Investigation
Disks
Convert disk to RAW image
Bash
# From VMWare
qemu-img convert -f vmdk -O raw disk.vmdk disk.img
# From Virtualbox
qemu-img convert -f ova -O raw disk.vmdk disk.img
Unpack LVM
Docker containers
Tracks
Other
Get hostname
Get timezone
Network
List interfaces
List actives connections
List hardcoded dns
Get DNS settings
User/Groups/Rights
List users from passwd
List sudoers
List groups
Persistant
Startup
Cron
List cron tasks
Bash
crontab -l
# Root
less /etc/crontab
# From a user
sudo crontab -u $USERNAME -l
# Hourly
ls -la /etc/cron.hourly/
# Daily
ls -la /etc/cron.daily/
# Weekly
ls -la /etc/cron.weekly/
# Montly
ls -la /etc/cron.montly/
Logs
Auth
Last login
Auth
Bash history
SSH Key