Add sec-google-evidence runbook: account state capture + re-entry check
Numbered field checklist for a consumer Google account, usable in two situations: capturing state before touching anything, and verifying nobody regained access after a password reset. Deliberately terse -- steps only, no rationale prose. This is worked standing up in someone's office, where explanatory text between steps makes the next action harder to find. Covers ground sec-google-compromise.md Phase 0 does not: the Takeout export history, which is the bulk-exfiltration path for a Google account and produces affirmative evidence in an account tier with no audit log; recovering Google's own security mail from Trash and Spam via in:anywhere; pending-but-unconfirmed forwarding addresses; the native filter XML export instead of a screenshot; and attacker-enrolled passkeys. Also records that Gmail keeps only ~10 recent-activity entries, so signing out and back in destroys evidence -- capture in one sitting. Placeholders only. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -73,6 +73,7 @@ run time — never commit filled-in values.
|
||||
| [`od-backup-verify.md`](od-backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) |
|
||||
| [`od-backup-schedule.md`](od-backup-schedule.md) | Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat) |
|
||||
| [`sec-google-compromise.md`](sec-google-compromise.md) | Incident response — suspected compromise of a **consumer** Google/Gmail account (AiTM session theft; no Workspace admin console) |
|
||||
| [`sec-google-evidence.md`](sec-google-evidence.md) | Google/Gmail account — evidence capture before changes + re-entry check after a password reset (numbered, field-usable) |
|
||||
| [`scripts/cg-disable.ps1`](scripts/cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) |
|
||||
| [`scripts/od-cfg-acl.ps1`](scripts/od-cfg-acl.ps1) | Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist) |
|
||||
| [`scripts/od-db-backup.ps1`](scripts/od-db-backup.ps1) | Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup) |
|
||||
|
||||
Reference in New Issue
Block a user