Live Linux Forensics training coming up @WWHackinFest Deadwood! Let's do some daily Linux Forensics trivia as a lead-up! wildwesthackinfest.com/deadw…
34
50
2
95
I'm going to give @stoney27 credit on this one-- his answer was "date on the device of the root file system". Since there is no standard artifact for install date on Linux systems, the creation date on the root directory (or "/lost+found") is generally used.
2
2
Some people use the creation dates on the host SSH keys (/etc/ssh/ssh_host_*). These are generally a good indicator for when the system was first booted, since they are usually generated automatically at first boot.
Sep 12, 2022 · 12:42 PM UTC
4
