artif: new artifacts to collect utmp and utmpdump results#298
artif: new artifacts to collect utmp and utmpdump results#298tclahr merged 3 commits intotclahr:developfrom
Conversation
New artifacts to collect /var/run/utmp and results of utmpdump command. utmpdump command may help to detect tampered log files.
|
Can we use Also, I was thinking about expanding this artifact to parse rotated (and compressed) utmp/wtmp/btmp files. Compressed ones could be read by zcat (if available on the target system). Parsing those files would be useful in situations like AIX, where there are no parsers for utmp/wtmp/btmp out there, so UAC could use the built-in I will work on it and commit to your PR. |
|
I think you are absolutely right that the However, the timestamp output by the |
|
I would Use both |
Add artifact to collect utmpdump and utmp/wtmp files using last -f. Add artifact to collect btmp files using lastb -f
New artifacts to collect /var/run/utmp and results of utmpdump command. utmpdump command may help to detect tampered log files.