Hunt planted indicators of compromise, contain the server, and preserve evidence

short · 60 min · Objective 4.3

Task

Plant a set of simulated indicators of compromise on lin-b -- or better, have a partner plant them -- and then find them with the commands an administrator would use: new accounts, privileged group changes, scheduled jobs, unexpected listeners and recent logons. Contain the server without switching it off, and collect volatile evidence first, with hashes, before anything is cleaned up.

Steps

  1. Plant the indicators on lin-b (or have a partner do it), with the file list above written first.
  2. Hunt: compare /etc/passwd and the sudo and admin group members with the documented baseline, list every user's crontab and /etc/cron.d, run ss -tlnp, and read last and journalctl -u ssh. Record each finding in lab/ioc/findings.csv with header type,detail,how_found.
  3. Before changing anything, capture volatile evidence: ps auxf, ss -tanp, who, and ip neigh into lab/ioc/evidence/, then save sha256sum of every evidence file to lab/ioc/evidence.sha256.
  4. Contain: add a firewall rule on lin-b dropping all traffic except from lin-srv, and save the ruleset to lab/ioc/containment.txt. Do not shut the VM down.
  5. Record in lab/ioc/timeline.csv with header time,event,source what happened and when, then compare your findings with lab/ioc/planted.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

awk -F, 'NR>1 {n++} END {print n" finding(s)"}' lab/ioc/findings.csv
awk -F, 'NR>1 {print $1}' lab/ioc/findings.csv | sort -u
ls lab/ioc/evidence | wc -l
sha256sum -c lab/ioc/evidence.sha256 | grep -c ': OK'
grep -c '192.168.56.10' lab/ioc/containment.txt
awk -F, 'NR>1 {n++} END {print n" timeline event(s)"}' lab/ioc/timeline.csv

All four planted indicators are among the findings, covering account, privilege, scheduled job and listener types. The evidence files verify against their hashes, which shows they have not changed since collection, and containment allows only lin-srv. The VM stayed running: switching it off would have destroyed the process and connection evidence captured in step 3.

Notes

A real incident goes to the security team through the incident response plan at the point you first suspect it, before hunting. This lab lets you practise the hunting and preservation that team will ask for; it does not replace calling them.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.