Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry
wired.com
wired.com
I'm running an Ubuntu server and if someone was to SSH into my machine and SCP some files to their own, delete the "SCO" command from the bash history then log out, I would have no clue right?
If there is no centralized logging/alerting, it is very hard to detect.
I work on endpoint protection software that goes deeper, using ebpf and a driver for older kernels to track specific syscalls, and look for things like permission escalations, forking and then doing naughty things, for instance. It's more meant for aggregating this data to a backend that then analyzes it and provides a panel that alerts security folks to unusual behavior.