LinuxHostThreatHunting
Archive Data with OpenSSL T1560.001
SSH Tunneling T1572
Find Dump Credential Activity T1003.008
Find JNDI Exploitation/Log4J T1190
Find Command Line Execution T1059.004
Find USB Devices T1025
Find Hidden Files T1564.001
User Creation T1136
Find Installed Packages T1072
View User Authentications T1078
Find Autostarts T1547
Find Vim Use T1059.004
Look for Kernel Exploits T1014
Last updated