Deterministic audit against vendored MITRE/NIST oracles (ATT&CK v19.1,
ATLAS 2026.07, NIST CSF 2.0, D3FEND v1.4.0) found and fixed:
- 27 wrong-framework leaks on 12 AI-security skills: ATLAS AML.* IDs were
under `mitre_attack` (-> `atlas_techniques`) and AI-RMF GOVERN/MEASURE IDs
under `nist_csf` (-> `nist_ai_rmf`).
- RS.AN-01 -> RS.AN-03 on 37 forensics/incident-analysis skills (CSF 1.1 ID
retired in CSF 2.0; RS.AN-03 is the incident-analysis successor).
- PR.DS-06 -> PR.DS-01 on the SLSA/Sigstore provenance skill (CSF 1.1 ID
absorbed into PR.DS-01 in CSF 2.0; body prose updated too).
- AML.T0104 -> AML.T0010 on 3 software-supply-chain skills (T0104 is
"Publish Poisoned AI Agent Tool" -- wrong topic; T0010 "AI Supply Chain
Compromise" is correct).
CSF/ATLAS replacements verified against NIST CSWP.29, the official CSF
1.1->2.0 transition workbook, and mitre-atlas/atlas-data.
Framework-ID gate: 0 defects. Schema: 817/817 pass.
Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised Linux systems.
cybersecurity
digital-forensics
linux-forensics
syslog
auth-log
systemd-journal
journalctl
linux-logs
ssh-forensics
cron
audit-log
log-analysis
1.0
mahipal
Apache-2.0
RS.AN-03
DE.AE-02
RS.MA-01
T1005
T1074
T1119
T1070
T1059
Performing Linux Log Forensics Investigation
Overview
Linux systems maintain extensive logs that serve as primary evidence sources in forensic investigations. Unlike Windows Event Logs, Linux logs are typically plain-text files stored in /var/log/ and binary journal files managed by systemd-journald. Key forensic logs include auth.log (authentication events, sudo usage, SSH sessions), syslog (system-wide messages), kern.log (kernel events), and application-specific logs. The Linux Audit framework (auditd) provides detailed security event logging comparable to Windows Security Event Logs. Forensic analysis of these logs enables investigators to reconstruct user sessions, identify unauthorized access, detect privilege escalation, trace lateral movement, and establish comprehensive event timelines.
When to Use
When conducting security assessments that involve performing linux log forensics investigation
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing
Prerequisites
Familiarity with digital forensics concepts and tools
Access to a test or lab environment for safe execution
Python 3.8+ with required dependencies installed
Appropriate authorization for any testing activities
Key Log Files and Locations
Log File
Path
Contents
auth.log / secure
/var/log/auth.log (Debian) or /var/log/secure (RHEL)
Authentication, sudo, SSH, PAM
syslog / messages
/var/log/syslog (Debian) or /var/log/messages (RHEL)