Skip to content

Shadow

Evidence: Shadow
Description: Collect shadow content
Category: Applications
Platform: linux
Short Name: shadow
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Linux shadow file contains encrypted password information and account security settings. This data is essential for understanding password policies, detecting password-based attacks, and investigating authentication security incidents.

This collector gathers structured data about shadow.

FieldDescriptionExample
UsernameUsernameExample value
ExpireExpire123
InactiveInactive123
LastChangeLast Change123
MaxMax123
MinMin123
PasswordStatusPassword StatusExample value
WarningWarning123

This collector parses the necessary data from the /etc/shadow file and records data into the shadow table.

This evidence is crucial for forensic investigations as it provides password and authentication information. It helps investigators understand password policies, detect password-based attacks, and investigate authentication security incidents.