The top priority is to reinstall Windows. While you could, possibly, look for and find every bit of malware they left on the system how will you ever be sure?
Change all passwords everywhere, if they had more than a momentary access they have a copy of your browser password vault, and the one in Windows itself. It’s also common to hijack the session cookies to sites, allowing for complete bypass of 2FA and the like.
Pray they didn’t install something more resilient on the compromised device that survives a full wipe.
If you have a cryptowallet and had apps related to that on your system then there’s a fair chance you no longer have that crypto anymore.
On your TrueNAS server you can save a config and reinstall, that takes care of the OS itself.
Before doing that I recommend checking:
- Credentials → Users for any unexpected users, specifically non-system default ones.
- Check if any new unexpected apps have appeared, pay extra attention to VPN apps or with remote capability like many apps of the YARR-variaty.
Any VPN or remote access app will need extra scrutiny in their respective configuration, to check if there was any tampering.
- Check System → Advanced Settings under Cron Jobs and Init/Shutdown Scripts for anything unexpected.
- I suppose your login script for your user shell could also be a way in that survives a reinstall, something like the .zshrc or .profile, etc. Check it.
- Are you running VMs? You will need to repeat all of this inside each VM… or just wipe it and start over.
Any of the above can all be used to create “call home”-functionality and things like settings made in the GUI, Apps and VMs all survive a TrueNAS OS reinstall.
Also check your router for any opened/forwarded ports or similar.
Some intruders use compromised hardware to build botnets, some deploy ransomware, some destroy and some steal passwords and other private information for monetary reasons or for leverage. Some do combos of all that.
Depending on who you are, what you work with, who you know and where you live, you may need to take further actions. For what should be obvious reasons, sometimes intruders aren’t after you, they are after something you have access to or someone you know. This can be the Defence-related company you work with, your journalist friend or something similar. In these cases you need to let that party know what happened so that appropriate precautions can be taken.
Hopefully this isn’t that, and all you had was your media server and personal Windows-client. It’s still a violation, but it’s limited in scope.