——

Incidents

Evidence-led explanations of real security failures: what happened, what the signals mean, and how teams can recover without destroying the facts.

13 articles · source-backed · editorially reviewed
HighINCIDENTS

· 12 min read · Advanced

Your Microsoft 365 account was breached. What now?

A first-hour response that revokes access, preserves cloud evidence, checks the persistence paths attackers commonly leave behind, and explains the recovery route when you cannot sign in.

Microsoft Graph PowerShellExchange Online PowerShell
Read article
HighINCIDENTS

· 19 min read · Intermediate

You ran the mystery script. Assume it won.

What to do after running software of unknown origin: contain the computer, replace exposed sessions and secrets from a clean device, then decide whether to investigate or rebuild.

Built-in shell toolsPowerShell and Windows Event Logss or PowerShell
Read article
HighINCIDENTS

· 9 min read · Advanced

Ransomware: the first 24 hours

How to slow the damage, preserve options, and make recovery decisions without turning an outage into an evidence-destruction exercise.

findPowerShell SMB cmdletsrestic
Read article
HighINCIDENTS

· 10 min read · Beginner

Someone clicked the phishing link

A proportionate response based on what the user entered, downloaded, approved, or executed—not panic based on the click alone.

grepPython standard library
Read article
HighINCIDENTS

· 9 min read · Advanced

A malicious OAuth app gained access

Investigate consent abuse as an identity incident: permissions, users, tokens, app activity, and the path that convinced someone to approve it.

Microsoft Graph PowerShell
Read article
HighINCIDENTS

· 9 min read · Advanced

A Linux server may be compromised

A careful triage path for suspicious processes, new persistence, unexpected network traffic, and altered accounts on a Linux host.

ps, ss and login toolsjournalctl and finddpkg or rpm
Read article
HighINCIDENTS

· 9 min read · Intermediate

A managed laptop was lost or stolen

Decide quickly using encryption, device state, cached credentials, data sensitivity, remote actions, and identity evidence.

BitLocker PowerShellMicrosoft Graph PowerShellPowerShell and Windows Event Log
Read article
HighINCIDENTS

· 9 min read · Intermediate

A cloud API key was exposed

Rotate the secret, but first understand where it appeared, what it could do, how it was used, and what automation depends on it.

GitShellProvider API client
Read article
HighINCIDENTS

· 9 min read · Advanced

Business email compromise changed the invoice

Coordinate identity response, payment interruption, bank contact, evidence preservation, and business communications when an invoice is manipulated.

Microsoft Graph PowerShellExchange Online PowerShellgrep
Read article