Services

Linux Server Incident Response & Recovery

Every engagement starts the same way: understand what actually happened before deciding what to change. Below is what each service covers, what to expect, and where the limits are.

Linux Server Compromise

Your server is behaving strangely and you suspect unauthorised access.

The problem
You have reason to believe someone has gained access to your Linux server — unexpected reboots, unfamiliar processes, changed files, or an alert from your provider.
Initial investigation
We start with what you can safely observe: running processes, active network connections, recent authentication activity, user accounts, scheduled tasks and startup services. The goal of the first pass is to establish whether there are signs of unauthorised access and how deep they appear to go.
What to expect
A clear written summary of what we found, what it likely means, and a recommended recovery path ranked by risk.
Limitations
An investigation describes what the available evidence shows. Where logs have been cleared or the system has been heavily modified, some questions may not be answerable.

Malware & Backdoor Removal

Identify malicious files, persistence mechanisms and unauthorised access paths.

The problem
Something malicious is running or has been installed, and you need to know what it is, how it persists and whether removal is realistic.
Initial investigation
We look for the mechanisms that let malicious code survive a reboot: modified service units, cron and timer entries, shell profile changes, preloaded libraries, altered binaries and unfamiliar kernel modules.
What to expect
An inventory of what we identified, removal of malicious persistence where it is safe to do so, and a direct recommendation on whether cleaning or rebuilding is the safer option.
Limitations
We do not promise that every compromised server can be cleaned. If we cannot establish confidence in the result, we will say so and recommend a rebuild.

Crypto Miner Removal

Unexplained CPU load, throttled workloads, or an abuse notice from your provider.

The problem
Your CPU is pinned at 100%, your bill has jumped, or your hosting provider has sent an abuse notification about mining activity.
Initial investigation
We identify the process and the account running it, trace how it starts, and look for the access path that placed it there. A miner is usually a symptom — the more important question is how it arrived.
What to expect
The mining workload stopped and its persistence removed where possible, plus an assessment of the underlying entry point so it does not simply return.
Limitations
Removing the miner does not by itself prove the server is clean. The initial access path matters more than the payload.

SSH Compromise

Unknown keys, unexpected logins, or credentials you believe are exposed.

The problem
You have found an SSH key you do not recognise, seen logins from unfamiliar addresses, or have reason to believe a credential has leaked.
Initial investigation
We review authorised keys across all accounts, authentication logs, sudo activity, and the SSH daemon configuration for weakened settings.
What to expect
Unauthorised keys and accounts removed, SSH access re-established on terms you control, and a hardened configuration.
Limitations
If an attacker had shell access, credential rotation should extend beyond the server itself to anything that server could reach.

Docker Security Incidents

A container behaving unexpectedly, or a host you think was reached through one.

The problem
A container is doing something you did not configure, an image came from an untrusted source, or you are concerned a container escaped to the host.
Initial investigation
We review running containers and their configuration, exposed sockets and ports, mounted host paths, privileged flags, image provenance, and whether host-level indicators are present.
What to expect
An assessment of whether the incident stayed within the container boundary, and concrete configuration changes to reduce that exposure.
Limitations
A container with a mounted Docker socket or privileged flags should be treated as host-level access until proven otherwise.

Server Hardening

Reduce the attack surface after recovery — or before anything goes wrong.

The problem
You want the server configured so the same class of incident is meaningfully harder to repeat.
Initial investigation
We review SSH policy, firewall rules, exposed services, account and sudo configuration, automatic security updates, and logging so that a future incident leaves usable evidence.
What to expect
A hardened configuration applied with your agreement, plus written notes on what changed and why.
Limitations
Hardening reduces risk. It does not make a server immune, and it cannot retroactively secure a system that is already compromised.

Incident Investigation

Establish what happened, when it started, and what it touched.

The problem
You need to understand the scope of an incident — for your own decision-making, for a customer, or for an insurer.
Initial investigation
We build a timeline from the evidence still available: authentication records, file modification times, service logs, shell history and network artefacts.
What to expect
A written timeline separating what the evidence supports from what remains uncertain.
Limitations
We report what the evidence shows. We will not present assumptions as findings, and anti-forensic activity can leave gaps that cannot be closed.

Suspicious Processes & Network Activity

An unfamiliar process or outbound connections you cannot account for.

The problem
Monitoring flagged unexpected outbound traffic, or you found a process you cannot identify.
Initial investigation
We identify the process, its parent, its owner, the binary behind it and its network behaviour, then determine whether it is legitimate, misconfigured or malicious.
What to expect
A definitive answer where the evidence allows one, and a recommended action for each finding.
Limitations
Some outbound traffic is legitimate but poorly documented. We will tell you when something is unexplained rather than guessing.

Production Server Recovery

Get a business-critical system back to a state you can trust.

The problem
A production system is down or untrusted after an incident, and you need a path back to service that does not simply restore the compromise.
Initial investigation
We weigh restoring from backup, rebuilding from a known-good image, and in-place cleaning against your recovery objectives — including whether your backups pre-date the incident.
What to expect
A recovery plan with the trade-offs stated plainly, and hands-on help carrying it out.
Limitations
Recovery time depends on your backups, your architecture and the extent of the compromise. We do not guarantee a specific recovery time.

Security Audits

A structured review of a server you want checked, with no active incident.

The problem
Nothing is obviously wrong, but you want an informed second opinion before something goes wrong.
Initial investigation
A structured review of exposed services, access control, patch status, configuration, logging and backup posture.
What to expect
A prioritised report separating issues worth acting on now from longer-term improvements.
Limitations
An audit is a point-in-time assessment. It reduces uncertainty; it does not certify a system as secure.

Pricing

Initial assessment available from €149. Emergency response pricing depends on the incident complexity, and complex incidents may require a custom quote. We agree scope and cost with you before any substantial work begins.

Think your server has been compromised?

Tell us what happened. We'll review your request and provide an initial response within 1 hour.