Add MIT LICENSE and a per-file as-is notice

The repo is public and files are fetched by raw URL, so a reader who lands
on one runbook never sees the README -- the repo's context does not travel
with the file. Each .md now carries two lines under the title, each .ps1 the
equivalent at the end of its .NOTES block.

Deliberately two lines, not a paragraph. These files are read through `| more`
on a client console mid-incident, and the top of the file is where the
procedure-specific warnings live -- never a live chart, stop the service
before copying, confirm authorization before acting. A legal preamble above
those competes with them and trains people to skip past.

Wording aims at a stranger who found the repo, not at the quality of the
procedure: these double as documented-procedure evidence for E&O, and
language implying the content is unreliable works against that.

MIT rather than no license: the warranty and liability disclaimer is the part
that does the work, and leaving it unlicensed makes reuse ambiguous rather
than disclaimed.

Also fixes 5 stale ops/rb URLs in scripts/*.ps1 that the previous commit
missed -- it only swept the .md files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwcG1jLs1T425QRMxtjxP7
This commit is contained in:
2026-09-02 23:06:44 -07:00
parent 6589082317
commit f2a979f047
16 changed files with 94 additions and 7 deletions
+3
View File
@@ -1,5 +1,8 @@
# Runbook: Incident response — suspected compromise of a consumer Google (Gmail) account
> For qualified IT professionals, on systems they are authorized to administer.
> Provided as-is, without warranty — verify it fits your environment. See LICENSE.
**Applies to:** A **personal `@gmail.com` account** used for practice business at `<CLIENT>`. **Not Google Workspace.** There is no Admin console, no Admin SDK, no GAM, no audit-log export, and no vendor phone support for this account type. Every recovery path is Google's automated self-service flow.
**Goal:** Evict an attacker who holds a stolen **session cookie** (not just a password), preserve evidence while doing it, and hand a clean factual record to the people who make the legal calls.
**Assume:** the mailbox contains PHI, a breach risk assessment may follow, and **this document may become evidence.**