CyberDefenders is an independently funded nonprofit project.. Donate
Incident response and threat intelligence research
2026 Summer Cohort — Capstone Project

After the Hack: Incident Response & Threat Intel for Community Defenders

Sponsored by SF Living Wage Coalition

Project Brief

Incident Response for a Real Nonprofit Compromise

SF Living Wage Coalition runs a WordPress website that was recently hacked. This track analyzed the compromise using available evidence — logs, user accounts, plugin and theme details, file changes, hosting artifacts, alerts, and recovery notes — and turned it into practical guidance for community defenders. The work combined incident response, careful evidence handling, OSINT-backed threat intelligence, MITRE ATT&CK mapping, and plain-language explanations of what the incident means for nonprofits and small organizations running WordPress.

Capstone Team

Project Workstreams

Incident Evidence Review

Reviewed web server logs, WordPress users, plugin and theme versions, file modification timestamps, suspicious redirects, malware signatures, and recovery notes to reconstruct what happened.

WordPress Attack Path Analysis

Identified likely entry points and defensive gaps — vulnerable plugins, outdated themes, weak administrator credentials, exposed login surfaces, and insecure file permissions.

Threat Intel Correlation

Validated and enriched indicators (IPs, domains, file hashes, URLs, user agents) and mapped observed behaviors to MITRE ATT&CK, explaining what each technique means for defenders.

Recovery & Hardening Playbook

Documented containment, cleanup, credential rotation, backup validation, plugin/theme updates, logging improvements, and safe operating practices for nonprofit WordPress sites.

Track Scope: Expected Deliverables

  • Incident timeline summarizing discovery, likely compromise window, observed symptoms, response actions, and remaining unknowns.
  • WordPress security assessment covering plugins, themes, users, configuration, backups, logs, and hosting exposure.
  • Root-cause hypothesis with evidence strength, confidence level, and alternative explanations.
  • IOC list with source citations, confidence notes, and safe-use guidance.
  • MITRE ATT&CK mapping of observed or likely techniques with defender-focused explanations.
  • Recovery and hardening checklist for SF Living Wage Coalition.
  • Reusable WordPress incident response playbook for nonprofits and small organizations.

Skills Demonstrated

Incident Response Digital Forensics MITRE ATT&CK Threat Intelligence IR Playbook Development Technical Documentation