Linux/Unix forensic artifacts β log files, configuration, persistence locations, and filesystem indicators β mapped to MITRE ATT&CK techniques and real SigmaHQ detection rules (auditd, builtin syslog, process_creation, file_event, network_connection). Companion to the Windows Registry Explorer.