meta data for this page
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| soc:irt:linux:start [2026/06/11 15:35] – titannet | soc:irt:linux:start [2026/06/11 15:53] (current) – titannet | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Linux ====== | ====== Linux ====== | ||
| + | |||
| + | ===== Live and Disk System ===== | ||
| + | |||
| + | |||
| + | ==== Process Information ==== | ||
| <code bash> | <code bash> | ||
| Line 14: | Line 19: | ||
| # open ports, assume folder / | # open ports, assume folder / | ||
| - | cat net/tcp | awk ' | + | cat ./net/tcp | awk ' |
| - | cat /net/udp | awk ' | + | |
| + | # local ip's and ports | ||
| + | awk ' | ||
| + | | ||
| + | hex = a[1] | ||
| + | # Extract bytes (IP is little-endian in the file) | ||
| + | b1 = substr(hex, | ||
| + | b3 = substr(hex, | ||
| + | | ||
| + | " | ||
| + | | ||
| + | }' | ||
| + | |||
| + | |||
| # connected local ip's | # connected local ip's | ||
| cat /net/arp | cat /net/arp | ||
| + | cat /net/route | ||
| + | |||
| + | </ | ||
| + | |||
| + | ==== Logs ==== | ||
| + | |||
| + | <code bash> | ||
| + | / | ||
| + | / | ||
| </ | </ | ||
| + | |||
| + | ==== Triage ==== | ||
| + | |||
| + | * [[soc: | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | ===== Live ===== | ||
| + | |||
| + | |||
| + | ==== Basic System Info ==== | ||
| + | |||
| <code bash> | <code bash> | ||