What to send us when you suspect a compromise
Treat unexpected administrator accounts, changed files or suspicious processes as evidence to investigate. A successful malware scan does not establish that a system is clean. Use a trusted device to contact support if the affected device or mailbox may be compromised.
Start with these details
- Identify the service, first known suspicious activity, discovery time and timezone.
- Describe the affected applications and attach relevant redacted logs or screenshots without passwords or personal datasets.
- Tell us what actions have already been taken, whether the system is still online and whether a recent known-good backup exists.
- Avoid deleting evidence or reinstalling immediately. Coordinate containment, evidence preservation and recovery with the responsible team.
Do not execute suspicious files to test them. Credential rotation and restoration should be planned from a trusted environment after considering the entry point and affected systems. The investigation and recovery work will be confirmed against your agreed service scope.
Further reading: CISA: incident response and recovery