Linux LEO

Linux LEO

The Law Enforcement and Forensic Examiner's Introduction to Linux
Home
Guide Home changelog.txt Supplemental Files

Contents

  1. 0.1 Legalities
  2. 0.2 Acknowledgements
  3. 0.3 Foreword
  4. 0.4 A word about the GNU in "GNU/Linux"
  5. 0.5 Why Learn Linux?
  6. 0.6 Where are all the GUI Tools?
  7. 0.7 The Hands-on Exercises
  8. 0.8 Conventions Used in this Document
  9. 1. Installation
    1. 1.1. Distributions
    2. 1.2. SLACKWARE and Using this Guide
    3. 1.3. Installation Methods
    4. 1.4. Slackware Installation Notes
    5. 1.5. System Users
    6. 1.6. Desktop Environment
    7. 1.7. The Linux Kernel
    8. 1.8. Kernel and Hardware Interaction
  10. 2. Linux Disks, Partitions, and the File System
    1. 2.1. Disks
    2. 2.2. Device Node Assignment - Looking Closer
    3. 2.3. The File System
    4. 2.4. Mounting External File Systems
  11. 3. Basic Linux Commands
    1. 3.1. Very Basic Navigation
    2. 3.2. File Permissions
    3. 3.3. Pipes and Redirection
    4. 3.4. File Attributes
    5. 3.5. Command Line Math
    6. 3.6. Bash ’globbing’
    7. 3.7. Command Review and Hints
  12. 4. Editing with Vi
    1. 4.1. The Joy that is vi
    2. 4.2. The vimtutor Tutorial
    3. 4.3. vi Command Summary
  13. 5. The Linux Boot Sequence (Simplified)
    1. 5.1. Init vs. Systemd
    2. 5.2. Booting the Kernel
    3. 5.3. System Initialization
    4. 5.4. Runlevel
    5. 5.5. Global Startup Scripts
    6. 5.6. Service Startup Scripts
    7. 5.7. Bash
  14. 6. Linux Network Basics
    1. 6.1. Network Interfaces
    2. 6.2. Network Configuration
    3. 6.3. Finding Yourself on the Network
    4. 6.4. Reviewing Network Connections and Ports
  15. 7. Configuring a Forensic Workstation
    1. 7.1. Securing the Workstation
    2. 7.2. Updating the Operating System
    3. 7.3. Installing and Updating "External" Software
  16. 8. Acquiring Evidence
    1. 8.1. Preparing for Evidence Acquisition
    2. 8.2. Analysis Organization
    3. 8.3. Write Blocking
    4. 8.4. Examining Physical Media Information
    5. 8.5. Hashing Media
    6. 8.6. Collecting a Forensic Image with dd
    7. 8.7. Alternative Imaging Tools
    8. 8.8. Imaging Over the Wire
    9. 8.9. Compression - Local and Over the Wire
    10. 8.10. Preparing a disk for the Suspect Image - Wiping
    11. 8.11. Final Words on Imaging
    12. 8.12. Mounting Evidence
  17. 9. Basic Analysis
    1. 9.1. Anti Virus - Scanning the Evidence with clamav
    2. 9.2. Basic Data Review on the Command Line
    3. 9.3. Making a List of File Types
    4. 9.4. Viewing Files
    5. 9.5. Searching All Areas of the Forensic Image for Text
  18. 10. Advanced Forensics for the Beginner
    1. 10.1. Manipulating and Parsing Files
    2. 10.2. Fun with dd
  19. 11. Advanced Analysis Tools
    1. 11.1. The Layer Approach to Analysis
    2. 11.2. Introduction to the Sleuth Kit
    3. 11.3. Sleuth Kit Exercises
    4. 11.4. bulk_extractor - comprehensive searching
    5. 11.5. Physical Carving
    6. 11.6. Application Analysis
  20. 12. Basic Network Investigation Tools
    1. 12.1. IP Address Lookup
    2. 12.2. Mail Exchange Lookup
    3. 12.3. Whois data
    4. 12.4. MAC Address Lookup
  21. 13. Integrating Linux with Your Work
  22. 14. Conclusion
  23. 15. Linux Support
    1. 15.1. Places to go for Support

© 1998–2026 Barry J. Grundy · LinuxLEO.com