Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / THREAT HUNT / LINUX

Hunt Matrix

LayerQuestionPrimary Artifacts
AuthenticationWho entered?auth.log, secure, journalctl
ExecutionWhat ran?bash_history, auditd, process artifacts
PersistenceWhat survives reboot?cron, systemd, rc.local
Privilege EscalationHow did they elevate?sudo logs, auth logs
Lateral MovementSSH / remote actions?ssh logs, authorized_keys
File ActivityWhat changed?mtime/ctime, package logs
NetworkWho connected where?ss, netstat remnants, journal
Malware / PayloadsWhat binaries/scripts exist?tmp, dev/shm, hidden files