Introduction to Forensics and Incident Response (soc L1)


ı tried all but I cant find the answer
stat /etc/sudoers
sudo cat /var/log/auth.log

hint: cat /var/log/auth.log | grep ‘root’

1 Like

I am stuck on question 4, I have been unable to solve it for hours. Is there anyone who can help?

1 Like

You have to find the SUID files. Check the Security and Permissions model. The file’s path is the answer.

2 Likes