
CyberCode Academy
Course 44 - RH Security Specialist | Episode 11: System Tracking and Port Reconnaissance
How do you know whether a Linux server is actually secure?Security professionals need more than preventive controls. They need the ability to monitor system activity, investigate suspicious behavior, audit sensitive resources, and verify what is exposed to the network.In this episode, we move from detailed internal auditing with the Linux Audit System to active network reconnaissance and firewall verification. You will learn how to manage and search audit data, create targeted monitoring rules, generate security reports, scan network services with Nmap, and validate the effectiveness of local firewall controls.The result is a practical security workflow that combines visibility, investigation, reconnaissance, and defensive verification.1. Managing the Linux Audit DaemonWe begin with the Linux Audit Daemon (auditd), which provides a framework for recording security-relevant events generated by the operating system.You will explore how administrators manage the audit service and its log lifecycle, including: Starting and stopping the auditing service. Managing audit log generation. Controlling log growth and rotation. Resuming auditing after maintenance or configuration changes. Understanding the relationship between audit configuration and stored event data. Effective audit management ensures that security records remain useful without allowing audit data to become an uncontrolled storage problem.2. Creating Real-Time Audit Rules with AuditctlAfter understanding the audit service itself, we move to auditctl, the command-line interface used to manage active audit rules.Rather than collecting every possible event, security administrators can define specific resources and activities that deserve additional monitoring.A practical example is monitoring a sensitive SSH configuration file such as:/etc/ssh/sshd_configA file watch can provide visibility when the configuration is accessed or modified, helping administrators identify unexpected changes to a critical remote-access component.This introduces an important auditing principle:Monitor the resources whose modification could materially affect system security.3. Searching Audit Data with AusearchGenerating audit records is only the beginning. Large audit logs are valuable only when administrators can efficiently search and interpret them.This is where ausearch becomes important.You will learn how to search audit records for specific categories of activity, including: Failed authentication events. Login-related activity. Account and group modifications. Events associated with particular users. Activity within defined time periods. Events associated with specific audited resources. Instead of manually reading thousands of raw records, targeted searches allow security analysts to quickly isolate events relevant to an investigation.4. Turning Audit Data into Reports with AureportWhile ausearch is useful for targeted investigations, aureport provides a broader reporting perspective.You will explore how aureport can transform detailed audit information into structured, human-readable summaries.These reports can help administrators understand: Authentication activity. Failed login attempts. Executable activity. User behavior. System-level events. Network-related audit information. Patterns that may indicate suspicious activity. This makes audit reporting useful not only to security analysts, but also to administrators who need a high-level overview of system activity.5. Detecting Suspicious Authentication ActivityAuthentication failures are particularly valuable from a security perspective.Repeated failed login attempts against a particular account or across multiple accounts can indicate: Misconfigured applications. Forgotten credentials. Automated authentication attempts. Password-guessing activity. Potential brute-force attacks. By combining targeted searches with audit reports, administrators can move from individual events toward recognizing patterns of suspicious behavior.The objective is not simply to collect failed logins, but to understand their frequency, distribution, and context.6. Introducing Network Reconnaissance with NmapAfter examining activity inside the Linux system, the episode shifts toward understanding what an attacker could discover from the network.We introduce Nmap, one of the most widely used tools for network discovery and security assessment.In an authorized testing environment, Nmap can help identify: Hosts that are reachable. Open network ports. Exposed services. Service configurations. Potentially unnecessary network exposure. Basic characteristics of remote systems. Common services encountered during these assessments may include: SSH. SMTP. VNC. Web services. Other application-specific network services. The key security lesson is straightforward:Every exposed service increases the system's attack surface and should have a clear business or operational justification.7. Understanding Operating System DetectionNetwork reconnaissance can go beyond simply identifying open ports.Nmap can also attempt to determine characteristics of the operating system running on a target.This demonstrates why security administrators should consider their infrastructure from an external perspective.An administrator may know exactly which services are intentionally deployed, but an external assessment can reveal what is actually visible to another system on the network.This creates a valuable defensive process:Configure β Expose β Scan β Compare β Harden8. Verifying Firewall Protection with IptablesNetwork exposure should not be evaluated only once.We demonstrate the importance of firewall verification by comparing network scan results before and after activating iptables firewall rules.The objective is to understand how host-based filtering changes the externally observable attack surface.A properly configured firewall can restrict access to services that do not need to be reachable from a particular network or source.This provides an important distinction:A service running on a server does not necessarily need to be accessible from every network interface or every remote host.Firewall policies therefore become an important layer between running services and potential network attackers.9. Connecting Internal Auditing with External DefenseThe major theme of this episode is the connection between internal visibility and external exposure.Audit tools help answer questions such as: What happened on the system? Which account performed an action? Was a sensitive file modified? Were authentication attempts successful or unsuccessful? Network assessment tools answer a different set of questions: What can an external system see? Which ports are accessible? Which services are exposed? How does firewall configuration affect visibility? Together, these perspectives provide a much more complete security assessment.10. Understanding Vulnerability Assessment with NessusThe episode also introduces Nessus as part of the broader vulnerability-assessment ecosystem.While Nmap focuses heavily on network discovery and service exposure, vulnerability scanners can take the assessment further by evaluating systems for known security weaknesses and configuration issues.This highlights the distinction between:Discovery β Enumeration β Vulnerability Assessment β Remediation β VerificationEach stage provides different information, and combining them creates a more comprehensive approach to infrastructure security.11. Building a Complete Linux Security Verification WorkflowThe concepts covered throughout the episode can be combined into a single security workflow:Monitor β Audit β Search β Report β Discover β Scan β Filter β VerifyInternal Security Visibilityauditd β auditctl β ausearch β aureportExternal Security Assessmentnmap β Service Discovery β Exposure Analysis β Firewall VerificationVulnerability Assessmentnessus β Vulnerability Identification β Remediation β RetestingThis layered approach allows administrators to examine both what is happening inside the system and what the system exposes to the outside world.Key TakeawaysBy the end of this episode, you should understand: The role of auditd in Linux security monitoring. How audit services and their logs are managed. How auditctl creates targeted monitoring rules. How file watches can monitor sensitive configuration resources. How ausearch helps investigate specific audit events. How aureport transforms audit records into useful summaries. How authentication failures can reveal suspicious activity. How Nmap identifies reachable hosts, open ports, and exposed services. The purpose and limitations of operating-system detection. How iptables can reduce network exposure. How Nmap and Nessus serve different roles in security assessment. Why internal auditing and external reconnaissance should be used together. How continuous verification strengthens Linux security. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy






