How we detect signs of prior compromise
A central purpose of a Server Security Analysis is answering the question 'has this server already been broken into?'. Alongside finding weaknesses, we hunt for traces of unauthorised access and signs of prior compromise.
Across the services on your machine we look for indicators such as:
- Evidence of access that should not have happened.
- Changes, additions or configurations consistent with an intruder having been present.
- Services or settings that look tampered with rather than merely misconfigured.
This is why the audit spans every provisioned service rather than a single component — attackers move between services, and the signs of a break-in are often scattered. If we find evidence of unauthorised access, the reports identify it and set out what needs to be done in response.

0 comments
Sign in with your TDesk account to comment.