Bash History Forensics

Here is Hal Pomeranz’ presentation on Bash history forensics from BSidesNOLA 2016.

The .bash_history file tracks a user’s command history and is an important artifact in Linux and Mac forensics. But many investigators don’t understand the rules for how and when they are written and can make wrong investigative assumptions.  Suspects may attempt anti-forensic techniques to corrupt or remove .bash_history content. In other words, “It’s complicated”.


