Linux Collections

AIR supports the following Linux Evidence and Artifacts

Linux Evidence List

#

Category

Evidence (click for details)

Parsed

Investigation Hub

Source Files Collected

1

System

Yes

Yes

No

2

System

Yes

Yes

No

3

System

Yes

Yes

No

4

System

Yes

Yes

No

5

System

Yes

Yes

No

6

System

Yes

Yes

No

7

System

Yes

Yes

No

8

Disk

Yes

Yes

No

9

Disk

Yes

Yes

No

10

Disk

Yes

Yes

No

11

Disk

Yes

Yes

No

12

File System

Yes

Yes

No

13

Processes

Yes

Yes

No

14

Processes

Yes

Yes

No

15

Memory

Yes

Yes

No

16

Memory

Yes

Yes

No

17

Memory

Yes

Yes

No

18

Memory

Yes

Yes

No

19

Browser

Yes

Yes

No

20

Browser

Yes

Yes

No

21

Browser

Yes

Yes

No

22

Browser

Yes

Yes

No

23

Browser

Yes

Yes

No

24

Browser

Yes

Yes

No

25

Browser

Yes

Yes

No

26

Browser

Yes

Yes

No

27

Browser

Yes

Yes

No

28

Browser

Yes

Yes

No

29

Browser

Yes

Yes

No

30

Browser

Yes

Yes

No

31

Browser

Yes

Yes

No

32

Browser

Yes

Yes

No

33

Browser

Yes

Yes

No

34

Browser

Yes

Yes

No

35

Browser

Yes

Yes

No

36

Browser

Yes

Yes

No

37

Browser

Yes

Yes

No

38

Browser

Yes

Yes

No

39

Browser

Yes

Yes

No

40

Browser

Yes

Yes

No

41

Browser

Yes

Yes

No

42

Browser

Yes

Yes

No

43

Browser

Yes

Yes

No

44

Browser

Yes

Yes

No

45

Browser

Yes

Yes

No

46

Browser

Yes

Yes

No

47

Browser

Yes

Yes

No

48

Browser

Yes

Yes

No

49

Browser

Yes

Yes

No

50

Browser

Yes

Yes

No

51

Browser

Yes

Yes

No

52

Browser

Yes

Yes

No

53

Browser

Yes

Yes

No

54

Browser

Yes

Yes

No

55

Browser

Yes

Yes

No

56

Browser

Yes

Yes

No

57

Browser

Yes

Yes

No

58

Browser

Yes

Yes

No

59

Browser

Yes

Yes

No

60

Browser

Yes

Yes

No

61

Browser

Yes

Yes

No

62

Browser

Yes

Yes

No

63

Browser

Yes

Yes

No

64

Browser

Yes

Yes

No

65

Browser

Yes

Yes

No

66

Browser

Yes

Yes

No

67

Browser

Yes

Yes

No

68

Browser

Yes

Yes

No

69

Browser

Yes

Yes

No

70

Browser

Yes

Yes

No

71

Browser

Yes

Yes

No

72

Browser

Yes

Yes

No

73

Browser

Yes

Yes

No

74

Browser

Yes

Yes

No

75

Browser

Yes

Yes

No

76

Browser

Yes

Yes

No

77

Browser

Yes

Yes

No

78

Browser

Yes

Yes

No

79

Browser

Yes

Yes

No

80

Browser

Yes

Yes

No

81

Browser

Yes

Yes

No

82

Browser

Yes

Yes

No

83

Browser

Yes

Yes

No

84

Browser

Yes

Yes

No

85

Browser

Yes

Yes

No

86

Browser

Yes

Yes

No

87

Browser

Yes

Yes

No

88

Browser

Yes

Yes

No

89

Browser

Yes

Yes

No

90

Browser

Yes

Yes

No

91

Browser

Yes

Yes

No

92

Browser

Yes

Yes

No

93

Browser

Yes

Yes

No

94

Browser

Yes

Yes

No

95

Browser

Yes

Yes

No

96

Browser

Yes

Yes

No

97

Browser

Yes

Yes

No

98

Browser

Yes

Yes

No

99

Browser

Yes

Yes

No

100

Browser

Yes

Yes

No

101

Browser

Yes

Yes

No

102

Browser

Yes

Yes

No

103

Users

Yes

Yes

No

104

Users

Yes

Yes

No

105

Users

Yes

Yes

No

106

Users

Yes

Yes

No

107

Users

Yes

Yes

No

108

Users

Yes

Yes

No

109

Users

Yes

Yes

No

110

SSH

Yes

Yes

No

111

SSH

Yes

Yes

No

112

SSH

Yes

Yes

No

113

SSH

Yes

Yes

No

114

Network

Yes

Yes

No

115

Network

Yes

Yes

No

116

Network

Yes

Yes

No

117

Network

Yes

Yes

No

118

Network

Yes

Yes

No

119

Network

Yes

Yes

No

120

Network

Yes

Yes

No

121

Network

Yes

Yes

No

122

Network

Yes

Yes

No

123

Network

Yes

Yes

No

124

Network

Yes

Yes

No

125

Network

Yes

Yes

No

126

Other Evidence

Yes

Yes

No

127

Other Evidence

Yes

Yes

No

128

Other Evidence

Yes

Yes

No

129

Other Evidence

Yes

Yes

No

130

Other Evidence

Yes

Yes

No

131

Other Evidence

Yes

Yes

No

132

Other Evidence

Yes

Yes

No

133

Other Evidence

Yes

Yes

No

134

Other Evidence

Yes

Yes

No

135

Other Evidence

Yes

Yes

No

Linux Artifact List

#

Category

Artifact (click for details)

Parsed

Investigation Hub

Source Files Collected

1

Server

Apache Logs

awaits

awaits

awaits

2

Server

NGINX Logs

awaits

awaits

awaits

3

Server

MongoDB Logs

awaits

awaits

awaits

4

Server

MySQL Logs

awaits

awaits

awaits

5

Server

PostgreSQL Logs

awaits

awaits

awaits

6

Server

SSH Server Logs

awaits

awaits

awaits

7

Server

DHCP Server Logs

awaits

awaits

awaits

8

System

System Logs

awaits

awaits

awaits

9

System

Messages

awaits

awaits

awaits

10

System

Auth Logs

awaits

awaits

awaits

11

System

Secure

awaits

awaits

awaits

12

System

Boot Logs

awaits

awaits

awaits

13

System

Kernel Logs

awaits

awaits

awaits

14

System

Mail Logs

awaits

awaits

awaits

15

Docker

Yes

Yes

No

16

Docker

Yes

Yes

No

17

Docker

Yes

Yes

No

18

Docker

Yes

Yes

No

19

Docker

Yes

Yes

No

20

Docker

Yes

Yes

No

21

Docker

Yes

Yes

No

22

Docker

Yes

Yes

No

23

Docker

Yes

Yes

No

24

Docker

Yes

Yes

No

25

Communication

AnyDesk Logs

awaits

awaits

awaits

Last updated

Was this helpful?