Hunt planted indicators of compromise, contain the server, and preserve evidence
Task
Plant a set of simulated indicators of compromise on lin-b -- or better, have a partner plant them -- and then find them with the commands an administrator would use: new accounts, privileged group changes, scheduled jobs, unexpected listeners and recent logons. Contain the server without switching it off, and collect volatile evidence first, with hashes, before anything is cleaned up.
Steps
- Plant the indicators on lin-b (or have a partner do it), with the file list above written first.
- Hunt: compare
/etc/passwdand the sudo and admin group members with the documented baseline, list every user's crontab and/etc/cron.d, runss -tlnp, and readlastandjournalctl -u ssh. Record each finding inlab/ioc/findings.csvwith headertype,detail,how_found. - Before changing anything, capture volatile evidence:
ps auxf,ss -tanp,who, andip neighintolab/ioc/evidence/, then savesha256sumof every evidence file tolab/ioc/evidence.sha256. - Contain: add a firewall rule on lin-b dropping all traffic except from lin-srv, and save the ruleset to
lab/ioc/containment.txt. Do not shut the VM down. - Record in
lab/ioc/timeline.csvwith headertime,event,sourcewhat happened and when, then compare your findings withlab/ioc/planted.txt.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
awk -F, 'NR>1 {n++} END {print n" finding(s)"}' lab/ioc/findings.csv
awk -F, 'NR>1 {print $1}' lab/ioc/findings.csv | sort -u
ls lab/ioc/evidence | wc -l
sha256sum -c lab/ioc/evidence.sha256 | grep -c ': OK'
grep -c '192.168.56.10' lab/ioc/containment.txt
awk -F, 'NR>1 {n++} END {print n" timeline event(s)"}' lab/ioc/timeline.csv
All four planted indicators are among the findings, covering account, privilege, scheduled job and listener types. The evidence files verify against their hashes, which shows they have not changed since collection, and containment allows only lin-srv. The VM stayed running: switching it off would have destroyed the process and connection evidence captured in step 3.
Notes
A real incident goes to the security team through the incident response plan at the point you first suspect it, before hunting. This lab lets you practise the hunting and preservation that team will ask for; it does not replace calling them.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.