Linux Forensics

The investigation of Linux-based systems, focusing on file systems (e.g., EXT), logs (e.g., /var/log), and command history to recover evidence or detect intrusions.