Incident Response: Bring Out the Body File
ID: 8d13a20c-4b43-54a3-8d31-7979aec12e87
STIX ID: report--8d13a20c-4b43-54a3-8d31-7979aec12e87
Feed Name: TrustedSec blog
This post is a practical guide for incident responders on creating Linux body files—file-system listings analogous to the NTFS $MFT—by combining find and stat (and alternatives like xargs/printf) to capture file metadata and timestamps. It includes concrete command examples, notes on platform differences (e.g., macOS), and warnings about performance and mounts when running exhaustive searches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
