Forensics Keyword List

This section covers forensics keyword information.

WTMP Log Data
WTMP data will contain the data for current and past logged in users reported typically under /var/log/wtmp. The WTMP file will reveal current and past logg...
Wed, 26 Jul, 2023 at 5:41 PM
BTMP Log Data
BTMP data will contain the data for bad login attempts under /var/run/btmp. The BTMP file will reveal invalid login attempts and where they originated. ...
Wed, 26 Jul, 2023 at 5:00 PM
Kernel Module Data
The Kernel Module data contains all attributes about a Linux kernel module that was flagged by Sandfly Security or a user defined sandfly for whatever reaso...
Wed, 26 Jul, 2023 at 4:59 PM
Systemd Data
The Systemd data contains all attributes about a systemd unit or user session that were flagged by Sandfly Security or a user defined sandfly for whatever r...
Wed, 26 Jul, 2023 at 4:57 PM
Cron Job Data
The data here will contain cron job information on the host if it was flagged by Sandfly Security or by a user. The formatting reflects standard Linux cron ...
Wed, 26 Jul, 2023 at 4:55 PM
At Job Data
These fields are for "at" job scheduled on the remote system flagged by Sandfly Security or by a user. They are formatted for easier parsing from ...
Wed, 26 Jul, 2023 at 4:54 PM