Open Investigator · Suspicious IP walkthrough

Investigate a suspicious IP on a Linux server with read-only evidence.

When an alert starts with only an IP address, the useful first question is not whether the host is compromised. It is where the IP appeared, what changed nearby, and which evidence is still missing.

Read-only toolsEvidence-backed reportFirst-pass triage
Open Investigator product mark
AI-driven server investigator: incident clues, host evidence, AI follow-up, timeline, and investigation report.

Why it matters

Use this walkthrough when a Linux server alert starts with one suspicious address and the team needs an evidence-backed first pass.

Start from an IP without assuming compromise.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Collect auth, web, process, network, persistence, and recent-file evidence.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Preserve evidence.jsonl, commands.log, report.json, and report.md for review.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.

Read the source, run the CLI, and send collector or report feedback.