Detection on the host itself, without a SIEM and without an agent that ships everything out. These guides show how sshd, auditd, canary files and a few lines of shell tell you when someone is inside — and what you may and may not do automatically.
Who can become root on which server, and with which SSH key? On one host that's five commands; on thirty hosts it's the question nobody answers anymore. This script produces one tsv per host with accounts, sudo rules and every authorised public key (with fingerprint and comment), plus the diff check that reports the moment a key or sudo rule is added.
The five RIRs (RIPE, ARIN, APNIC, AFRINIC, LACNIC) publish for free which IP block is allocated to which country. With one 30 MB download and forty lines of shell you see the country of every SSH login, and alert on "this user has never logged in from that country". No MaxMind, no API key, no data leaving the host.
An attacker planting a backdoor in sshd or nginx leaves the process running. The file on disk has been replaced, or the process runs from a deleted file that no longer exists anywhere. Three checks that make this visible without EDR: the hash of /proc/<pid>/exe against a baseline, dpkg -V against the package database, and the (deleted) marker no legitimate process should carry.
How to see in two minutes who is hammering your SSH port, which five sshd settings make 99% of attacks pointless, and how to configure fail2ban correctly on Ubuntu 24.04 (the systemd backend trap). Then: the three attack patterns fail2ban is blind to.
An intruder who's inside looks for keys, passwords and backups within minutes. Plant them — fake — and let auditd report the moment someone touches them. Complete setup with auditd rules, the exclusions for updatedb and your backup tool, and a cron that pushes to your phone. Zero false positives after day one.