February 2026
Intermediate to advanced
456 pages
17h 3m
English
Like Windows, Linux has a number of logs that can be interesting for a forensic investigation. This section provides a brief description of each of the major Linux logs and the forensic relevance of that log.
This log file contains failed user logins. This can be very important when tracking attempts to crack into the system. Usually, a normal user might occasionally have one or two failed login attempts. Numerous failed login attempts, or even frequent failed login attempts that occur at diverse times, can be an indicator of someone trying to compromise access to the system. It is also worth noting the times of failed login attempts. If an employee normally works from 8:00 a.m. to 5:00 p.m. and there are ...
Read now
Unlock full access