Linux Server Compromise
Your server is behaving strangely and you suspect unauthorised access.
- The problem
- You have reason to believe someone has gained access to your Linux server — unexpected reboots, unfamiliar processes, changed files, or an alert from your provider.
- Initial investigation
- We start with what you can safely observe: running processes, active network connections, recent authentication activity, user accounts, scheduled tasks and startup services. The goal of the first pass is to establish whether there are signs of unauthorised access and how deep they appear to go.
- What to expect
- A clear written summary of what we found, what it likely means, and a recommended recovery path ranked by risk.
- Limitations
- An investigation describes what the available evidence shows. Where logs have been cleared or the system has been heavily modified, some questions may not be answerable.