A security analyst is investigating a Linux system where a user's account was compromised. The attacker is believed to have used a privilege escalation exploit and then tried to cover their tracks by deleting critical log files. Which of the following host-based forensic artifacts, if present, would provide the most resilient evidence of the attacker's commands, even if 'bash_history' and common system logs were cleared?
- AContents of '/proc/<PID>/cmdline' for currently running processes.
- BThe auditd logs (e.g., '/var/log/audit/audit.log') with specific rules configured to log command execution.
- CThe 'lastlog' file indicating last login times.
- DThe 'wtmp' and 'btmp' files for user login/logout records.
Show answer & explanationAnswer & explanation
Correct answer: B. The auditd logs (e.g., '/var/log/audit/audit.log') with specific rules configured to log command execution.
Auditd (Linux Auditing System) is designed to provide detailed, tamper-resistant logging of system calls and events, including command execution, file access, and privilege changes. If properly configured with rules to log 'execve' system calls, auditd logs can capture the full command-line arguments of executed programs, even if 'bash_history' is cleared or other logs are deleted, making it a highly resilient source of evidence.
Why the other options are wrong
- A. '/proc/<PID>/cmdline' shows commands for *currently running* processes, but not commands that have already completed or been terminated by the attacker.
- C. The 'lastlog' file shows last login times but does not record specific commands executed by the user.
- D. 'wtmp' and 'btmp' record login/logout events but do not capture the specific commands executed during a session.
Auditd Command Logging
Using the Linux Auditing System (auditd) to log specific system calls, such as 'execve', to capture detailed information about command execution, including full command-line arguments, for forensic purposes.
- Captures system calls, not just shell commands.
- Resilient to 'bash_history' clearing.
- Requires specific rules for 'execve' logging.
Memory trick: Auditd logs all commands, even when history is gone.