Unix Security: Diagnostics and Forensics

This document is intended to help Unix/Linux sys-admins with the diagnostic and forensic examination of a machine that has been hacked — or help determine whether a suspect machine has been. Specifically the document describes:

