Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Guide categories

OPSEC & Threat Modeling

Incident response for ordinary people

A calm first-response plan for a stolen device, compromised account, suspicious login or exposed personal information.

Slow down first

An incident creates pressure. Attackers use urgency to keep you from preserving evidence, checking a message, or asking another person for help. Write down what happened, when you noticed it, which device or account was involved, and what you have already changed.

Contain the immediate path

Use a known-clean device to change the most important account password, revoke active sessions, remove unknown recovery methods, and enable stronger authentication. If a device is stolen, use the platform’s lock or erase controls and contact the carrier when the phone number is involved.

Do not delete every message or wipe the affected device before deciding whether evidence is needed. If money, abuse, stalking or an active workplace compromise is involved, contact the relevant bank, platform, employer, or local support service through a verified channel.

Recover and learn

Restore only from backups you trust. Check for new forwarding rules, browser extensions, OAuth apps, administrator accounts and unfamiliar devices. Then update the threat model: what was exposed, what made the event possible, and which control would reduce the chance or impact next time?

Sources

  1. Computer Security Incident Handling Guide National Institute of Standards and Technology standard Accessed
  2. Account security guidance Federal Trade Commission regulator Accessed