Your Microsoft 365 account was breached. What now?
A first-hour response that revokes access, preserves cloud evidence, checks the persistence paths attackers commonly leave behind, and explains the recovery route when you cannot sign in.
Knowledge base / Incidents
Evidence-led explanations of real security failures: what happened, what the signals mean, and how teams can recover without destroying the facts.
A first-hour response that revokes access, preserves cloud evidence, checks the persistence paths attackers commonly leave behind, and explains the recovery route when you cannot sign in.
A practical fibre troubleshooting story: we investigated optical budgets, modules, speed and configuration before remembering that one transmitter must meet the other receiver.
How a helpful OpenClaw assistant turned a WhatsApp contact list into shared authority over Gmail and the host—and how to rebuild it with real trust boundaries.
What to do after running software of unknown origin: contain the computer, replace exposed sessions and secrets from a clean device, then decide whether to investigate or rebuild.
How to slow the damage, preserve options, and make recovery decisions without turning an outage into an evidence-destruction exercise.
A proportionate response based on what the user entered, downloaded, approved, or executed—not panic based on the click alone.
Investigate consent abuse as an identity incident: permissions, users, tokens, app activity, and the path that convinced someone to approve it.
Treat a failed restore as an incident, then separate media integrity, credentials, dependencies, capacity, and runbook failures.
A careful triage path for suspicious processes, new persistence, unexpected network traffic, and altered accounts on a Linux host.
Decide quickly using encryption, device state, cached credentials, data sensitivity, remote actions, and identity evidence.
Rotate the secret, but first understand where it appeared, what it could do, how it was used, and what automation depends on it.
Coordinate identity response, payment interruption, bank contact, evidence preservation, and business communications when an invoice is manipulated.
Recover registrar control, stabilise authoritative DNS, protect email, and determine whether the change enabled credential or certificate abuse.