Performing Linux Log Forensics Investigation

Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal (via journalctl), kern.log, auditd, and application logs to reconstruct user sessions, identify unauthorized access and privilege escalation, trace lateral movement, and establish event timelines. Use when investigating a suspected compromise of a Linux system and needing to analyze SSH, sudo, cron, or kernel-level activity from plain-text or systemd journal logs.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/performing-linux-log-forensics-investigation commit a4925c8341

Frequently asked questions

npx skillmds@latest add gabrielmoreira/performing-linux-log-forensics-investigation