The Benefits of Enabling Timestamps in Your Command-Line History
ID: d8aca349-35a1-5787-ab42-a7edc988c782
STIX ID: report--d8aca349-35a1-5787-ab42-a7edc988c782
Feed Name: TrustedSec blog
This blog post explains how to configure Bash command history timestamping on Linux (Ubuntu) by setting HISTTIMEFORMAT to include Unix epoch time, human‑readable date/time, and timezone. It demonstrates examples of command history output, file stat comparisons, and raw hex views of .bash_history records, and discusses forensic uses and caveats—such as lost unsaved history on power loss and steps to avoid assigning the same timestamp to prior entries when enabling timestamps on an existing history file.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
