4 ms·
The problem with this strategy is that IP Address/Domains/Hashes that are publicly available for free are typically dated and are rarely useful for catching any
by LoveKebabble 7y ago
The problem with this strategy is that IP Address/Domains/Hashes that are publicly available for free are typically dated and are rarely useful for catching anything other than mass scanning / ssh brute forcing or for doing retroactive searching and analysis.
You're also assuming that the linux server is the initial attack vector.
It is not uncommon for an org to be breached, and for the adversary to pivot to an admin box, and for the adversary to then gain control of a server using the admins legitimate credentials. All the while dropping persistence mechanisms along the way. Secure configurations and setups are always recommended and the above information is great advice. BUT it is also dated advice.
If you're not actively monitoring these servers and the activity on these servers they will eventually be popped. Logging all process/CLI activity is an awesome way to get started on monitoring, but if you're going that route, deploying Wazuh or an EDR tool can only add extra value by allowing you to create alerts off of specific values.