Use this checklist when a Linux host shows unexplained or suspicious behavior and you need to determine what was impacted. The goal is triage and evidence collection: identify active sessions, suspicious processes/connections, persistence, credential exposure, and the likely timeline.
Important: If compromise is plausible, avoid making unnecessary changes before collecting evidence. Commands can alter timestamps, logs, process state, or other evidence. For important systems, consider isolating the host at the network layer and preserving a disk/memory image before remediation.
Check before changing anything. An active intruder may be able to observe commands you run.