home.social

#linuxforensics — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #linuxforensics, aggregated by home.social.

fetched live
  1. Analyze Linux process arguments and environment directly from kernel memory using Volatility 3's linux.psaux.PsAux plugin. It walks task_struct to access mm_struct and reads user-space stack strings—more reliable than /proc/[pid]/cmdline during live analysis. #volatility #linuxforensics #memoryforensics

    valtersit.com/vault/analyze-li

  2. If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.

    #DFIR #LinuxForensics #SIEM #CSIRT

    kostas-ts.medium.com/telemetry

  3. If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.

    #DFIR #LinuxForensics #SIEM #CSIRT

    kostas-ts.medium.com/telemetry