<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Service_Auditing</id>
	<title>Draft:Introduction to Service Auditing - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Service_Auditing"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Service_Auditing&amp;action=history"/>
	<updated>2026-09-24T04:43:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Service_Auditing&amp;diff=172&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Service_Auditing&amp;diff=172&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:43Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l59&quot;&gt;Line 59:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 59:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Linux Service Auditing|026]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Linux Service Auditing|026]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-92:rev-172:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Service_Auditing&amp;diff=92&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/linux/service_auditing/intro_service_auditing.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Service_Auditing&amp;diff=92&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:23Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/linux/service_auditing/intro_service_auditing.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/linux/service_auditing/intro_service_auditing (source: docs/linux/service_auditing/intro_service_auditing.md) --&amp;gt;&lt;br /&gt;
Author(s): Matthias Lee (ml2322) &amp;lt;br /&amp;gt; Last Updated: 7-17-2025&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
None! This is an introductory article.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== What is a service? ===&lt;br /&gt;
&lt;br /&gt;
A service is a background process managed by the init system, usually systemd. Services not only provice necessary functions for the system, like &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;auditd&amp;lt;/code&amp;gt;, but can also host servers like Apache, Nginx, SSH, and more.&lt;br /&gt;
&lt;br /&gt;
=== Why is this important? ===&lt;br /&gt;
&lt;br /&gt;
Auditing services is important, as unwanted services may be providing remote access or sensitive data to malicious actors. Even things like SSH or Apache should be removed if not necessary, as they increase the attack surface, and can be configured to grant remote access or exfiltrate data. While this is the most common way services are abused, services can also be created to run malicious code and take advantage of running in the background, and potentially with elevated privileges.&lt;br /&gt;
&lt;br /&gt;
=== How to audit services ===&lt;br /&gt;
&lt;br /&gt;
There are several ways to check for malicious services, each with different benefits and drawbacks.&lt;br /&gt;
&lt;br /&gt;
==== nmap ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; (Network Mapper) is a tool to scan a host and see what ports are open. However, you can also run it on yourself (&amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;) and see what ports are open on your own machine. This is by far the easiest way to check if there is an unauthorized port open, indicating an unwanted service is present.&lt;br /&gt;
&lt;br /&gt;
Nmap doesn&amp;#039;t come preinstalled, so you will have to install it with &amp;lt;code&amp;gt;apt&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;user@system:~$ sudo apt install nmap&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Once nmap is installed, you can run it on yourself to check for open ports:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;user@system:~$ nmap localhost&lt;br /&gt;
Starting Nmap 7.80 ( https://nmap.org ) at 2025-07-17 10:23 PDT&lt;br /&gt;
Nmap scan report for localhost (127.0.0.1)&lt;br /&gt;
Host is up (0.00018s latency).&lt;br /&gt;
Not shown: 993 closed ports&lt;br /&gt;
PORT     STATE SERVICE&lt;br /&gt;
22/tcp   open  ssh&lt;br /&gt;
80/tcp   open  http&lt;br /&gt;
139/tcp  open  netbios-ssn&lt;br /&gt;
445/tcp  open  microsoft-ds&lt;br /&gt;
631/tcp  open  ipp&lt;br /&gt;
&lt;br /&gt;
Nmap done: 1 IP address (1 host up) scanned in 0.09 seconds &amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Here, we see that I have ports &amp;lt;code&amp;gt;22&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;80&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;139&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;445&amp;lt;/code&amp;gt;, and &amp;lt;code&amp;gt;631&amp;lt;/code&amp;gt; open. &amp;lt;code&amp;gt;139&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;445&amp;lt;/code&amp;gt; are used for netbios discovery. These are managed by the &amp;lt;code&amp;gt;nmbd&amp;lt;/code&amp;gt; service. This isn&amp;#039;t inherently malicious and is standard on many systems, but you may want to disable it for extra security. However, &amp;lt;code&amp;gt;22&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;80&amp;lt;/code&amp;gt; are used for SSH and HTTP respectively. You can disable services with systemctl, but outright removing the packages is better.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;user@system:~$ sudo systemctl disable ssh&lt;br /&gt;
user@system:~$ sudo systemctl disable apache2&lt;br /&gt;
user@system:~$ sudo systemctl disable nginx&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;user@system:~$ sudo apt purge openssh-server&lt;br /&gt;
user@system:~$ sudo apt purge apache2&lt;br /&gt;
user@system:~$ sudo apt purge nginx-common&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
If you don&amp;#039;t know the specific service running on a port, remove or disable all servers that could be running on that port.&lt;br /&gt;
&lt;br /&gt;
[[Category:Linux Service Auditing|026]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>