CompTIA SecurityX (CAS-005)Security OperationsHard
An incident response team is analyzing a compromised Linux server. They discover that a malicious user account was created by an attacker, and this account was subsequently used to modify critical system files. The team needs to determine the exact commands executed by the attacker using this malicious account. Which of the following log files would be MOST crucial to review for this information on a standard Linux system?
- A/var/log/auth.log
- B~/.bash_history
- C/var/log/messages
- D/var/log/kern.log
Show answer & explanationAnswer & explanation
Correct answer: B. ~/.bash_history
While /var/log/auth.log would show the malicious user logging in, the `~/.bash_history` file (or history files for other shells) for that specific user is MOST crucial for determining the exact commands executed. This file stores a chronological list of commands typed into the shell by that user.
Why the other options are wrong
- A. /var/log/auth.log (or /var/log/secure on some systems) would show authentication attempts and successful logins for the malicious user, but not the specific commands they executed.
- C. /var/log/messages contains general system messages, not typically specific user commands.
- D. /var/log/kern.log contains kernel-related messages and warnings, not user-executed commands.
Linux Shell History
Linux shell history files (e.g., ~/.bash_history) store commands executed by a user in their shell, providing a chronological record of their actions.
- Specific to each user and their shell.
- Can be manipulated or cleared by an attacker.
- Crucial for forensic analysis of user activity.
Memory trick: Audit Records History of Commands.