Show HN: CLI forensics tool for tracking USB device artifacts on Linux
github.com
github.com
It would be IMHO advisable to use not the name of the month and somehow fit in the line the year.
Note: Small typo: the past of "shut down" is "shut down" and not "shutted down".
usbrip works with non-modified structure of system log files only, so, unfortunately, it won't be able to parse USB history if you change the format of syslogs (with syslog-ng or rsyslog, for example). That's why the timestamps of "Connected" and "Disconnected" fields don't have the year, by the way. Keep that in mind.If the format of syslogs doesn't change there should be no issues (or should it be read as "the system logs don't have the year"? )
If you don't have the year, it is not a "full date" in the forensic sense of the term, and you simply cannot present such a result in a Court.
A statement like "A Netac USB device was connected on May 26, presumably in the year 2019, exactly at 00:51:54 and soon after disconnected, exactly at 00:52:21" won't be good.
If it is technically not possible to retrieve the year, then the whole stuff has very little relevance on itself.
It would be needed to create a complete timeline of the system under investigation and correlate the month, day, time with activities that have an objective timestamp including the year.
It's a pity, of course, but it can only be a tool to confirm findings that have a "proper" timestamp.
Most probably the log consists of "appended" entries that might mitigate the issue, still it is needed a clear and extended "justification" to the procedure with wich the year is "attributed" to the yearless entry for forensics use.
Reading that on mobile was painful.
linux /etc/rsyslog.conf $ActionFileDefaultTemplate RSYSLOG_FileFormat
openbsd /etc/rc.conf.local syslogd_flags="-Z"
> $ echo 'SUBSYSTEMS=="block", RUN+="/usr/bin/logger --tag=block-device-history -- %E{ACTION} | %E{DEVNAME} | %E{ID_MODEL_ID} | $attr{serial}"' | sudo tee /etc/udev/rules.d/10-block-device-history.rules
Activate the new rule by reloading and retrigging:
> $ udevadm control --reload-rules && sudo udevadm trigger
Then in another terminal run:
> $ sudo journalctl -f
...Insert a USB drive and see information about it printed.
journalctl supports querying with time intervals (eg, journalctl --since "2018-01-10" --until "2019-08-01 23:59").
> SUBSYSTEM=="block",ENV{DEVTYPE}=="disk", RUN+="/usr/bin/logger --tag=block-device-history -- '%E{ACTION} | %E{DEVNAME} | %E{ID_SERIAL}'"
Run
> $ sudo udevadm control --reload-rules && sudo udevadm trigger
> $ sudo journalctl -f SYSLOG_IDENTIFIER=block-device-history
...Then re-inserting a USB device produces output similar to the below:
> Jan 01 12:00:00 hostname block-device-history[12345]: add | /dev/sdY | TOSHIBA_TOSHIBA_USB_DRV_012345678900FF00-0:0
To customize the printed variables, have a look at:
> sudo udevadm info /dev/sdY
for example: https://github.com/snovvcrash/usbrip/blob/master/setup.py?ts...
Honest question, when you hit issues caused by someone else code not using your favorite style of tab vs spaces? Is there an editor/IDE that can't autodetect this and work properly or is there a language that would fail because is hyper sensitive to white space?