|
In this chapter, you were given a general introduction to the Linux operating system, along with basic forensics. You learned which logs to look at for specific types of evidence and how to retrieve those logs. You also learned about specific directories and shell commands that are useful in a forensic investigation. Furthermore, you were introduced to recovering data from a file system. You may also want to check out specific websites devoted to Linux forensics. A great one is http://www.linux-forensics.com.
|