August 2017
Intermediate to advanced
336 pages
11h 39m
English
Like Windows, Linux has a number of logs that can be very interesting for a forensic investigation. This section provides a brief description of each of the major Linux logs and the forensic relevance of that log.
This log file contains failed user logins. This can be very important when tracking attempts to crack into the system. Usually, a normal user might occasionally have one or two failed login attempts. Numerous failed login attempts, or even frequent failed login attempts that occur at diverse times, can be an indicator of someone trying to compromise access to the system. It is also worth noting the times of failed login attempts. If an employee normally works from 8:00 a.m. to 5:00 p.m., and ...
Read now
Unlock full access