Add sec-google-compromise runbook: consumer Gmail account takeover IR
Incident response for a suspected compromise of a personal @gmail.com account used for practice business. Written for the consumer-account reality: no Admin console, no Admin SDK, no audit-log export, no vendor phone support — every recovery path is Google's automated self-service flow. Initial vector assumed to be an AiTM credential phishing kit (blob: URI rendering a spoofed sign-in page locally, relaying to an attacker session), with an endpoint infostealer as an unruled-out alternative. Both steal a post-authentication session cookie, so 2FA does not prevent it and a password reset alone does not evict it. That drives the whole ordering: revoke sessions, then OAuth grants, then app passwords, THEN reset the password, then enroll phishing-resistant 2FA, then sweep Gmail persistence. Rationale is inline so it doesn't get optimized away mid-incident. Phases 0-5 with durations and exit criteria: evidence preservation, access triage (live-session branch vs. account recovery), containment, blast radius (registrar first, then financial/vendor/licensing), endpoint investigation (GravityZone history before scanning, policy and exclusion audit, Autoruns/Process Explorer, RMM hunt, UniFi logs), and documentation/handoff. Appendices for decision log and contacts. Google UI paths verified against Google's help docs at time of writing; deep links used over menu wording, with an appendix on their volatility. Kaspersky tooling deliberately excluded (US distribution restrictions). Makes no compliance determination by design — legal calls route to counsel/compliance contact. Placeholders only; work the filled-in copy in the private tier. New sec- prefix for security/IR runbooks. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -46,6 +46,7 @@ Runbook prefixes:
|
||||
| `m365-` | Microsoft 365 / Entra |
|
||||
| `od-` | Open Dental |
|
||||
| `net-` | Networking |
|
||||
| `sec-` | Security / incident response |
|
||||
|
||||
## Placeholder conventions
|
||||
|
||||
@@ -71,6 +72,7 @@ run time — never commit filled-in values.
|
||||
| [`od-db-backup.md`](od-db-backup.md) | Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB) |
|
||||
| [`od-backup-verify.md`](od-backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) |
|
||||
| [`od-backup-schedule.md`](od-backup-schedule.md) | Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat) |
|
||||
| [`sec-google-compromise.md`](sec-google-compromise.md) | Incident response — suspected compromise of a **consumer** Google/Gmail account (AiTM session theft; no Workspace admin console) |
|
||||
| [`scripts/cg-disable.ps1`](scripts/cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) |
|
||||
| [`scripts/od-cfg-acl.ps1`](scripts/od-cfg-acl.ps1) | Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist) |
|
||||
| [`scripts/od-db-backup.ps1`](scripts/od-db-backup.ps1) | Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup) |
|
||||
|
||||
Reference in New Issue
Block a user