TERMINAL
REBELS
Play

TERMINAL REBELS / WIKI

Company defense and counterattacks

Companies can respond to attacks. Small businesses defend cautiously; larger companies react faster and may strike back. Tutorial servers are excluded.

What happens during an attack?

A detected attack can trigger an alarm. The company investigates it, starts a Lockdown or isolates a service. Its countermeasures require running protection software and available resources. Distractions can buy you time.

A Lockdown also slows the company's outgoing actions. Stopping its Antivirus ends that protection. The control node in an intrusion therefore remains a useful target.

When a company strikes back

Counterattacks are uncommon and require confirmed detection. The company uses the IP it observed. Changing your IP in time breaks that trail. Clearing a log later does not erase information the company has already observed.

Normally, the response starts after two to five minutes. The company must scan your server, gain access, then upload and install one vSpam or miner. Your running protection software and Sentinel can intercept those steps. The virus remains inactive until installation finishes.

Companies do not steal bank balances or launch Doom attacks this way. High-security companies may choose DDoS instead, with the same possibility of hardware damage as other DDoS attacks.

At most one company counterattack starts against a player within 24 hours, across all companies. Aborted attempts also count. A single attempt ends within 20 minutes. New-player protection, vacation and shutdown restrictions still apply.

Finding the transit nodes

Bastion Circuit and Vesper Signal each operate three transit nodes. Internal headquarters documents contain their addresses. The nodes hold further handover notes and links to the network.

Their DDoS response requires three active carriers. Removing one or taking a node offline prevents that response. The programs return only during scheduled maintenance. Nodes rotate their IP and password after two to three days, and intact company documents are updated accordingly.

Keeping watch over your server

  • Check your server log and security alerts.
  • Use Nmap to find connected machines. Their Firewall strength affects what you can see.
  • Keep suitable protection running and leave enough RAM available.
  • Remove hostile infections with your Antivirus.
  • Changing your IP still has its normal price and cooldown.

Defense works through both desktop controls and console commands. Company attacks can continue while you are logged out.