Coolest thing is seeing a Linux box through the lense of a timeline. Overlaying log data on top of filesystem metadata
1
@corey_harrell What's interesting is to try to map cmds in shell history to filesystem artifacts: pkg updates, file copies, archive unpacks.
2
@hal_pomeranz Besides testing, I've been examining a few Linux boxes over past few months. Pretty interesting stuff
1
Replying to @corey_harrell
@corey_harrell Need to blog about this, but file timeline + user logins + cmd history tells an interesting story about system activity.

Oct 30, 2012 · 3:46 PM UTC