Investigate a compromised Linux host from a real browser shell
An internet-facing web server logged a flood of SSH failures overnight, then a success. Work the live box from a terminal to confirm the break-in and find how the attacker is keeping access.
A developer's SSH login came from the wrong continent. Trace a stolen-credential intrusion to an injected authorized_keys entry and a SUID root backdoor left for next time.
A PHP file appeared in a folder that should only hold images. Follow it from the upload to a reverse-shell dropper and a systemd service that restarts the implant on every boot.
A finance database was touched at 3am by someone who belonged there. Separate the staging and scp exfil of an insider from normal work, and find the /etc/hosts edit and the hole they cut in the logs.