首先展示关于Linux的关键目录,这是应急响应查看的关键:
data:image/s3,"s3://crabby-images/209ea/209eabd57afb8208204e206d7236f1bc5ace5c30" alt=""
常用命令
top //查看进程资源的占用情况
ps -aux //查看进程 直接写ps aux也可以
netstat -antpl //查看网络连接
ls -alh /proc/pid //查看某个pid对应的可执行程序 pid记得修改
lsof //开放端口的进程
lastb //显示错误的尝试登录信息
last //显示系统用户最近的登录信息
lastlog //所示所有的用户最近的登录信息
grep //查找符合条件的字符串 如netstat -antpl | grep 22
crontab -l 或 cat /etc/crontab //查看相应的定时任务
history 或 cat ~/.bash_history //查看历史命令
data:image/s3,"s3://crabby-images/3b7e5/3b7e5b35cd59017b0e3845dfae73db1fad37daef" alt=""
data:image/s3,"s3://crabby-images/bc114/bc114af23892b35578485543028fc852357d3d0b" alt=""
data:image/s3,"s3://crabby-images/f1a84/f1a84c3ff2ef5d2e47bfb9ced61d078c07c62a09" alt=""
data:image/s3,"s3://crabby-images/78f18/78f184a25aecebb9a2cf55dca3a0e7b9deb56f7d" alt=""
data:image/s3,"s3://crabby-images/d272e/d272ede7934fa95d39c584a4e23757e23ab7fdc4" alt=""
data:image/s3,"s3://crabby-images/83074/83074e5cee16db57dea682c40587f2d700d1008a" alt=""
接下来学习到一些常见的应急工具需要学习使用:
chkrootkit //linux下检查RootKit的脚本
河马Webshell查杀工具
Web日志分析:
data:image/s3,"s3://crabby-images/c77b1/c77b1a0d9e747dc27dd95cc49f8dd0cd5f72feef" alt=""
data:image/s3,"s3://crabby-images/e61c7/e61c7f85deaa44b9483ebeeb58ceecdf45f9e6a2" alt=""
data:image/s3,"s3://crabby-images/d2de0/d2de0f86dfd3a5127921d6be6d2ddd4cee8747a0" alt=""
data:image/s3,"s3://crabby-images/0679c/0679c14c2d94bda57effed9ecd034755961c1f9a" alt=""
data:image/s3,"s3://crabby-images/58de1/58de102366b18435e78659b4f306bf9f5d777941" alt=""
data:image/s3,"s3://crabby-images/2e45d/2e45d4129612a492ce4015a6440da4d66e4260a2" alt=""