CyberDefenders is an independently funded nonprofit project.. Donate
Incident response and threat intelligence research
Summer 2026 Internship — Project Track 6

After the Hack: Incident Response and Threat Intel for Community Defenders

Analyze a real WordPress website compromise, reconstruct what happened, and turn incident evidence plus threat intelligence into practical guidance for community defenders.

Track Focus

Real-world incident response and threat intelligence

WordPress incident analysis, evidence review, attack timeline reconstruction, MITRE ATT&CK mapping, IOC validation, recovery guidance, and nonprofit defender recommendations.

Project Sponsor

This track is grounded in a real incident affecting a community organization.

Community Sponsor

Karl Kramer

SF Living Wage Coalition

SF Living Wage Coalition runs a WordPress website that was recently hacked. Students will help review available evidence, document what likely happened, and translate lessons learned into practical guidance for nonprofits and small organizations.

About This Track

Work through a real incident review while building threat intelligence that community defenders can actually use.

Students will analyze a recently hacked WordPress site for SF Living Wage Coalition using available evidence such as logs, user accounts, plugin and theme details, file changes, hosting artifacts, alerts, recovery notes, and public indicators.

The work combines incident response, careful evidence handling, OSINT-backed threat intelligence, MITRE ATT&CK mapping, and plain-language explanations of what the incident means for nonprofits, advocacy groups, and other small organizations running WordPress.

Project Workstreams

Four connected workstreams: incident evidence review, WordPress security analysis, threat intelligence, and community defender guidance.

Incident Evidence Review

Reconstruct what happened from available artifacts.

Review web server logs, WordPress users, plugin and theme versions, file modification timestamps, suspicious redirects, malware signatures, recovery notes, and hosting or security alerts where available.

WordPress Attack Path Analysis

Identify likely entry points and defensive gaps.

Analyze common WordPress compromise paths such as vulnerable plugins, outdated themes, weak administrator credentials, exposed login surfaces, insecure file permissions, nulled components, or hosting control panel issues.

Threat Intel Correlation

Connect incident clues to public reporting where appropriate.

Validate and enrich indicators such as IPs, domains, file hashes, URLs, user agents, malware names, CVEs, and suspicious infrastructure. Map observed behaviors to MITRE ATT&CK and explain what each technique means for defenders.

Recovery and Hardening Playbook

Turn incident lessons into prevention guidance.

Document containment, cleanup, credential rotation, backup validation, plugin and theme updates, logging improvements, monitoring recommendations, and safe operating practices for nonprofit WordPress sites.

Expected Deliverables

Incident artifacts and defender guidance that are useful to the sponsor and reusable by similar organizations.

  • Incident timeline summarizing discovery, likely compromise window, observed symptoms, response actions, and remaining unknowns.
  • WordPress security assessment covering plugins, themes, users, configuration, backups, logs, and hosting exposure.
  • Root-cause hypothesis with evidence strength, confidence level, and alternative explanations.
  • IOC list with source citations, confidence notes, and safe-use guidance.
  • MITRE ATT&CK mapping of observed or likely techniques with defender-focused explanations.
  • Recovery and hardening checklist for SF Living Wage Coalition.
  • Reusable WordPress incident response playbook for nonprofits and small organizations.
  • Short executive summary suitable for non-technical stakeholders.

Skills You’ll Learn

Hands-on incident response and threat intelligence methods for evidence review, mapping, hardening, and communication.

Incident Response

Reviewing logs, timelines, system artifacts, recovery notes, and evidence gaps from a real website compromise.

WordPress Security

Assessing plugin, theme, user, configuration, backup, hosting, and monitoring risks for a common nonprofit platform.

Threat Intel

Validating indicators, correlating public reporting, and distinguishing evidence from speculation.

IOC Handling

Validating, enriching, deduplicating, and documenting indicators with confidence and expiration notes.

ATT&CK Mapping

Mapping observed or likely behaviors to MITRE ATT&CK and explaining practical defender implications.

Defender Writing

Turning technical research into recommendations that small organizations can safely act on.

Ready to Apply?

View the full internship overview for program details, dates, and application information.