Respond and rebuild

Recognize a possible compromise

Treat unexpected accounts, keys, listeners, processes, outbound traffic, files, and privilege events as evidence to investigate, not proof to ignore or panic over.

8 minute lesson

~~~

One strange process does not prove compromise. It does justify preserving evidence and checking what changed.

Record time, symptoms, recent deployments, access events, network connections, process trees, and relevant provider activity. Avoid installing many new tools on the suspect host. Compare against known-good configuration and independent logs.

An unknown SSH key may come from automation, a former administrator, or an attacker. Deleting it immediately reduces access but can destroy context before you identify its origin and use.

Collect evidence from independent systems first when practical. Provider audit logs and remote authentication records remain useful even if timestamps or files on the host were changed.

Build a timeline from key metadata, authentication logs, provider events, processes, and network connections. Test the checklist with a harmless planted key and prove it preserves evidence before containment begins.

Lesson completed

Take this course offline

Get every free book and course as PDF and EPUB files.

Get the download library →