Compromise Containment SOP
First 30 minutes after you suspect a breach. Contain before you investigate.
— Step 1: Snapshot the live state first — disk and DB — for forensics. Don't wipe evidence.
— Step 2: Rotate every secret: all admin passwords, the 8 wp-config salts, DB password, API keys.
— Step 3: Force-logout all sessions by changing the salts — invalidates stolen cookies.
— Step 4: Audit users for unknown admins created in the last 30 days; remove them.
— Step 5: Diff core/plugin files against known-good checksums to locate injected code.
— Step 6: Block the attacker's source IPs and pull the site behind maintenance mode if active exfil.
— Verify: no unauthorized admin accounts remain.
Run this every time.
Lockdown Ledger
@LockdownLedger
Compromise Containment SOP
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.