Recognising intrusion.
WHAT SUGGESTS COMPROMISE
Unexplained processes Unexpected listening ports Outbound connections to unfamiliar addresses Unknown scheduled tasks New accounts or keys Sudden load or bandwidth Files modified without explanation
WHAT TO CHECK FIRST
What is listening, and what is connected outward.
WHY OUTBOUND MATTERS
Compromised machines send: spam, attacks, or stolen data.
WHAT TO EXAMINE
Running processes and their command lines Scheduled tasks for every user Authorised keys for every account Recently modified files Authentication logs
HOW TO FIND RECENT CHANGES
find, restricted to a recent modification time.
WHAT TO BE CAREFUL ABOUT
That tools on a compromised machine may be lying.
WHY
Attackers replace commands to hide their presence.
WHAT THAT MEANS
Confirm findings from outside the machine where possible.
WHAT TO DO FIRST ON SUSPICION
Preserve evidence before changing anything.
WHAT TO DO NEXT
Contain: restrict access, stop outbound abuse.
WHAT NOT TO DO
Delete what you found before understanding it Assume cleaning is sufficient
WHY THAT SECOND POINT
You rarely know everything that was changed.
WHAT THE SAFEST RESPONSE IS
Rebuild, restoring data from a known-good point.