Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

- - - - -

How to check for suspicious activity on your Ubuntu system (Part 1)


  • Please log in to reply
No replies to this topic

#1 Guest_Khiam_*

Guest_Khiam_*

  •  Avatar image
  • Guests
  • OFFLINE
  •  

Posted 20 October 2020 - 08:51 AM

Hello everyone.

 

I will make this topic for who is interested on malware/rootkit analysis, or checking suspicious activities on Linux.

 

We'll obtain superuser acces with one of these commands/parameters :

  • sudo su
  • sudo -i
  • su username

1. Check for suspicious users logged into your machine

w

or

who

2. Check your login sessions

last

3. Check your bash shell (Terminal) history

history

4. Monitor your network traffic

netstat -ls

or

netstat -la

5. Enable Chkrootkit for anti-rootkit protection/scan for threats

apt install chkrootkit

Then scan :

sudo chkrootkit

You can export your result report with :

sudo chkrootkit > results

I hope it helps. Let me know if it works.



BC AdBot (Login to Remove)

 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users