- uptime - it tell you how long the system has been up. In case of system compromise, it’s a handy command.
- uname - a : OS, Filesystem information
- ifconfig - network configuration, look for IP address and is it in promisc mode or not.
- netstat -at : Shows TCP Connection
- lsof: List open files and gives you open network
- lsof +L : list recently deleted files.
0 Comments
Leave a Reply. |
Join DFIR Global Slack ChannelMac Forensics
|