incident evidence record
Post-remediation verification
- Incident
- INC-2026-0418-A7
- Classification
- Credential compromise → OAuth persistence → C2
- Confidence
- 0.94 (verified)
- Affected identities
- 1 · j.mercer@demo.example
- Affected assets
- 1 endpoint · WS-4471
- First observation
- 2026-04-18T09:14:22Z
- Containment issued
- 2026-04-18T09:14:51Z
actions · precondition → authorisation → execution → verification
- Endpoint isolationverifiedhost reachable only via control channel
- Session + token revocationverified0 active refresh tokens remain
- Malicious OAuth grant removalverifiedgrant absent on re-query
- Forwarding rule removalverifiedmailbox rules re-enumerated
- C2 domain blockingverifiedresolution denied at egress