Skip to main content

The Mindset

System logs matter to a pentester from two angles:
  • Offensive — Logs contain credentials, activity trails, internal hostnames, and evidence of what’s running on the system
  • Defensive awareness — Understanding what gets logged tells you what traces you’re leaving behind
Every action you take on a compromised system is potentially being logged somewhere. Know what those sources are.

Log Locations Overview


Reading Logs

Basic Log Reading

Filtering Log Output


Authentication Logs

/var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL/CentOS) is the most valuable log for a pentester. It records every login attempt, sudo command, and session event.
What to look for:
Pentest intel from auth.log:

System Logs

What to look for:
Cron entries in syslog show you exactly what scripts run as root and when — cross-reference with the actual scripts to find hijack opportunities.

Kernel Logs

What to look for:

Application Logs

Web Server Logs

Hunting credentials in web logs:

Database Logs


Systemd Journal

On modern systems, many logs go to the systemd journal instead of flat files.

Security Logs


Log Analysis for Pentesters

Reconstructing What Happened

Finding Cleartext Credentials in Logs

Next: Linux Security & Hardening — understanding SELinux, AppArmor, TCP Wrappers, and the defenses you’ll encounter on hardened systems.