Files
rb/README.md
T
igodwin e961a76176 Add sec-google-compromise runbook: consumer Gmail account takeover IR
Incident response for a suspected compromise of a personal @gmail.com
account used for practice business. Written for the consumer-account
reality: no Admin console, no Admin SDK, no audit-log export, no vendor
phone support — every recovery path is Google's automated self-service
flow.

Initial vector assumed to be an AiTM credential phishing kit (blob: URI
rendering a spoofed sign-in page locally, relaying to an attacker
session), with an endpoint infostealer as an unruled-out alternative.
Both steal a post-authentication session cookie, so 2FA does not prevent
it and a password reset alone does not evict it. That drives the whole
ordering: revoke sessions, then OAuth grants, then app passwords, THEN
reset the password, then enroll phishing-resistant 2FA, then sweep Gmail
persistence. Rationale is inline so it doesn't get optimized away
mid-incident.

Phases 0-5 with durations and exit criteria: evidence preservation,
access triage (live-session branch vs. account recovery), containment,
blast radius (registrar first, then financial/vendor/licensing),
endpoint investigation (GravityZone history before scanning, policy and
exclusion audit, Autoruns/Process Explorer, RMM hunt, UniFi logs), and
documentation/handoff. Appendices for decision log and contacts.

Google UI paths verified against Google's help docs at time of writing;
deep links used over menu wording, with an appendix on their volatility.
Kaspersky tooling deliberately excluded (US distribution restrictions).

Makes no compliance determination by design — legal calls route to
counsel/compliance contact. Placeholders only; work the filled-in copy
in the private tier.

New sec- prefix for security/IR runbooks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 15:04:18 -07:00

89 lines
3.9 KiB
Markdown

# rb — runbooks
Generic, reusable IT procedures and scripts for MSP field work. Fetched onto
client workstations during on-site work with short, hand-typeable commands.
> [!WARNING]
> **This repository is PUBLIC-READ.** It must never contain client-identifying
> information — no client names, hostnames, IPs, usernames, credentials, or
> screenshots. Procedures with placeholders **only**. See
> [CONTRIBUTING.md](CONTRIBUTING.md) for the sanitization rule.
> Provided as-is, no warranty. Running any script is at your own risk. Contains
> no client-identifying data by policy.
## Using a runbook
Fetch and read on the target workstation:
```powershell
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file> | more
```
Run an executable runbook script directly (scripts live under `scripts/`):
```powershell
irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/scripts/<file>.ps1 | iex
```
Scripts prompt for anything client-specific via `Read-Host` — nothing to edit
before running. See [`scripts/_template.ps1`](scripts/_template.ps1) for the
convention.
## Layout & naming
- **Runbooks** (`.md`) live flat at the repo root with short, hand-typeable
filenames and light category prefixes.
- **Scripts** (`.ps1`) live under [`scripts/`](scripts/). `_template.ps1`
sorts first and is the convention reference, not a runnable runbook.
- **Meta** (`README.md`, `CONTRIBUTING.md`) stays at the root.
Runbook prefixes:
| Prefix | Domain |
|---|---|
| `win-` | Windows workstation / server |
| `m365-` | Microsoft 365 / Entra |
| `od-` | Open Dental |
| `net-` | Networking |
| `sec-` | Security / incident response |
## Placeholder conventions
Fill these from the private tier (private repo or Bitwarden secure note) at
run time — never commit filled-in values.
| Placeholder | Meaning |
|---|---|
| `<CLIENT>` | Client / site identifier |
| `<SERVER>` | Server hostname |
| `<SHARE>` | Share name |
| `<SHARE_USER>` | Local account used for share access |
| `<USER>` | End-user account |
| `<PASSWORD>` | From password manager — never written to a file |
## Contents
| File | Purpose |
|---|---|
| [`od-smb-cred.md`](od-smb-cred.md) | Open Dental SMB share — stored-credential fix |
| [`od-cfg-persist.md`](od-cfg-persist.md) | Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml) |
| [`od-scan-duplex.md`](od-scan-duplex.md) | Open Dental — duplex ADF scanner captures only one side (TWAIN, Show TWAIN UI branches) |
| [`od-db-backup.md`](od-db-backup.md) | Open Dental — rock-solid cold backup of the database + images (stop/copy/start MySQL/MariaDB) |
| [`od-backup-verify.md`](od-backup-verify.md) | Open Dental — verify a backup by test-restoring into an isolated Hyper-V VM (health checklist) |
| [`od-backup-schedule.md`](od-backup-schedule.md) | Open Dental — schedule the backup + off-site upload and monitor it (dead-man's-switch heartbeat) |
| [`sec-google-compromise.md`](sec-google-compromise.md) | Incident response — suspected compromise of a **consumer** Google/Gmail account (AiTM session theft; no Workspace admin console) |
| [`scripts/cg-disable.ps1`](scripts/cg-disable.ps1) | Disable Credential Guard, then reboot (prompts to confirm) |
| [`scripts/od-cfg-acl.ps1`](scripts/od-cfg-acl.ps1) | Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist) |
| [`scripts/od-db-backup.ps1`](scripts/od-db-backup.ps1) | Cold backup: stop MySQL/MariaDB, copy whole data dir + OpenDentImages, always restart (od-db-backup) |
| [`scripts/od-backup-check.ps1`](scripts/od-backup-check.ps1) | Read-only backup health check: freshness/completeness/size + heartbeat ping (od-backup-schedule) |
## Tiers
- **This repo (public):** generic procedures, placeholders only.
- **Private tier:** filled-in, client-specific versions — private repo or
Bitwarden secure notes. Never here.
This repo also serves as the raw source for Intune remediation scripts and as
documented-procedures evidence for E&O / cyber insurance.