Edge Device Compromised
EDGE DEVICE COMPROMISED
Trigger: VPN, firewall, or web appliance exploited. 40% of China-nexus exploited vulns targeted edge devices. 42% exploited before public disclosure.
Priority Actions: The appliance is the foothold, not the target. Check for credential harvest, config dump, tunnel establishment, and pivot to internal systems. Covers FortiGate, Ivanti, PanOS, Cisco, Citrix, F5, SonicWall, SAP NetWeaver.
reactive · perimeter breach · 10-step checklist · 7 platform CVEs
Supply Chain Indicator
SUPPLY CHAIN INDICATOR
Trigger: Third-party compromise, SaaS OAuth abuse, or vendor software backdoored. Supply chain attacks quadrupled over 5 years.
Priority Actions: Assess exposure: shared credentials, OAuth tokens, API integrations, and how many environments the compromised vendor touches. Four subtypes: software supply chain, SaaS/OAuth, vendor credential, and hardware/firmware.
reactive · third-party · 10-step checklist · 4 supply chain subtypes
Data Exfiltration Detected
DATA EXFILTRATION DETECTED
Trigger: Outbound data movement found in proxy, DLP, or network telemetry.
Priority Actions: Reconstruct what left, how (HTTPS, DNS, cloud storage, code repo, USB), when it started, and whether the channel is still active. Work backward from the exfil point to the staging host to the initial compromise. Six exfil channel types covered.
reactive · data loss · 10-step checklist · 6 exfil channel types
SaaS Tenant Hijack
SAAS TENANT HIJACK / OAUTH PERSISTENCE
Trigger: The identity provider itself is compromised. Not a mailbox, not a user: the Okta tenant, the Entra ID directory, the entire identity plane.
Priority Actions: Terminate unauthorized admin sessions via token revocation. Enumerate rogue Enterprise Applications. Check for shadow federation trusts (backdoor IdPs). Audit Global Admin roles and cross-tenant sync. Rotate all signing certificates.
reactive · clock-stopping · 7-step checklist · IdP takeover · OAuth persistence · shadow federation