You may have been infected by a botnet and your machine may be doing things without you knowing.
It is possible of course to have some countermeasures (integrity checks, baseline checks) but this is hard work.
You may have been infected by a botnet and your machine may be doing things without you knowing.
It is possible of course to have some countermeasures (integrity checks, baseline checks) but this is hard work.
I haven't used an AV since before Microsoft Defender. I don't even remember. I had no need and considered them a scam, but I'm aware that lots of people are literally helpless against them.
That out of the way, I did catch a few things occasionally, but not even once a rare. Before there were SSDs it was actually really easy to spot when your system behaved differently, simply because the system started acting differently.
I'm sure, or hope, you remember times before the were SSDs. Things took time to load. Windows took time to pop up. One could hear his harddrive doing it's work.
And that's how I spotted a virus I've caught from * microsoft.com, somehow, I don't know. Suddenly the system's timing was complete off. Things took a quarter second more longer to load, irregular hardware accesses, etc.
So I took a look into the task manager (TM) and noted that there was a program that sounded "off". It didn't feel like it belonged there. I had a rough instinct about what's running in the background in a normal system, so that definitely helped.
I even got rid of it manually and because I can type pretty fast I'm going to share the rest of this story. ^_^
It was actually pretty easy. Killing the process in the TM made it restart again automatically, so I've went out seeking the file in question. If my memory serves me right it was pretty easy, using the TM itself.
Sadly there's no great hacking story behind this. Accessing the executable in question wasn't possible while it was running, so I've made a command line ready to rename the file when I've killed it. That was pretty much all it took and after a few attempts I've nailed it.
Deleted it from the harddisk and that's the end of it.
So ... you can notice based on the timing of things happening on your computer. When they feel off, then there's a good chance something's unusual. Same goes for your computer temperature and fans spinning.
When you notice that your fans are spinning up more often, or your internet is suddenly slower, then you should check if there's something wrong with your system.
There are tons* of data points one can use to assess if the system is acting normally, you just have to notice them. :D
Obviously, it's one of those things that is rarely done by the people who use fancy security products.
.. because it’s hard
E.g.: Botnet traffic is often “strange” and easy to recognize
In a home setting, I do not see how manually analyzing the network logs can help (not to mention that most of the traffic is encrypted). You then have integrity checks on files, IOCs you need to check your files against etc.
Basically this means you have to rewrite an EDR from scratch.
Fancy security products are not always a way to check a box in an audit it also means using a product that you otherwise would need to either write, or put together from many pieces.
Just look at wazuh (open source EDR+) and when you go past the intro you ht some hard walls (especially with updating IOCs from external sources).
Security is really hard, but doing it yourself is really, really hardest.
At home, OS and software updates combined with network monitoring should be sufficient for the more common threat models.
One needs to draw a line somewhere.
EDRs are complex and often fail to protect business systems when professionally managed. I do not believe it's worth wasting time on that at home.