/body-ugid-dist

A Python script that parses the contents of an fls bodyfile (see The Sleuth Kit) and outputs the distribution of u/gids per directory. This has been useful for finding malicious code that an attacker has placed on a Linux host while neglecting to change u/gids to match "normal" values for the given directory.

Primary LanguagePython

Stargazers