
GIAC Linux Incident Responder
The GIAC Linux Incident Responder (GLIR) certification validates deep command-line and triage acumen in Linux environments, a differentiator for modern DFIR and threat hunting teams. It proves you can conduct system triage, collect evidence, and analyze intrusions to identify the initial entry point and lateral movement across Linux systems. Ideal for incident responders, threat hunters, and SOC analysts who need to defend Linux infrastructure.
508 practice questions · Updated 2026-07-30
4Domains
13Objectives
99Concepts
508Questions
GLIR Curriculum
Every domain, objective, and concept the GLIR exam measures.
- Linux Boot Process
- Runlevels and Targets
- Systemd Essentials
- File System Hierarchy Standard (FHS)
- File Types and Permissions
- Special Permissions and Attributes
- Hard Links and Symbolic Links
- Mounting and Unmounting File Systems
- Disk Usage and Inodes
- Process Management
- Environment Variables and Shell Configuration
- Package Management
- Logging and Journaling
- System Monitoring and Performance
- User and Group Management
- Networking Fundamentals
- Service and Socket Activation
- System Initialization and Configuration Files
- File System Hierarchy
- File Types
- Inodes and Metadata
- Mount Points and Filesystems
- Permissions and Ownership
- Hard Links and Symbolic Links
- File System Navigation Commands
- File System Forensics Basics
- Linux File System Hierarchy
- File Types and Permissions
- Inodes and Metadata
- Hard Links and Symbolic Links
- Mount Points and File Systems
- File System Analysis Tools
- File System Hierarchy
- File Metadata and Timestamps
- File System Journaling and Logs
- Artifact Locations
- File System Mounting and Partitions
- Deleted File Recovery
- Linux OS Event Log Introduction
- Linux Event Sources
- Syslog and journald
- Auditd framework
- Log file locations and formats
- Timestamps and time zones
- Event correlation
- Timeline analysis techniques
- Common Linux event types
- Log analysis tools
- Identify Application Event Sources
- Parse Application Log Formats
- Correlate Application Events with System Activity
- Analyze Authentication and Authorization Events
- Analyze Application Errors and Anomalies
- Trace User Actions Across Applications
- Detect Malicious Application Behavior
- Utilize Timeline Analysis Tools
- Timeline Analysis Fundamentals
- Acquiring and Normalizing Timestamps
- Building a Super Timeline
- Correlating Events Across Artifacts
- Filtering and Searching Timelines
- Identifying Anomalous Activity
- Using Timeline Analysis Tools
- Interpreting Timeline Results
- Triage Process Overview
- Evidence Identification
- Evidence Preservation
- Initial Assessment
- Prioritization Criteria
- Triage Documentation
- Evidence Collection Fundamentals
- Mounting Filesystems Read-Only
- Using Mount Options for Forensic Integrity
- Handling Encrypted or Special Filesystems
- Documenting Mounting Procedures
- Identify anti-forensics techniques
- Detect data hiding methods
- Detect artifact wiping and destruction
- Detect log tampering and manipulation
- Detect encryption and obfuscation
- Analyze anti-forensics impact on evidence
- Apply countermeasures to anti-forensics
- Memory Acquisition
- Memory Analysis Tools
- Process and Network Artifacts
- Kernel Memory Structures
- Device Profiling Fundamentals
- Device Artifact Analysis
- Correlating Memory and Device Evidence
- Threat Hunting Fundamentals
- Linux Artifact Analysis
- Process and Memory Forensics
- Persistence Mechanisms
- Lateral Movement Detection
- Threat Hunting with Sysmon and Auditd
- YARA Rule Development
- Network Traffic Analysis
- Incident Response Playbooks
- Threat Intelligence Integration
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GLIR, so none is invented.