From BruCON 2015
This hands-on workshop is a rapid introduction to key artefacts and techniques for investigating compromised Linux systems using Linux tools. Part 1 covers collecting and analyzing disk and memory evidence, showing you where to look and introducing tools every investigator should know. Part 2 is a deep-dive into the Linux EXT file system family, including recovery of deleted data and data from damaged file systems.