Incident Response
A practical IR runbook for small teams and solo operators. Built around the SANS PICERL phases: Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned.
When to invoke
You are in incident territory if any of these are true:
- A site you operate is defaced, redirecting, or serving content you did not publish
- A webshell or backdoor file has been found
- An admin/root account appeared that nobody on the team created
- A hosting provider
[Description truncada. Veja o README completo no GitHub.]