5 guides

Security & detection

Detection on the host itself, without a SIEM and without an agent that ships everything out. These guides show how sshd, auditd, canary files and a few lines of shell tell you when someone is inside — and what you may and may not do automatically.

Security & detection
intermediate · 5 min read
2026-09-16

Inventorying sudo rights and authorized_keys across the whole fleet with one script

Who can become root on which server, and with which SSH key? On one host that's five commands; on thirty hosts it's the question nobody answers anymore. This script produces one tsv per host with accounts, sudo rules and every authorised public key (with fingerprint and comment), plus the diff check that reports the moment a key or sudo rule is added.

sudosshauthorized_keysaccess-reviewinventoryiso27001
Security & detection
intermediate · 4 min read
2026-09-16

Who logged in from which country? Geolocating SSH logins without a MaxMind licence

The five RIRs (RIPE, ARIN, APNIC, AFRINIC, LACNIC) publish for free which IP block is allocated to which country. With one 30 MB download and forty lines of shell you see the country of every SSH login, and alert on "this user has never logged in from that country". No MaxMind, no API key, no data leaving the host.

sshgeoiprirripejournalctldetection
Security & detection
intermediate · 4 min read
2026-09-16

Checking whether a running process is still the original binary: /proc/<pid>/exe, sha256 and dpkg -V

An attacker planting a backdoor in sshd or nginx leaves the process running. The file on disk has been replaced, or the process runs from a deleted file that no longer exists anywhere. Three checks that make this visible without EDR: the hash of /proc/<pid>/exe against a baseline, dpkg -V against the package database, and the (deleted) marker no legitimate process should carry.

integrityprocfssha256dpkgdetectionlinux
Security & detection
beginner · 5 min read
2026-09-15

Detecting and blocking SSH brute force: sshd config, fail2ban, and what fail2ban doesn't see

How to see in two minutes who is hammering your SSH port, which five sshd settings make 99% of attacks pointless, and how to configure fail2ban correctly on Ubuntu 24.04 (the systemd backend trap). Then: the three attack patterns fail2ban is blind to.

sshfail2bansshdufwjournalctlubuntu
Security & detection
intermediate · 5 min read
2026-09-15

Honeypot files on a Linux server: four canary files that give an intruder away

An intruder who's inside looks for keys, passwords and backups within minutes. Plant them — fake — and let auditd report the moment someone touches them. Complete setup with auditd rules, the exclusions for updatedb and your backup tool, and a cron that pushes to your phone. Zero false positives after day one.

honeypotcanaryauditddetectionlinuxntfy

← All guides