I've been wondering for a while now - how do owners of small webapps monitor intrusion attempts, scan for past successful intrusions, and prepare for the possibility of one?
Sometimes the effects of an intrusion are obvious (a blackhat takes down the site), I'm more worried about the case where someone plants something on the system to monitor and send info back out. How would you detect this?
That said, most intrusion attempts are unsophisticated, analogous to a person walking around a parking lot trying car doors to see if any are unlocked.
Tools I've used (it's been a while so some of these may be dated) include logwatch to check for suspicious log activity, portsentry to watch for suspicious connection activity, and tripwire to spot modified system files.