Commit Graph

2 Commits

Author SHA1 Message Date
igodwin f2a979f047 Add MIT LICENSE and a per-file as-is notice
The repo is public and files are fetched by raw URL, so a reader who lands
on one runbook never sees the README -- the repo's context does not travel
with the file. Each .md now carries two lines under the title, each .ps1 the
equivalent at the end of its .NOTES block.

Deliberately two lines, not a paragraph. These files are read through `| more`
on a client console mid-incident, and the top of the file is where the
procedure-specific warnings live -- never a live chart, stop the service
before copying, confirm authorization before acting. A legal preamble above
those competes with them and trains people to skip past.

Wording aims at a stranger who found the repo, not at the quality of the
procedure: these double as documented-procedure evidence for E&O, and
language implying the content is unreliable works against that.

MIT rather than no license: the warranty and liability disclaimer is the part
that does the work, and leaving it unlicensed makes reuse ambiguous rather
than disclaimed.

Also fixes 5 stale ops/rb URLs in scripts/*.ps1 that the previous commit
missed -- it only swept the .md files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwcG1jLs1T425QRMxtjxP7
2026-09-02 23:06:44 -07:00
igodwin e961a76176 Add sec-google-compromise runbook: consumer Gmail account takeover IR
Incident response for a suspected compromise of a personal @gmail.com
account used for practice business. Written for the consumer-account
reality: no Admin console, no Admin SDK, no audit-log export, no vendor
phone support — every recovery path is Google's automated self-service
flow.

Initial vector assumed to be an AiTM credential phishing kit (blob: URI
rendering a spoofed sign-in page locally, relaying to an attacker
session), with an endpoint infostealer as an unruled-out alternative.
Both steal a post-authentication session cookie, so 2FA does not prevent
it and a password reset alone does not evict it. That drives the whole
ordering: revoke sessions, then OAuth grants, then app passwords, THEN
reset the password, then enroll phishing-resistant 2FA, then sweep Gmail
persistence. Rationale is inline so it doesn't get optimized away
mid-incident.

Phases 0-5 with durations and exit criteria: evidence preservation,
access triage (live-session branch vs. account recovery), containment,
blast radius (registrar first, then financial/vendor/licensing),
endpoint investigation (GravityZone history before scanning, policy and
exclusion audit, Autoruns/Process Explorer, RMM hunt, UniFi logs), and
documentation/handoff. Appendices for decision log and contacts.

Google UI paths verified against Google's help docs at time of writing;
deep links used over menu wording, with an appendix on their volatility.
Kaspersky tooling deliberately excluded (US distribution restrictions).

Makes no compliance determination by design — legal calls route to
counsel/compliance contact. Placeholders only; work the filled-in copy
in the private tier.

New sec- prefix for security/IR runbooks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 15:04:18 -07:00