Incident Response

Network Security
What to Do When a Device Hits CISA KEVNew!!

An incident-style response guide for routers, firewalls, VPNs, NAS devices, and other systems that appear in CISA's KEV catalog.

Read more
Linux and Homelab
Restore From a Compromised Backup Without Reinfecting ProductionNew!!

A clean-room restore workflow for compromised backups: isolate, separate data from executable state, rotate secrets, validate provenance, and reconnect safely.

Read more
Network Security
Is My Router Affected by This CVE? Model, Firmware, and Exposure ChecksNew!!

Match the exact router model, hardware revision, firmware build, affected feature, and management exposure before acting on a CVE headline. Then route known exploitation or compromise to the appropriate patch, rebuild, rotation, or replacement runbook.

Read more
Linux and Homelab
WordPress Core Under Active Exploitation: Verify the Fix and Rule Out Compromise

Updating WordPress core is only the first step. Use this checklist to verify versions, checksums, users, cron, uploads, logs, WAF data, and rebuild criteria.

Read more