Eight chapters from filesystem and permissions foundations through users and authentication, syslog and journald analysis, persistence mechanisms, live process and network internals, shell tradecraft, container and Docker security, and closing with Linux incident response and hardening. Built for analysts who need to investigate and defend Linux servers and containers, not just Windows endpoints.
No chapters match “”.
The Linux filesystem hierarchy, the permissions model including setuid, the PID/PPID process model, and shell basics.
User account structure, PAM authentication, sudo versus su, common privilege escalation vectors, and privileged group membership.
Logging architecture (syslog versus journald), key log files, reading authentication events, journalctl, and log tampering as a detectable technique.
Cron persistence, systemd service and timer persistence, shell profile files, SSH authorized_keys persistence, and a hunting checklist.
The /proc filesystem, process tree analysis, network visibility with ss and netstat, and open file visibility with lsof.
Reverse shell concepts, bash history manipulation, the Linux living-off-the-land parallel to LOLBAS, and layered detection strategy.
Namespaces and cgroups, Docker architecture and risk, container escape technique categories, Kubernetes security basics, and hardening practices.
Linux live response priorities, an incident response workflow, common Linux incident patterns, and baseline hardening controls.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Parses 18 forensic artifact types, useful for correlating log and persistence artifacts uncovered in Chapters 3 and 4.
Multi-source IOC analysis, useful for pivoting on outbound connections found during process and network internals work in Chapter 5.
Passive DNS and domain history lookups, a direct fit for corroborating outbound reverse-shell infrastructure flagged in Chapter 6.
Bring-your-own-key IOC triage across the same source set as X-VERDIKT, useful for verifying indicators surfaced during a Linux investigation.