Computer Forensics Assignment Help, Computer Forensics Project, Digital Forensic
CDS 341 SURVEY OF DIGITAL FORENSICS
LINUX SYSTEM COMMANDS AND FORENSICS ASSIGNMENT
Define the following terms:
Bootstrap Environment
Grand Unified Bootloader (GRUB)
Graphical User Interface (GUI)
Intrusion Detection System (IDS)
Journaling
Linux Directories
Linux Filesystems
Linux Loader (LILO)
Linux Shell
Identify each log and whether it is important to forensic investigations; if so, how:
/var/log/faillog
/var/log/kern.log
/var/log/lpr.log
/var/log/mail
/var/log/mysql.*
/var/log/apache2/*
/var/log/lighttpd/*
/var/log/apport.log
Intrusion detection system logs
Linux Shell Command Identification: What is the purpose of the following key Linux directories and the types of files they contain?
/dmesg
/pstree
/file
/root
/bin
/sbin
/etc
/etc/inittab
/dev
/mnt
/boot
/usr
/var
/var/spool
/proc
Of the above directories, answer the following:
Which directories are most likely to contain malware?
Which directories hold files that an attacker could modify to change application behavior?
Which directories hold files that an attacker could modify to change system behavior?
Which directories are most important to check when performing live analysis and before shutting down the system?