
-
If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.
#DFIR #LinuxForensics #SIEM #CSIRT
https://kostas-ts.medium.com/telemetry-on-linux-vs-windows-a-comparative-analysis-849f6b43ef8e
-
Linux Forensics Analysis Cheatsheet: https://fareedfauzi.github.io/2024/03/29/Linux-Forensics-cheatsheet.html
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Linux Forensics - I have just completed this room! Check it out: https://tryhackme.com/room/linuxforensics #tryhackme #security #linux #dfir #forensics #artifacts #incidentresponse #linuxforensics via @RealTryHackMe
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Linux Forensics - I have just completed this room! Check it out: https://tryhackme.com/room/linuxforensics #tryhackme #security #linux #dfir #forensics #artifacts #incidentresponse #linuxforensics via @RealTryHackMe