Pick an hour, six, a day, a week, a month. Everything for that window is gathered first — the auth log, the sessions, sudo, service and package changes, cron, Fail2Ban, the firewall log, the files modified since — and only then investigated. Two rules are built into how she reads it: usernames stuffed into a log are noise rather than evidence, and shell history is never trusted.
What comes out is an executive summary, a timeline with a source on every single row — this journal unit, this Lens ledger line, this dpkg log, this firewall tail — and threats ranked. Including a category most tools do not have: UNEXPLAINED. Where the record and the live state disagree and she cannot resolve it from the box, she says so plainly instead of guessing, and tells you what to check.
The investigation below came back clean, and the interesting part is how it got there. A brand-new account created with sudo, revoked and locked inside ninety seconds looks exactly like an intrusion — she matched it to the operator's own actions in the Lens ledger and called it what it was. A broken service at 18:40:31 looks like an attack — the sudo log shows a config push one second earlier, so the cause is self-inflicted. And the brute-force noise that fills the log is reported as contained, with the numbers: hundreds of failed attempts, none reaching the password stage, because password authentication is off.