The Mindset
System logs matter to a pentester from two angles:
- Offensive — Logs contain credentials, activity trails, internal hostnames, and evidence of what’s running on the system
- Defensive awareness — Understanding what gets logged tells you what traces you’re leaving behind
Every action you take on a compromised system is potentially being logged somewhere. Know what those sources are.
Log Locations Overview
Reading Logs
Basic Log Reading
Filtering Log Output
Authentication Logs
/var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL/CentOS) is the most valuable log for a pentester. It records every login attempt, sudo command, and session event.
What to look for:
Pentest intel from auth.log:
System Logs
What to look for:
Cron entries in syslog show you exactly what scripts run as root and when —
cross-reference with the actual scripts to find hijack opportunities.
Kernel Logs
What to look for:
Application Logs
Web Server Logs
Hunting credentials in web logs:
Database Logs
Systemd Journal
On modern systems, many logs go to the systemd journal instead of flat files.
Security Logs
Log Analysis for Pentesters
Reconstructing What Happened
Finding Cleartext Credentials in Logs
Next: Linux Security & Hardening — understanding SELinux, AppArmor, TCP Wrappers, and the defenses you’ll encounter on hardened systems.