logo

Incident Response: Bring Out the Body File

ID: 8d13a20c-4b43-54a3-8d31-7979aec12e87

STIX ID: report--8d13a20c-4b43-54a3-8d31-7979aec12e87

Feed Name: TrustedSec blog

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This post is a practical guide for incident responders on creating Linux body files—file-system listings analogous to the NTFS $MFT—by combining find and stat (and alternatives like xargs/printf) to capture file metadata and timestamps. It includes concrete command examples, notes on platform differences (e.g., macOS), and warnings about performance and mounts when running exhaustive searches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.