The National White Collar Crime Center (NW3C) was asked to conduct several presentations during the 2023 National Cyber Crime Conference in April 2023 in Norwood, Massachusetts. This entry represents the speaker and presentation as follows:
Presenter: Ali Hadi/Mariam Khader
Title: Linux Forensics Part 2
Description: This workshop is designed to provide DFIR analysts with the most essential knowledgeand abilities to handle computers running a Linux OS with confidence. Topics covered: 1. Understanding Linux FHS, and main system services 2. Search, Identify and Collect important artifacts including from devices, volumes, shells, default scripts, variables, users, groups, processes, cron jobs, and Procfs 3. Learn how to use The Sleuth Kit (TSK) to perform basic file system forensic analysis 4. Perform basic log analysis on different services, system and activity logs
Please check the box next to the following questions if the answer is 'yes'.
Please enter the applicable Event Date if there is an Event associated with this TTA.
When entering an Event Date, the Time is also required.
If the TTA is targeted to a particular audience or location, please complete the questions below.
Milestones are an element, activity, work product, or key task associated with completing the TTA (e.g. kick-off meeting, collect data from stake holders, deliver initial data analysis).
Please complete the fields below, if applicable, to create a milestone for this TTA.
Please respond to the Performance Metrics below. The Performance Metrics questions are based on the TTA Type indicated in the General Information section of the TTA.
Please submit a signed letter of support from your agency’s executive or other senior staff member. The letter can be emailed to or uploaded with this request. The letter should be submitted on official letterhead and include the following information:
- General information regarding the request for TTA services, i.e., the who, what, where, when, and why.
- The organizational and/or community needs specific to the request for TTA services.
- The benefits or anticipated outcomes from the receipt of TTA services.
By submitting this application to BJA NTTAC, I understand that upon approval of this application for TTA, the requestor agrees to keep BJA NTTAC informed of any circumstances that may impact the delivery of the TTA, including changes in the date of the event, event cancellation, or difficulties communicating with the assigned TTA provider.
Please call [site:phone] if you need further assistance completing this application.