If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
The system files have been copied by a remote attacker
The system administrator has created an incremental backup
The system has been compromised using a t0rnrootkit
Nothing in particular as these can be operational files
Submit