| Command | What it does | When to use |
|---|---|---|
files | Open files (system-wide) | Find suspicious file usage |
files -p <pid> | Files for process | What was process touching |
mount | Mounted filesystems | Detect weird mounts |
BLUE TEAM / MALWARE REVERSE / LINUX / CRASH
| Command | What it does | When to use |
|---|---|---|
files | Open files (system-wide) | Find suspicious file usage |
files -p <pid> | Files for process | What was process touching |
mount | Mounted filesystems | Detect weird mounts |