100% agree. Disclaimer I own a data center and have dealt with customer collocated equipment breaches. In addition to the above steps:
-> disable root being able to login inside your sshd_config file. Make sure PermitRootLogin no
-> rename the root account too so if they are using an exploit based on user authentication then perhaps they won't be able to elevate to root.
-> disable password based logins and go to cert based auth. This will shutdown brute force attacks.
-> lower MaxAuthTries in sshd_config to something like 1 or 2 to help slow down attackers.
-> change the port you listen on. A little security through obscurity while not very effective might slow future casual port scanners that are testing a single port. In practice I've seen this really eliminate a lot of reconnaissance or farming type activities.
-> Make sure you're openssl and openssh are at the latest stable releases.
-> If the perp is coming from the same IP, you can use an iptables rule to block the netblock. Again, not perfect but may help slow things down.
-> grab shell history of all the user accounts on the box. Example ~/.bash_history. This is more reconnaissance but may be helpful if they are sloppy - you might see what they were doing on the box.
-> look for any modified files or new ones. Obviously logs will show up in the list but you're looking for things that should not be there.
Example: find / * -mtime -60 -print
where 60 is how many days ago you want to go back.
-> look at chron file to see if any timed delay bombs exist.
-> look at ps -aux output for any running processes that don't make sense
-> look at iptraf for any suspicious traffic to IPs you can't reconcile.
Good luck!