Observing typos within command histories is a good indicator of hands-on-keyboard activity. Serious automation scripts will typically have typos in commands removed, as they do not work and throw errors. Humans naturally make typos from time to time, so typos in command lines are a good indicator that a human typed it rather than automated/worming malware.
typos as an indicator of hands on keyboard
0001-01-01
Recent Posts
Linux Persistence: Modular Software
2025-04-17 DFIR CTF persistence linux persistence apache asterisk
Linux Persistence: Web Shells
2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP
Linux Persistence: Rootkits
2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking
Defanging Linux LKM Rootkits With cleanup_module()
2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit