Every command this range teaches, decoded. Pick one on the left, or search above.
FORENSICS · LINUX · difficulty 5 · ~50 min · 20 steps
The logs were destroyed and the toolkit was shredded. The filesystem kept more than either of them intended.
srv-app-02 was rebuilt on Sunday afternoon by someone who is now unavailable. Before it was rebuilt it was imaged, which is the only reason this investigation exists. The journal directory is empty. /var/log is a set of files with the right names and no content in them. The attacker's working directory is gone and at least one binary was shredded rather than deleted. You have 480 gigabytes of E01 and no live system to ask. Everything from here is recovered from the difference between removing a NAME and removing DATA.