Linux Command line cheatsheet for compromise detection

Dear readers,

    Whenever host is compromised ,we might be puzzled about where to check and what to audit or which were the things needs to be audited, I have formulated for linux common list of checks where it might be possibly compromised.

Before jumping to the list ,I recommend you to run lynis from github to execute such links.

Lynis use cases :
Audience and use cases
  • Developers: Test that Docker image, or improve the hardening of your deployed web application.
  • System administrators: Run daily health scans to discover new weaknesses.
  • IT auditors: Show colleagues or clients what can be done to improve security.
  • Penetration testers: Discover security weaknesses on systems of your clients, that may eventually result in system compromise.
Download Link : https://cisofy.com/downloads/lynis/

Once you executed the lynis you would be able to get the desired list where we need to be patched.

The following checklist will help you to identify where exactly the loophole is .

Key things before audit :
Processes– Suspicious processes and network activity.
Directories – Suspicious directories holding malicious payloads, data, or tools to allow lateral movement into a network.
Files – Files that are malicious, likely tampered with, or otherwise out of place on a Linux host.
Users – Areas to check for suspicious user activity.
Logs – Log file tampering detection and common areas to check for signs someone has been covering their tracks.

Please download the pdf which will give you more inputs related to it.

Comments

Popular Posts