When a server is hacked and files are copied out of the server, how do admins figure this out?
I'm running an Ubuntu server and if someone was to SSH into my machine and SCP some files to their own, delete the "SCO" command from the bash history then log out, I would have no clue right?