Please enable JavaScript.
Coggle requires JavaScript to display documents.
9️⃣ Evidence Collection (Enterprise Linux Incident Response) 📂 - Coggle…
9️⃣ Evidence Collection (Enterprise Linux Incident Response) 📂
📖 Definition
Evidence Collection = The process of collecting, preserving, documenting, and securing all digital evidence after a security incident.
Goal
Identify what happened
Determine attacker activities
Preserve evidence for legal action
Support forensic investigation
Prevent evidence tampering
Assist recovery and lessons learned
Principle
Collect first
Analyze later
Never modify original evidence
Maintain integrity
Maintain chain of custody
🎯 Objectives
Identify attack source
Identify compromised systems
Identify affected users
Determine attacker timeline
Preserve volatile evidence
Preserve non-volatile evidence
Support legal investigation
Support compliance requirements
🏢 Enterprise Preparation Before Collection
Evidence Collection Kit
Write-blocker
External SSD
USB Boot Forensics Kit
Memory Acquisition Tool
Hashing Tools
Secure Evidence Storage
Investigation Laptop
Linux Forensics Distribution
Kali Linux
SIFT Workstation
REMnux
Documentation
Incident Ticket
Case Number
Investigator Name
Investigation Notes
Time Synchronization
Verify NTP
date
timedatectl
chronyc tracking
1️⃣ First Response
Do NOT Shutdown System
RAM evidence will be lost
Running processes disappear
Network connections disappear
Do NOT Reboot
Do NOT Delete Files
Do NOT Restart Services
Disconnect Network if Required
Physical Cable
Switch Port Shutdown
Firewall Isolation
EDR Isolation
Photograph Screen
Record Current State
2️⃣ Chain of Custody
Definition
Documentation proving who collected evidence
Who accessed evidence
Where evidence stored
When transferred
Record
Case Number
Date
Time
Hostname
Investigator
Evidence ID
Serial Number
Hash Value
Storage Location
3️⃣ Evidence Categories
Volatile Evidence
RAM
Running Processes
Logged-in Users
Open Files
Network Connections
Kernel Modules
Mounted File Systems
Clipboard
Cache
Environment Variables
Non-Volatile Evidence
Disk Image
Logs
Configuration Files
User Files
Cron Jobs
SSH Keys
Bash History
Databases
Backups
4️⃣ System Identification
Hostname
hostnamectl
hostname
Path
/etc/hostname
Operating System
cat /etc/os-release
uname -a
lsb_release -a
Kernel
uname -r
Architecture
uname -m
Uptime
uptime
Time
date
timedatectl
5️⃣ User Evidence
Logged In Users
who
w
users
Login History
last
lastlog
faillog
User Accounts
cat /etc/passwd
cat /etc/shadow
Groups
cat /etc/group
Sudo Users
getent group sudo
getent group wheel
sudo -l
SSH Keys
~/.ssh/
/root/.ssh/
authorized_keys
known_hosts
6️⃣ Running Process Evidence
List Processes
ps aux
ps -ef
top
htop
Process Tree
pstree -p
Process Files
lsof
Process Executable
ls -l /proc/PID/exe
Process Environment
cat /proc/PID/environ
7️⃣ Memory Evidence (RAM)
Importance
Malware
Encryption Keys
Passwords
Running Malware
Network Connections
Injected Code
Enterprise Tools
LiME
AVML
WinPMEM (Windows)
Save Memory
lime.ko
Store Image
External Storage
Calculate Hash
sha256sum memory.lime
8️⃣ Network Evidence
IP Address
ip addr
Routing Table
ip route
ARP Cache
ip neigh
arp -a
Listening Ports
ss -tulnp
netstat -tulnp
Active Connections
ss -antp
lsof -i
Firewall
nft list ruleset
iptables -L
firewall-cmd --list-all
DNS
cat /etc/resolv.conf
Hosts
cat /etc/hosts
9️⃣ File System Evidence
Mounted File Systems
mount
findmnt
lsblk
Disk Usage
df -h
du -sh
Recently Modified Files
find / -mtime -1
find / -mmin -60
Suspicious Files
find /tmp
find /var/tmp
find /dev/shm
Hidden Files
find / -name ".*"
SUID Files
find / -perm -4000
SGID Files
find / -perm -2000
World Writable
find / -perm -0002
🔟 Log Evidence
System Logs
/var/log/messages
/var/log/syslog
Authentication Logs
/var/log/secure
/var/log/auth.log
Kernel Logs
dmesg
journalctl -k
Journal Logs
journalctl
SSH Logs
journalctl -u ssh
journalctl -u sshd
Cron Logs
/var/log/cron
Web Logs
/var/log/httpd/
/var/log/apache2/
/var/log/nginx/
Database Logs
/var/log/mysql/
/var/log/mariadb/
PostgreSQL Logs
1️⃣1️⃣ Persistence Evidence
Cron Jobs
crontab -l
/etc/crontab
/etc/cron.*
Startup Services
systemctl list-unit-files
systemctl list-units
rc.local
/etc/rc.local
Bash Profiles
~/.bashrc
~/.profile
/etc/profile
Systemd Services
/etc/systemd/system/
/usr/lib/systemd/system/
1️⃣2️⃣ Malware Evidence
Suspicious Processes
Suspicious Network Connections
Suspicious Users
Recently Executed Files
Downloaded Payloads
Encoded Scripts
Base64 Commands
Reverse Shell Indicators
Crypto Miner Processes
1️⃣3️⃣ Disk Imaging
Purpose
Exact Bit-by-Bit Copy
Preserve Original Evidence
Enterprise Tools
dd
dcfldd
dcfldd
Guymager
FTK Imager
Example
dd if=/dev/sda of=/evidence/server01.img bs=4M status=progress
Verify
sha256sum server01.img
1️⃣4️⃣ Hash Verification
Purpose
Verify Integrity
Detect Modification
Algorithms
SHA256
SHA512
MD5 Legacy Only
Commands
sha256sum filename
sha512sum filename
md5sum filename
1️⃣5️⃣ Timeline Collection
File Creation
File Modification
File Access
User Logins
Process Start
Service Start
Bash History
Journal Timeline
Tools
stat
journalctl
ausearch
log2timeline
1️⃣6️⃣ Evidence Storage
Read Only Storage
Secure Evidence Vault
Encryption
Access Control
Backup Copies
Evidence ID
Digital Signature
1️⃣7️⃣ Documentation
Case Number
Asset Name
IP Address
Hostname
Investigator
Evidence Description
Commands Executed
Time Collected
Hash Values
Storage Location
Chain of Custody Updates
1️⃣8️⃣ Enterprise Best Practices
Work On Copies Never Original
Calculate Hash Before Analysis
Calculate Hash After Analysis
Preserve Time Synchronization
Collect RAM Before Shutdown
Record Every Command Executed
Use Read-Only Media
Encrypt Evidence Storage
Restrict Access
Maintain Audit Trail
Follow NIST SP 800-61
Follow ISO 27035
Follow Chain of Custody
Validate Evidence Integrity Before Every Transfer
🎯 Final Deliverables
Memory Dump
Disk Image
Log Archive
Network Connection Snapshot
Running Process List
User Activity Report
Timeline Report
Hash Verification Report
Chain of Custody Form
Evidence Inventory
Forensic Package Ready For Investigation