performing-linux-log-forensics-investigation
mukul975/Anthropic-Cybersecurity-Skills
This comprehensive guide details techniques for performing forensic investigations on Linux systems. It covers analyzing critical logs—including auth.log, syslog, systemd journal, and auditd—to reconstruct user sessions, trace unauthorized access, detect privilege escalation, and establish detailed event timelines following a suspected security compromise.