Host Integrity Checklist
Use this checklist after security incidents or when compromise is suspected.
Use this checklist after security incidents or when compromise is suspected.
Preconditions
- Owner approval recorded
- Incident folder created under
Incidents/<date-time>-<incident-name>/ - Evidence-first workflow enabled (capture before cleanup)
Baseline Capture
- Record current UTC timestamp and uptime
- Capture logged-in sessions and active SSH sessions
- Capture outbound and inbound network sockets
- Capture process tree and suspicious long-running processes
Persistence Sweep
- Review systemd units and timers for unauthorized entries
- Review cron paths and user crontabs
- Review startup/profile scripts for unexpected modifications
- Check SSH authorized keys against approved principals
Service and Package Integrity
- List enabled services and compare against approved runtime stacks
- Review recent package changes and pending updates
- Validate key security controls (UFW, fail2ban, sshd effective auth)
- Verify no unexpected public service exposure on host ports
Credential and Access Review
- Rotate root password when compromise indicators exist
- Rotate trusted SSH keys when trust boundary is uncertain
- Verify provider remote console remains disabled outside approved break-glass windows
- Validate CI and registry credentials are still scoped and expected
Decision Gate
- Decide recovery posture: continue on cleaned host or rebuild from clean baseline
- Record rationale, residual risk, and owner approval in incident notes
Exit Criteria
- Checklist completed with evidence file references
- Next-step items created for any unresolved risk
- Incident close decision recorded by owner