Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / LINUX

Linux Matrix

ArtifactData StoredExecCreateDeletePersistUserNetPrivEscTimestompMITREToolsLocation
Bash HistoryUser command historyT1059cat ~/.bash_history/home/*/.bash_history
Auth LogsSSH logins, sudo usage, failed authT1021grep -i "ssh" /var/log/auth.log<br>grep -i "sudo" /var/log/auth.log/var/log/auth.log
Secure Log (RHEL)Authentication eventsT1021grep -i "failed" /var/log/secure/var/log/secure
SyslogSystem-wide eventsVariousless /var/log/syslog/var/log/syslog
JournalctlSystemd logsVariousjournalctl -xe<br>journalctl --since "1 hour ago"systemd journal
wtmpSuccessful loginsT1033last/var/log/wtmp
btmpFailed loginsT1110lastb/var/log/btmp
lastlogLast login per userT1033lastlog/var/log/lastlog
Crontab (User)Scheduled jobsT1053.003crontab -lUser crontabs
Crontab (System)System scheduled jobsT1053.003cat /etc/crontab/etc/crontab
Systemd ServicesService persistenceT1543.002systemctl list-unit-files/etc/systemd/system
rc.localStartup commandsT1037cat /etc/rc.local/etc/rc.local
SSH Authorized KeysBackdoor access keysT1098cat ~/.ssh/authorized_keys~/.ssh/authorized_keys
SSH ConfigSSH settingsT1021cat /etc/ssh/sshd_config/etc/ssh/sshd_config
/etc/passwdUser accountsT1136cat /etc/passwd/etc/passwd
/etc/shadowPassword hashesT1003sudo cat /etc/shadow/etc/shadow
SudoersPrivilege escalation rulesT1548cat /etc/sudoers/etc/sudoers
Auditd LogsDetailed syscall loggingVariousausearch -ts recent/var/log/audit/audit.log
File MAC TimesFile timestampsT1070stat filenameAny file
Inotify LogsFile monitoringVariousinotifywatch -r /pathMonitored dirs
Network ConnectionsActive socketsT1105ss -tunap/proc/net
iptables RulesFirewall configT1562iptables -L -n -vKernel firewall
Hosts FileDNS overridesT1565cat /etc/hosts/etc/hosts
Docker LogsContainer logsT1610docker ps<br>docker logs <id>Docker runtime
Kube Audit LogsKubernetes API activityT1610cat /var/log/kube-apiserver-audit.logK8s control plane
/proc ArtifactsRunning processesT1057ps aux<br>ls /proc/<pid>/proc
LD_PRELOADLibrary hijackingT1574cat /etc/ld.so.preload/etc/ld.so.preload