Authentication and accounts
Review successful and failed logins, source IPs, privileged users, sudo indicators, SSH keys, and account context.
Open Investigator · Linux host investigation
For Linux servers, Open Investigator can correlate auth logs, users, processes, network connections, services, cron, systemd, packages, containers, recent files, and shell history into one local case.
Search intent
Practical workflow
Review successful and failed logins, source IPs, privileged users, sudo indicators, SSH keys, and account context.
Inspect command lines, parent processes, listeners, outbound connections, cron, systemd units, timers, services, and startup behavior.
Check package inventory, suspicious tooling, Docker/CRI/Kubernetes local state, recent files, and shell history.
Common searches
The source, usage examples, contribution notes, and issue tracker live in the public Open Investigator repository.