Linux Endpoint Investigation

Master Linux Endpoint Investigation

Respond decisively when Linux systems are under attack. Learn a proven forensic methodology to investigate, contain, and eradicate threats in Linux, cloud, and container environments, turning complex incidents into structured, defensible investigations.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

Apply a structured forensic methodology to investigate incidents on Linux systems
Collect and analyze volatile and persistent evidence from Linux hosts, cloud instances, and containers
Investigate attacker activity in Docker, Kubernetes, and cloud workloads (AWS, Azure, GCP)
Reconstruct attack timelines using Linux artifacts, logs, memory, and cloud audit trails
Perform effective containment and eradication with minimal disruption to production environments
Document and report Linux-focused investigations clearly for technical and executive stakeholders
FOR402 | Premium tier | 10 modules | 36–40 hours at your own pace | 40 CPE credits | Updated June 2026

Course Syllabus

Every module and every lesson. Open a module to see its lessons.

Download the full syllabus (PDF)

Phase 3: Compromise Scenarios

Phase 0: Course Resources

LX92
Lab Setup

Building a Linux investigation lab on hardware you already own, with the logging Linux ships disabled turned on, and a written ground truth to check your analysis against.

5 lessonsHide lessons
  1. What To Build On
  2. Building the Hosts
  3. Turning On the Logging Linux Ships Disabled
  4. Generating Evidence With a Ground Truth
  5. Verify the Lab, and Know Its Limits
LX93
Walkthroughs

Seven worked Linux investigations, each carried from the referral to a written finding, including the ones that end in a defensible no.

7 lessonsHide lessons
  1. Ten Minutes to a Defensible No
  2. From an Upload Form to Root in Four Minutes
  3. The File That Claimed to Be a Year Old
  4. The Process Nobody Could See
  5. The Container That Did Not Stay In Its Container
  6. The Credential That Was Already Gone
  7. The Sixty Minutes
LX94
Playbooks

Seven Linux threats, each with the examination sequence that establishes what happened, the check that could end it early, and what the handoff must carry.

7 lessonsHide lessons
  1. Suspected SSH Compromise
  2. Web Application Compromise
  3. Cryptomining on a Linux Host
  4. Suspected Concealment or Rootkit
  5. Container or Cloud Workload Compromise
  6. Data Staging on a Server
  7. Ransomware Precursor on Linux
LX95
Playground

Where to practice Linux investigation and use it at work: guided scenarios against Linux evidence, the toolkit, the detection library, and your own lab.

LX96
References & Further Reading

Linux forensic tool documentation, distribution and kernel references, container and cloud provider resources, and incident response frameworks used throughout the Linux Endpoint Investigation course.

Course Completion

Course Exam

Linux Endpoint Investigation end-of-course exam: a simulation-based assessment testing your ability to triage, investigate, and report on a Linux server compromise you have not seen before, using the artifacts and...

1 lessonsHide lessons
  1. Course Completion. Linux Endpoint Investigation

Course overview

The Linux Endpoint Investigation course teaches a practical forensic methodology specifically for Security Engineers and IR Professionals working in Linux, cloud, and container environments. You'll gain hands-on expertise to:

Collect and analyze volatile and persistent evidence from Linux systems
Investigate attacks in cloud workloads (AWS, Azure, GCP) and container platforms (Docker, Kubernetes)
Reconstruct attacker activity using Linux artifacts, logs, and memory
Perform containment, eradication, and recovery with minimal business disruption

By the end, you'll have the skills and structured approach to confidently lead Linux-focused incident response, reducing dwell time and strengthening defenses in modern cloud-native and hybrid environments.

How this course works

Linux investigation is done against a system that logs less than Windows and tells you more if you know where to look. This course runs the same loop for every compromise it works.

1. Establish what this distribution actually records. Log locations, retention and audit configuration vary by distribution and by whoever built the image. Assume nothing that has not been read.

2. Take the volatile evidence first. Processes, connections, open files and loaded modules. On a server nobody wants to reboot, this is the material with an expiry on it.

3. Read the filesystem for what the attacker had to touch. Timestamps, permissions, and the directories a technique cannot avoid. This is where the intrusion leaves marks it did not choose to leave.

4. Follow the account, not the process. Escalation and lateral movement are identity events on Linux as much as anywhere else, and the trail runs through sudo, SSH and the key files.

5. Say what the evidence supports and where it stops. A finding with a gap named is stronger than a finding with the gap hidden, and Linux estates have gaps.

What this course assumes

No minimum experience and no prerequisite course. The filesystem layout, the log stack and the process model are explained where they first matter, and the course does not assume you administer Linux.

What makes it go faster: a Linux machine you can run commands on, and comfort at a shell. Neither is required, and every command in the course is shown with its output.

What this course does not cover: Windows and macOS forensics, network investigation, and Linux system administration. Those are their own courses, and this one stays on the endpoint.

Who this course is for

You're a Security Engineer or Incident Response Professional who needs to investigate and respond to security incidents in Linux, cloud, and container environments. This course is built for you if you want to:

Move from ad-hoc Linux troubleshooting to a professional, repeatable forensic methodology
Master evidence collection and analysis across Linux servers, cloud instances, and modern container platforms
Gain confidence when responding to attacks in cloud-native and hybrid Linux environments
Bridge the gap between traditional Linux forensics and cloud/container-specific techniques

In short: if you're responsible for investigating incidents on Linux systems and want to do it effectively and professionally, this course is for you.

What you'll learn

By the end of this Linux Endpoint Investigation course you will be able to:

Execute a proven end-to-end forensic investigation methodology for Linux environments
Collect and preserve volatile data (memory, processes, network connections) and persistent artifacts
Analyze key Linux evidence sources: logs (syslog, auditd, journalctl), file system artifacts, and memory dumps
Investigate container (Docker/Kubernetes) and cloud workload attacks using cloud logs and runtime security tools
Reconstruct attacker timelines and identify persistence mechanisms in Linux environments
Perform safe containment, eradication, and recovery actions in production Linux and cloud systems

Key course takeaways

Master a repeatable forensic methodology tailored for Linux, cloud, and container incidents
Confidently collect and analyze evidence across Linux hosts, Docker, Kubernetes, and cloud platforms
Reconstruct attacks quickly and accurately to reduce dwell time
Bridge traditional Linux forensics with modern cloud-native investigation techniques
Perform effective containment and eradication with minimal business impact
Become a trusted Linux Incident Responder who can handle complex incidents across hybrid and cloud environments

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches Linux forensic investigation from first principles. Basic Linux command-line familiarity will help you move faster, but is not required. Every artifact, tool, and technique is explained at first use.

What are the device requirements?

A device with a modern browser. For hands-on forensic work, a Linux VM (Ubuntu or RHEL) with standard forensic tools. The course walks you through setup and provides evidence datasets for all scenarios.

How will the course benefit your career?

Linux runs the majority of cloud workloads, containers, and production servers. Most IR cybersecurity professionals are stronger on Windows than Linux, this gap is a career differentiator. This course gives you the Linux forensic methodology, artifact knowledge, and container/cloud investigation skills that make you effective across the full infrastructure stack.

Cross-platform IR capability is increasingly a requirement for senior DFIR and security engineering roles.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy investigation scripts, collection tools, and analysis workflows in your production environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 2.0  |  Last updated: June 2026

June 2026, v2.0: Course rebuilt and renamed to Linux Endpoint Investigation. Ten modules from forensic foundations through compromise scenarios to readiness and reporting.

v1.0: Course launch. Filesystem forensics, log analysis, memory forensics, container and cloud investigation.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
2scenarios
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.