Certified: SANS GIAC GSEC Audio Course
Episode 42 — Linux Incident Basics: Triage and Artifacts
22 Oct 2025
When something goes wrong on a Linux system, knowing where to start determines how much truth you recover. This episode walks you through initial triage—stabilizing the system, identifying scope, and capturing volatile evidence before it disappears. You’ll learn how to inspect running processes, open network connections, recent logins, and loaded modules, all of which can reveal intrusion clues. The episode also emphasizes the importance of minimizing contamination—using write blockers, mounting drives read-only, and documenting every command to preserve evidentiary integrity.Listeners will then explore common artifacts that persist after an event, such as shell histories, cron jobs, temporary directories, and configuration files in /etc. We discuss how these traces help reconstruct attacker timelines and confirm persistence mechanisms. The goal is to make you comfortable with the investigative mindset: observe first, act second, and interpret data in context. By mastering these fundamentals, you’ll not only be ready for GSEC exam scenarios but also equipped to handle real-world incidents methodically and confidently. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
No persons identified in this episode.
This episode hasn't been transcribed yet
Help us prioritize this episode for transcription by upvoting it.
Popular episodes get transcribed faster
Other recent transcribed episodes
Transcribed and ready to explore now
3ª PARTE | 17 DIC 2025 | EL PARTIDAZO DE COPE
01 Jan 1970
El Partidazo de COPE
Buchladen: Tipps für Weihnachten
20 Dec 2025
eat.READ.sleep. Bücher für dich
BOJ alza 25pb decennale sopra 2%, Oracle vola con accordo Tik Tok, 90 mld eurobond per Ucraina | Morning Finance
19 Dec 2025
Black Box - La scatola nera della finanza
365. The BEST advice for managing ADHD in your 20s ft. Chris Wang
19 Dec 2025
The Psychology of your 20s
LVST 19 de diciembre de 2025
19 Dec 2025
La Venganza Será Terrible (oficial)
Cuando la Ciencia Ficción Explicó el Mundo que Hoy Vivimos
19 Dec 2025
El Podcast de Marc Vidal