Windows forensics
Linux forensics
RedLine
Tools in a nutshell
Challenges
cat /var/log/auth.log* |grep -i COMMAND|tail
cat ~/.bash_history
cat ~/.viminfo