Track Focus
Real-world incident response and threat intelligence
WordPress incident analysis, evidence review, attack timeline reconstruction, MITRE ATT&CK mapping, IOC validation, recovery guidance, and nonprofit defender recommendations.
This track is grounded in a real incident affecting a community organization.
Community Sponsor
Karl Kramer
SF Living Wage Coalition
SF Living Wage Coalition runs a WordPress website that was recently hacked. Students will help review available evidence, document what likely happened, and translate lessons learned into practical guidance for nonprofits and small organizations.
Work through a real incident review while building threat intelligence that community defenders can actually use.
Students will analyze a recently hacked WordPress site for SF Living Wage Coalition using available evidence such as logs, user accounts, plugin and theme details, file changes, hosting artifacts, alerts, recovery notes, and public indicators.
The work combines incident response, careful evidence handling, OSINT-backed threat intelligence, MITRE ATT&CK mapping, and plain-language explanations of what the incident means for nonprofits, advocacy groups, and other small organizations running WordPress.
Four connected workstreams: incident evidence review, WordPress security analysis, threat intelligence, and community defender guidance.
Incident Evidence Review
Reconstruct what happened from available artifacts.
Review web server logs, WordPress users, plugin and theme versions, file modification timestamps, suspicious redirects, malware signatures, recovery notes, and hosting or security alerts where available.
WordPress Attack Path Analysis
Identify likely entry points and defensive gaps.
Analyze common WordPress compromise paths such as vulnerable plugins, outdated themes, weak administrator credentials, exposed login surfaces, insecure file permissions, nulled components, or hosting control panel issues.
Threat Intel Correlation
Connect incident clues to public reporting where appropriate.
Validate and enrich indicators such as IPs, domains, file hashes, URLs, user agents, malware names, CVEs, and suspicious infrastructure. Map observed behaviors to MITRE ATT&CK and explain what each technique means for defenders.
Recovery and Hardening Playbook
Turn incident lessons into prevention guidance.
Document containment, cleanup, credential rotation, backup validation, plugin and theme updates, logging improvements, monitoring recommendations, and safe operating practices for nonprofit WordPress sites.
Incident artifacts and defender guidance that are useful to the sponsor and reusable by similar organizations.
Hands-on incident response and threat intelligence methods for evidence review, mapping, hardening, and communication.
Incident Response
Reviewing logs, timelines, system artifacts, recovery notes, and evidence gaps from a real website compromise.
WordPress Security
Assessing plugin, theme, user, configuration, backup, hosting, and monitoring risks for a common nonprofit platform.
Threat Intel
Validating indicators, correlating public reporting, and distinguishing evidence from speculation.
IOC Handling
Validating, enriching, deduplicating, and documenting indicators with confidence and expiration notes.
ATT&CK Mapping
Mapping observed or likely behaviors to MITRE ATT&CK and explaining practical defender implications.
Defender Writing
Turning technical research into recommendations that small organizations can safely act on.
View the full internship overview for program details, dates, and application information.