Article 6KGV0 private forensys

private forensys

by
alex0009
from LinuxQuestions.org on (#6KGV0)
I would like to know from the analysis of which directories\files\processes one can draw an unambiguous conclusion: there was a user here. Maybe itis better to use the commands Code:-ctime, -atime, -mtime, and which directories /subdirectories, processes to look at? Maybe there is a manual on this topic? I would appreciate any answers.
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments