so, i'm getting harassed by a group online. one of them had uninterrupted physical access to my pc a few years back, and probably put something on there. a worm i think.i found out about BPFdoors, (i only found an ioc on linux), and ran the scanner by rapid7 and got lots of critical alerts of fingerprint matches. i am now on a new network with a new pc, and the test runs negative, which is good. my question is, how do i go at documenting this? I still have the compromised pc and the compromised network (im not using them). But if a backdoor is on there, there has to be other things, how do i find out what? what are other ioc's? keylogger? screen capture? (im also looking at linux forensics courses, and im not very knowledgeable of these stuff) please help out if you can
Work on your question. Be extremely precise about the details and about what you want, and use it as a prompt to the paid version of ChatGPT. It will give you all the steps necessary. You could also mention that you will contact the authorities in your prompt.Nowadays you don't need to be very knowledgeable if you have access to the right tools.
>>1571714Oh, and if I were to play the role of a Infrastructure Systems Engineer, I would check the version of everything installed on this compromised system and diff everything with the official package files.These guys may be able to help you further:https://www.reddit.com/r/sysadmin/