What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
There is no single command that can confirm a Linux server is free of a backdoor. Check for unexpected access and persistence—such as unfamiliar accounts, SSH keys, scheduled jobs, services, or network activity—and compare each finding with an approved baseline. One anomaly is a lead to investigate, not proof of compromise.
Before you investigate, establish what is normal
Record the server’s role, Linux distribution and version, expected services, authorized administrators, and the period you are checking. Use approved configuration records, package or configuration management, and service-owner knowledge as comparison points. A legitimate maintenance change can look suspicious if you do not know when or why it happened.
If compromise is plausible, follow your organization’s incident-response process and consider how to preserve relevant logs and evidence before making changes. The right containment sequence depends on the incident and the server’s operational impact; do not assume that shutting the server down or deleting a suspicious file is always the correct first move. CISA recommends initiating incident response when compromise is detected.
Check scheduled jobs and boot-time persistence
Attackers can use ordinary Linux mechanisms to run code again after a reboot or on a schedule. CISA’s joint guidance, Identifying and Mitigating Living Off the Land Techniques (2025), advises: “In Linux environments, regularly audit cron jobs and systemd timers for unexpected entries.” CISA’s red-team assessment also documented cron and boot-script modifications as persistence techniques.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Review cron jobs and systemd timers
- Inventory scheduled jobs and timers, including the scripts, commands, and unit files they reference.
- Compare each entry with approved configuration and change records. Investigate unfamiliar commands or paths, unexpected owners, recent unexplained changes, and jobs that run with elevated privileges.
- Check critical cron and systemd configuration for unexpected modifications. Follow references to the files or scripts that actually run; an innocuous-looking schedule can call a separate, unfamiliar program.
Locations and commands vary by distribution and system setup. Checking one directory or one type of timer does not cover every possible persistence mechanism.
Review boot-related changes
Compare boot scripts and related startup configuration with the server’s approved state. Focus on unexplained edits and unfamiliar commands, then verify who made the change and when. A recent timestamp alone does not establish malicious activity; correlate it with maintenance records and other evidence.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Check accounts, privileges, SSH keys, and logins
Compare accounts and privileged access
Compare local accounts and their login shells with the expected account inventory. Investigate unfamiliar accounts, unexpected interactive shells, and changes to privileged access. Verify whether each account or privilege change has an authorized owner and purpose before treating it as suspicious.
Verify authorized SSH keys
Review public keys authorized for SSH access against the approved access list and confirm unfamiliar keys with their owners. The OpenSSH sshd manual documents the default user-level authorized-key locations as ~/.ssh/authorized_keys and ~/.ssh/authorized_keys2. The comment attached to a key is not reliable proof of who owns it; check it against access records or with the key owner.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Correlate login activity
Compare successful logins, source addresses, times, and key use with normal administrative activity. In its red-team assessment, CISA described defenders identifying abnormal use of a root SSH private key, including logins to multiple hosts at unusual times and for unusual durations. Treat this as an example of a useful detection signal, not a universal login pattern or a threshold that applies to every server.
Review running activity and network behavior
Look for unexplained processes, services, listening ports, outbound connections, or activity that does not fit the server’s role. Compare what you observe with the known workload and normal network behavior, and establish the owner and purpose of unfamiliar activity.
Rank #4
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
CISA’s red-team assessment documented HTTPS command-and-control traffic in a Linux environment. That example shows why a familiar protocol alone cannot clear a connection—or make it suspicious. Evaluate the destination, timing, process, and host baseline together rather than treating any HTTPS connection as a sign of compromise.
Review logs, and confirm what was retained
Check the authentication, system, kernel, service, and audit records available for the period under investigation. Look for activity that corroborates other findings, such as unexpected logins or privilege changes, and note suspicious gaps or changes in records.
The systemd-journald manual says the journal collects kernel messages, syslog messages, service standard output and error, and audit records. Journal storage may be persistent under /var/log/journal or volatile under /run/log/journal, depending on configuration and whether the persistent directory exists. Confirm how this server was configured before interpreting missing local entries: absence from a log does not show that an event did not occur if the record was never retained or is no longer available.
CISA recommends enabling and centralizing logs and monitoring for unusual activity, including failed logins and privilege escalation. If centralized logs are available, compare them with local records; they may retain information beyond the host’s local retention window. The Linux audit rules manual describes reports that can assist with investigations of login and authentication activity, system anomalies, user activity, and SELinux AVC events.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Judge findings by corroboration, not by a single clue
For each anomaly, record what you found, where it was found, its timestamp, the account or process involved, and the baseline or change record you used for comparison. Then verify its owner and purpose with the responsible service owner or administrator. Independent evidence—such as an unexplained key together with unusual logins—makes a finding more consequential than an unfamiliar entry with no corroboration.
| Question | What to establish |
|---|---|
| Is it authorized? | Whether the account, key, job, service, or activity appears in approved access or change records. |
| Is its owner and purpose known? | Who is responsible for it and why the server needs it. |
| Does it fit the baseline? | Whether its timing, source, behavior, or destination differs from the host’s normal activity. |
| Is there corroboration? | Whether independent logs or other observations support the concern. |
| Could it provide access or persistence? | Whether it enables access to the server or causes code to run again. |
When to escalate
If credible evidence remains after checking approved changes and ownership, follow incident-response procedures and preserve relevant evidence. Do not assume that deleting one unfamiliar key, job, or file has removed an intruder or every way back into the server. CISA recommends initiating incident response when compromise is detected; the investigation and containment steps should be tailored to the incident and operational impact.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

