Perspective V Docs

Host Integrity Checklist

Use this checklist after security incidents or when compromise is suspected.

Use this checklist after security incidents or when compromise is suspected.

Preconditions

  • Owner approval recorded
  • Incident folder created under Incidents/<date-time>-<incident-name>/
  • Evidence-first workflow enabled (capture before cleanup)

Baseline Capture

  • Record current UTC timestamp and uptime
  • Capture logged-in sessions and active SSH sessions
  • Capture outbound and inbound network sockets
  • Capture process tree and suspicious long-running processes

Persistence Sweep

  • Review systemd units and timers for unauthorized entries
  • Review cron paths and user crontabs
  • Review startup/profile scripts for unexpected modifications
  • Check SSH authorized keys against approved principals

Service and Package Integrity

  • List enabled services and compare against approved runtime stacks
  • Review recent package changes and pending updates
  • Validate key security controls (UFW, fail2ban, sshd effective auth)
  • Verify no unexpected public service exposure on host ports

Credential and Access Review

  • Rotate root password when compromise indicators exist
  • Rotate trusted SSH keys when trust boundary is uncertain
  • Verify provider remote console remains disabled outside approved break-glass windows
  • Validate CI and registry credentials are still scoped and expected

Decision Gate

  • Decide recovery posture: continue on cleaned host or rebuild from clean baseline
  • Record rationale, residual risk, and owner approval in incident notes

Exit Criteria

  • Checklist completed with evidence file references
  • Next-step items created for any unresolved risk
  • Incident close decision recorded by owner

On this page