Linux Incident Response: Collect a First-Response Snapshot
When a Linux host shows signs of compromise, first capture a focused record of its current state. A small, access-controlled collection of host details, logged-in users, processes, sockets, and recent journal entries can help an incident responder decide what to investigate next.
This walkthrough collects command output into a root-only case directory and hashes the resulting files. It is an operational triage aid, not a substitute for a forensic disk image or a documented evidence-handling process. Follow your incident plan, record who collected the data and when, and coordinate containment decisions with the response lead.
Step 1: Create a Restricted Case Directory
Start a Root Shell and Prepare a Case Folder
Evidence HandlingUse an approved administrative session. Set a restrictive umask and create a uniquely named directory under /root so collected output is not readable by ordinary users. Keep this shell open for the remaining steps so CASE_DIR stays defined.
sudo -iumask 077CASE_DIR="/root/ir-$(date -u +%Y%m%dT%H%M%SZ)"mkdir -m 0700 "$CASE_DIR"printf 'Case directory: %s\n' "$CASE_DIR"date -u '+Collection started: %Y-%m-%dT%H:%M:%SZ' | tee "$CASE_DIR/collection-notes.txt"❯ View Expected Console Output
Case directory: /root/ir-20261003T120000ZCollection started: 2026-10-03T12:00:00ZStep 2: Record Host, User, and Process State
Capture Host Details and Active Sessions
System TriageSave a timestamped snapshot of the host and its current activity. These commands query system state; they do not terminate processes or modify network configuration. Review output handling under your organization’s incident policy.
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/host.txt"hostnamectl status >> "$CASE_DIR/host.txt" 2>&1uname -a >> "$CASE_DIR/host.txt" 2>&1uptime >> "$CASE_DIR/host.txt" 2>&1
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/sessions.txt"who -a >> "$CASE_DIR/sessions.txt" 2>&1last -Fai | head -n 100 >> "$CASE_DIR/sessions.txt" 2>&1
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/processes.txt"ps -eo pid,ppid,user,lstart,stat,args --sort=start_time >> "$CASE_DIR/processes.txt"❯ View Expected Console Output
host.txt Hostname, operating system, uptime, and capture timesessions.txt Logged-in users and recent login recordsprocesses.txt Process IDs, owners, start times, and command linesStep 3: Capture Listening Sockets and Recent Logs
Save Network and Journal Evidence
Logs and NetworkRecord listening TCP/UDP sockets with process details and collect a bounded window of recent system journal entries. Adjust the time window to match the suspected incident timeline. Logs can contain usernames, addresses, and other sensitive information; restrict access to the case directory.
date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/listening-sockets.txt"ss -H -tulpn >> "$CASE_DIR/listening-sockets.txt" 2>&1
# Adjust the window to cover the suspected activity.date -u '+Captured: %Y-%m-%dT%H:%M:%SZ' > "$CASE_DIR/recent-journal.txt"journalctl --since '30 minutes ago' --no-pager -o short-iso-precise \ >> "$CASE_DIR/recent-journal.txt" 2>&1
ls -lah "$CASE_DIR"❯ View Expected Console Output
-rw------- 1 root root 164 Oct 3 12:01 collection-notes.txt-rw------- 1 root root 411 Oct 3 12:01 host.txt-rw------- 1 root root 8.2K Oct 3 12:01 listening-sockets.txt-rw------- 1 root root 12K Oct 3 12:01 processes.txt-rw------- 1 root root 31K Oct 3 12:01 recent-journal.txt-rw------- 1 root root 602 Oct 3 12:01 sessions.txtStep 4: Hash and Recheck the Collected Files
Create a SHA-256 Checksum List
Integrity CheckGenerate a checksum list for the captured files and verify it immediately. The temporary manifest is excluded, so rerunning these commands will not hash the old manifest or create a self-referential checksum. If you add or edit evidence files later, document that action in the case notes. A checksum helps detect changes after hashing; it does not prove the host was trustworthy or that the collection is complete.
cd "$CASE_DIR"find . -maxdepth 1 -type f \ ! -name 'SHA256SUMS' ! -name '.SHA256SUMS.tmp' -print0 \ | sort -z \ | xargs -0 -r sha256sum > .SHA256SUMS.tmp &&chmod 0600 .SHA256SUMS.tmp &&mv .SHA256SUMS.tmp SHA256SUMS &&sha256sum --check SHA256SUMS❯ View Expected Console Output
./collection-notes.txt: OK./host.txt: OK./listening-sockets.txt: OK./processes.txt: OK./recent-journal.txt: OK./sessions.txt: OK