Emergency server help: get in touch

Server hacked: incident response runbook for Linux and cPanel Pro

An incident response runbook for a hacked Linux or cPanel server: contain it, preserve evidence, find the entry point, decide clean or rebuild, rotate credentials in the right order and tell customers.

Published Updated 10 min read
ProThis is part of srvScripts Pro. See what Pro includes.

The first hour after you discover a compromise decides whether you will know what happened, or only that you cleaned something. Most damage in hosting incidents is done by the responder: a reboot that wipes the running malware, a cleanup scanner that deletes the web shell before anyone reads the access log, a password reset done while the attacker still has a shell and watches it happen. This incident response runbook gives the order we work in: contain, preserve, investigate, decide, rotate, communicate, harden.

Symptoms

  • Your provider forwards abuse reports, or null-routes the IP for outbound attacks.
  • CPU pinned by an unknown process (xmrig, kdevtmpfsi, kinsing, a random 8-letter name) or by php running from /tmp, /dev/shm or /var/tmp.
  • Outbound spam from PHP scripts, new SSH keys or users you did not create, cron entries that pipe curl or wget into sh.
  • Sites redirect to casino or pharma pages, often only for search-engine user agents or mobile visitors.
  • Imunify360, maldet or ClamAV alerts, or ps, ls, netstat giving output that disagrees with /proc.

First 5 minutes

Do not reboot, do not delete anything, do not run automatic cleanup yet. Start a timeline file on your own machine and write down, in UTC, what you saw and when.

srvScripts Pro

The rest of this is for Pro members.

Pro removes ads and adds Pro scripts, runbooks, 50 monitors, the Tools API and a bigger AI quota — and it keeps the free tools free.

See Pro plansSign in

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.