Posts
August 27, 2026
Invasion Investigation · Part 10 Most hardening advice wouldn’t have saved you Every checklist opens the same way. Update your plugins. Use strong passwords. Install a security plugin. Enable two-factor.…
Read More →
August 27, 2026
Invasion Investigation · Part 9 The files came off in an afternoon. This didn’t. By now the malicious files are gone and the door is closed. And there are still…
Read More →
August 27, 2026
Invasion Investigation · Part 8 The last article was about decisions with a price tag. This one is about the decisions that involve other people — and they work differently,…
Read More →
August 27, 2026
Invasion Investigation · Part 7 These aren’t technical decisions Everything up to here had a method. Look at this, check that, compare, label. What follows doesn’t, and the reason people…
Read More →
August 27, 2026
Invasion Investigation · Part 6 Findings are not conclusions You finished the last post with a pile of facts: files that don’t belong, dates, accounts, settings that changed, things you…
Read More →
August 27, 2026
Invasion Investigation · Part 5 The tempo flips here Part 4 was fast because the scene might have been live. You took the copy, you found out whether anyone was…
Read More →
August 27, 2026
Invasion Investigation · Part 4 Crossing the tape Everything so far has been a record about your site — Google’s index, Google’s reports, your server’s log of visitors. None of…
Read More →
August 27, 2026
Invasion Investigation · Part 3 The last step outside Logs feel like they belong to the server, so this feels like going inside. It isn’t. An access log is a…
Read More →
August 27, 2026
Invasion Investigation · Part 2 Still outside the building Part 1 gave you an approximate number and a look at what the world can see. This gives you the exact…
Read More →
August 27, 2026
Invasion Investigation · Part 1 Start outside the building You know your site was hacked. The files may already be gone, the passwords already changed. What you don’t know yet…
Read More →