Project Brief
SF Living Wage Coalition runs a WordPress website that was recently hacked. This track analyzed the compromise using available evidence — logs, user accounts, plugin and theme details, file changes, hosting artifacts, alerts, and recovery notes — and turned it into practical guidance for community defenders. The work combined incident response, careful evidence handling, OSINT-backed threat intelligence, MITRE ATT&CK mapping, and plain-language explanations of what the incident means for nonprofits and small organizations running WordPress.
Capstone Team
Project Workstreams
Incident Evidence Review
Reviewed web server logs, WordPress users, plugin and theme versions, file modification timestamps, suspicious redirects, malware signatures, and recovery notes to reconstruct what happened.
WordPress Attack Path Analysis
Identified likely entry points and defensive gaps — vulnerable plugins, outdated themes, weak administrator credentials, exposed login surfaces, and insecure file permissions.
Threat Intel Correlation
Validated and enriched indicators (IPs, domains, file hashes, URLs, user agents) and mapped observed behaviors to MITRE ATT&CK, explaining what each technique means for defenders.
Recovery & Hardening Playbook
Documented containment, cleanup, credential rotation, backup validation, plugin/theme updates, logging improvements, and safe operating practices for nonprofit WordPress sites.
Deliverables
Track Scope: Expected Deliverables
Skills Demonstrated