performing-linux-log-forensics-investigation - Performing Linux Log Forensics Investigation
Perform forensic investigation of Linux system logs to reconstruct user activity, detect unauthorized access, and establish event timelines.
Tags
Updated: 2026-09-23Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Analyze Linux authentication logs
- Export systemd journal logs
- Search Linux audit framework events
- Inspect cron job execution logs
- Detect SSH brute force attempts
- Generate forensic analysis report
Inputs
- Linux system log files
- Authentication log file path
- Output directory path
Outputs
- Exported journal JSON files
- JSON forensic analysis report
- Console summary output
Requirements
- Python 3.8 or higher
- Access to Linux system log files
- Authorization for testing activities
