How to determine if my AWS/EC2 server has been compromised / resolution?
- by ElHaix
I have recently seen an increase in network in/out activity on my server and am trying to determine if my AWS/EC2 instance has been compromised, and if so, how to resolve?
In my security group I have:
Inbound:
80 (HTTP) 0.0.0.0/0
Outbound:
80 (HTTP) 0.0.0.0/0
443 (HTTPS) 0.0.0.0/0
Using TCP-UDP Endpoint Viewer:
I see a lot of w3wp.exe…