NorthLedger has identified unusual activity on one of its Linux jump servers, nl-jump01.
The server is exposed to regular SSH traffic, making it difficult to separate routine noise from genuine malicious activity. You have been provided with authentication, system, audit and shell history logs.
Your task is to identify the point of compromise and reconstruct what happened.
