{"id":24129,"date":"2021-07-14T08:00:00","date_gmt":"2021-07-14T12:00:00","guid":{"rendered":"https:\/\/michigan.it.umich.edu\/news\/?p=24129"},"modified":"2024-07-08T06:04:30","modified_gmt":"2024-07-08T10:04:30","slug":"checking-systems-for-signs-of-compromise","status":"publish","type":"post","link":"https:\/\/michigan.it.umich.edu\/news\/2021\/07\/14\/checking-systems-for-signs-of-compromise\/","title":{"rendered":"Checking systems for signs of compromise"},"content":{"rendered":"\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"295\" src=\"https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-600x295.png\" alt=\"\" class=\"wp-image-24131\" srcset=\"https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-600x295.png 600w, https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-300x147.png 300w, https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-768x377.png 768w, https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-1536x755.png 1536w, https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1-665x327.png 665w, https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1.png 1600w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n\n<p>Almost all IT professionals at some time in their career have faced the question of whether or not a system they are responsible for has been compromised, and many people face this worry with their own tech as well. ITS Information Assurance (IA) provides help checking UM-owned systems and guidance that can be useful for checking any computer.<\/p>\n\n\n\n<p><strong>If a system contains sensitive U-M data and you suspect it has been compromised<\/strong>, report it immediately to ITS IA at <a href=\"mailto:security@umich.edu\">security@umich.edu<\/a>. If the situation is urgent, please indicate that clearly in your report.<\/p>\n\n\n\n<p><em>Do not install or alter software on your system while waiting for IA to respond! Disconnect the system from any networks by unplugging the ethernet cord or turning off the WiFi.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CrowdStrike Falcon and detection on U-M computers<\/strong><\/h2>\n\n\n\n<p>If the system in question is a UM-owned computer and has CrowdStrike Falcon endpoint protection installed, contact your unit&#8217;s Falcon administrator. Your unit&#8217;s Falcon admin can check for detections or incidents for the system and may also suggest a course of action and contact ITS Information Assurance (IA) for more assistance.<\/p>\n\n\n\n<p>If you have U-M systems that do not yet have Falcon installed, contact your unit Falcon administrator or ITS IA for assistance getting it installed. Not sure who your Falcon admin is? Contact your <a href=\"https:\/\/safecomputing.umich.edu\/it-security-professionals\/security-unit-liaisons\">Security Unit Liaison<\/a> (SUL) to find out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What to look for<\/strong> if you suspect your system has been compromised<\/h2>\n\n\n\n<p>Start by checking system and software logs for the following components to be sure they are running as expected and there are no unexpected configuration changes to them:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Endpoint protection, antivirus, and\/or malware detection software<\/li><li>Network activity<\/li><li>Changes to the operating system or files and directories<\/li><li>Unexpected changes, including to protections like firewalls<\/li><\/ul>\n\n\n\n<p>Be sure to check your endpoint protection, antivirus, and malware detection software logs for any alerts to possible problems after they have run.<\/p>\n\n\n\n<p><a href=\"https:\/\/safecomputing.umich.edu\/it-security-professionals\/tools-templates\/checking-for-compromise\">Checking Systems for Signs of Compromise<\/a> covers these points and more to help you know when you could be facing a potential IT security incident. If you need assistance with checking a system, ITS IA is there to help! Contact IA through the <a href=\"https:\/\/its.umich.edu\/help\">ITS Service Center<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Worried a system was compromised? Understanding what to look for and when to call for help can give you peace of mind and protect university and personal data.<\/p>\n","protected":false},"author":49,"featured_media":24130,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","_umich_oidc_access":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_ef_editorial_meta_date_first-draft-date":"","_ef_editorial_meta_paragraph_assignment":"","_ef_editorial_meta_checkbox_needs-photo":"","_ef_editorial_meta_number_word-count":"","footnotes":""},"categories":[5],"tags":[488,23],"class_list":["post-24129","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-campus-news","tag-cybersecurity","tag-security"],"uagb_featured_image_src":{"full":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920.png",1920,943,false],"thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-400x266.png",400,266,true],"medium":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-300x147.png",300,147,true],"medium_large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-768x377.png",665,326,true],"large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-600x295.png",600,295,true],"1536x1536":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-1536x754.png",1536,754,true],"2048x2048":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920.png",1920,943,false],"excerpt-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-200x140.png",200,140,true],"themonic-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-60x42.png",60,42,true],"ioslider-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-658x300.png",658,300,true],"post-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-665x327.png",665,327,true],"400x250-crop":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2021\/07\/magnifying-2681372_1920-400x250.png",400,250,true]},"uagb_author_info":{"display_name":"Matt Ranville, ITS Privacy Office","author_link":"https:\/\/michigan.it.umich.edu\/news\/author\/mrr\/"},"uagb_comment_info":0,"uagb_excerpt":"Worried a system was compromised? Understanding what to look for and when to call for help can give you peace of mind and protect university and personal data.","_links":{"self":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/24129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/users\/49"}],"replies":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/comments?post=24129"}],"version-history":[{"count":5,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/24129\/revisions"}],"predecessor-version":[{"id":24217,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/24129\/revisions\/24217"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media\/24130"}],"wp:attachment":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media?parent=24129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/categories?post=24129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/tags?post=24129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}