Home Network Accessed Remotely

I believe someone got into my Windows 11 computer remotely, at least that is where I saw some activity. I’m looking for information on tracking down what happened, if they still have access, and what I should do from this point.

My main concern is if they have installed remote access software and if they now have some type of permanent access to my network. On my LAN I three Windows computers and a TrueNAS server running SCALE.

Can anyone recommend what I should look at on my TrueNAS SCALE system to see if it might have been compromised?

Any help would be much appreciated.

The top priority is to reinstall Windows. While you could, possibly, look for and find every bit of malware they left on the system how will you ever be sure?
Change all passwords everywhere, if they had more than a momentary access they have a copy of your browser password vault, and the one in Windows itself. It’s also common to hijack the session cookies to sites, allowing for complete bypass of 2FA and the like.
Pray they didn’t install something more resilient on the compromised device that survives a full wipe.

If you have a cryptowallet and had apps related to that on your system then there’s a fair chance you no longer have that crypto anymore.

On your TrueNAS server you can save a config and reinstall, that takes care of the OS itself.

Before doing that I recommend checking:

  • Credentials → Users for any unexpected users, specifically non-system default ones.
  • Check if any new unexpected apps have appeared, pay extra attention to VPN apps or with remote capability like many apps of the YARR-variaty.
    Any VPN or remote access app will need extra scrutiny in their respective configuration, to check if there was any tampering.
  • Check System → Advanced Settings under Cron Jobs and Init/Shutdown Scripts for anything unexpected.
  • I suppose your login script for your user shell could also be a way in that survives a reinstall, something like the .zshrc or .profile, etc. Check it.
  • Are you running VMs? You will need to repeat all of this inside each VM… or just wipe it and start over.

Any of the above can all be used to create “call home”-functionality and things like settings made in the GUI, Apps and VMs all survive a TrueNAS OS reinstall.

Also check your router for any opened/forwarded ports or similar.

Some intruders use compromised hardware to build botnets, some deploy ransomware, some destroy and some steal passwords and other private information for monetary reasons or for leverage. Some do combos of all that.

Depending on who you are, what you work with, who you know and where you live, you may need to take further actions. For what should be obvious reasons, sometimes intruders aren’t after you, they are after something you have access to or someone you know. This can be the Defence-related company you work with, your journalist friend or something similar. In these cases you need to let that party know what happened so that appropriate precautions can be taken.

Hopefully this isn’t that, and all you had was your media server and personal Windows-client. It’s still a violation, but it’s limited in scope.

On your scale machine, I suggest you delete every login account and start over with new logins / credentials.

That way, if someone tries to log in with an old login name, you know they got those credentials. It’s a canary of sorts.

I would not enable a user / device access to your NAS until you have verified that the platform they use / are is ‘clear’ of malware.

Would it make sense to just grab a snapshot from a couple weeks ago? I primarily use my server as a media server.

Snapshots do not capture whether your login credentials have been compromised. They also do not protect your NAS settings. If someone installed malware at the TrueNAS Debian OS level, a snapshot wont’t protect you either.

Now there may be other good reasons to snapshot, but my primary concern would be login credentials / key logger threats.