Noticing a compromise rather than being told by someone else.
WHAT TO WATCH
Failed and successful authentication attempts New user accounts Changes to system files Unexpected listening ports Unusual outbound connections Unexplained CPU or bandwidth consumption New cron jobs
TOOLS
File integrity monitoring alerts when system files change unexpectedly. Rootkit scanners check for known compromise indicators. Log analysis tools summarise authentication activity. Malware scanners check web content.
Run them on a schedule and have results emailed to an address you read.
THE SIGNS OF COMPROMISE
Outbound spam, which usually surfaces as a blacklisting Sustained CPU use with no explanation, often mining Files you did not create Login sessions from addresses you do not recognise Services restarting or stopping
IF YOU FIND SOMETHING
Do not simply delete the visible symptom. Assume additional access exists. Isolate the server, preserve evidence, and work through the compromise recovery article.
THE MOST COMMON DISCOVERY ROUTE
Someone else tells you: a blacklist notification, an abuse report, or a customer. That is late.