Skip to content

Linux Incident Response: Collect a First-Response Snapshot

When a Linux host shows signs of compromise, first capture a focused record of its current state. A small, access-controlled collection of host details, logged-in users, processes, sockets, and recent journal entries can help an incident responder decide what to investigate next.

This walkthrough collects command output into a root-only case directory and hashes the resulting files. It is an operational triage aid, not a substitute for a forensic disk image or a documented evidence-handling process. Follow your incident plan, record who collected the data and when, and coordinate containment decisions with the response lead.


Step 1: Create a Restricted Case Directory

01

Start a Root Shell and Prepare a Case Folder

Evidence Handling

Use an approved administrative session. Set a restrictive umask and create a uniquely named directory under /root so collected output is not readable by ordinary users. Keep this shell open for the remaining steps so CASE_DIR stays defined.

Terminal window
sudo -i
umask 077
CASE_DIR="/root/ir-$(date -u +%Y%m%dT%H%M%SZ)"
mkdir -m 0700 "$CASE_DIR"
printf 'Case directory: %s\n' "$CASE_DIR"
date -u '+Collection started: %Y-%m-%dT%H:%M:%SZ' | tee "$CASE_DIR/collection-notes.txt"
❯ View Expected Console Output
Case directory: /root/ir-20261003T120000Z
Collection started: 2026-10-03T12:00:00Z

Step 2: Record Host, User, and Process State

02

Capture Host Details and Active Sessions

System Triage

Save a timestamped snapshot of the host and its current activity. These commands query system state; they do not terminate processes or modify network configuration. Review output handling under your organization’s incident policy.

Terminal window
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/host.txt"
hostnamectl status >> "$CASE_DIR/host.txt" 2>&1
uname -a >> "$CASE_DIR/host.txt" 2>&1
uptime >> "$CASE_DIR/host.txt" 2>&1
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/sessions.txt"
who -a >> "$CASE_DIR/sessions.txt" 2>&1
last -Fai | head -n 100 >> "$CASE_DIR/sessions.txt" 2>&1
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/processes.txt"
ps -eo pid,ppid,user,lstart,stat,args --sort=start_time >> "$CASE_DIR/processes.txt"
❯ View Expected Console Output
host.txt Hostname, operating system, uptime, and capture time
sessions.txt Logged-in users and recent login records
processes.txt Process IDs, owners, start times, and command lines

Step 3: Capture Listening Sockets and Recent Logs

03

Save Network and Journal Evidence

Logs and Network

Record listening TCP/UDP sockets with process details and collect a bounded window of recent system journal entries. Adjust the time window to match the suspected incident timeline. Logs can contain usernames, addresses, and other sensitive information; restrict access to the case directory.

Terminal window
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/listening-sockets.txt"
ss -H -tulpn >> "$CASE_DIR/listening-sockets.txt" 2>&1
# Adjust the window to cover the suspected activity.
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/recent-journal.txt"
journalctl --since '30 minutes ago' --no-pager -o short-iso-precise \
>> "$CASE_DIR/recent-journal.txt" 2>&1
ls -lah "$CASE_DIR"
❯ View Expected Console Output
-rw------- 1 root root 164 Oct 3 12:01 collection-notes.txt
-rw------- 1 root root 411 Oct 3 12:01 host.txt
-rw------- 1 root root 8.2K Oct 3 12:01 listening-sockets.txt
-rw------- 1 root root 12K Oct 3 12:01 processes.txt
-rw------- 1 root root 31K Oct 3 12:01 recent-journal.txt
-rw------- 1 root root 602 Oct 3 12:01 sessions.txt

Step 4: Hash and Recheck the Collected Files

04

Create a SHA-256 Checksum List

Integrity Check

Generate a checksum list for the captured files and verify it immediately. The temporary manifest is excluded, so rerunning these commands will not hash the old manifest or create a self-referential checksum. If you add or edit evidence files later, document that action in the case notes. A checksum helps detect changes after hashing; it does not prove the host was trustworthy or that the collection is complete.

Terminal window
cd "$CASE_DIR"
find . -maxdepth 1 -type f \
! -name 'SHA256SUMS' ! -name '.SHA256SUMS.tmp' -print0 \
| sort -z \
| xargs -0 -r sha256sum > .SHA256SUMS.tmp &&
chmod 0600 .SHA256SUMS.tmp &&
mv .SHA256SUMS.tmp SHA256SUMS &&
sha256sum --check SHA256SUMS
❯ View Expected Console Output
./collection-notes.txt: OK
./host.txt: OK
./listening-sockets.txt: OK
./processes.txt: OK
./recent-journal.txt: OK
./sessions.txt: OK

Comments