Incident Response
- Client
- Live breach, production website
- Role
- Forensics lead
- Year
- 2026
The problem
A production marketing site was found compromised. The scope was unknown: how the attackers got in, how long they had been there, what they could still reach, and whether anything had been taken.
The approach
A full forensic investigation from server logs upward. Six distinct malicious components were identified, including a command-and-control implant that took its instructions from Ethereum smart contracts, a data-theft plugin exfiltrating site secrets on a schedule, a permanent admin backdoor, and a theme-level backdoor enabling passwordless account takeover. Unauthorised access was traced across hundreds of source addresses to reconstruct the timeline.
The outcome
Containment and restoration inside 24 hours of discovery: every malicious component removed, backdoors closed, two-factor enforced on all admin accounts, and login exposure cut by IP restriction. A structured report documented the timeline and indicators of compromise in enough detail to refer onward.
Built with
- Digital forensics
- Server log analysis
- Linux
- WordPress
- MySQL