For those of you waiting for EWAT, here is a sneak peek of the program itself. In the video I am simply showing off some simple commands and a module within EWAT. There will be many many more to come within the next… https://t.co/mSlELuYFFQ
If you are investigating a suspicious process, use the strings command to look at /proc/[PID]/environ for the PID. It will often have information such as the SSH IP address that started it. #DFIR