Topic · Security
Security reports.
Incident response, fraud prevention, encryption, and the security work that keeps East Tennessee businesses out of the headlines.
01
Security
Open RDP on the Public Internet: Found During Onboarding Discovery
Day-one discovery for a new client found Remote Desktop exposed to the public internet. Nothing was breached yet; we closed it before someone found it. 02 SecurityGetting Verification Codes You Didn't Request? How to Tell Spam From Account Compromise
A title company user received back-to-back OTP codes she never asked for. The triage playbook: attacker on a signup form versus actual account compromise. 03 SecurityFinding Your BitLocker Recovery Key After a Windows Update Breaks Boot
How to find your BitLocker recovery key after a Windows update breaks boot: Microsoft account, Entra, or the copy your IT team escrowed. There is no bypass. 04 SecurityBEC Wire Fraud at a Title Company: How We Stopped a High-Six-Figure Loss
An attacker got into a closer's inbox and sent fraudulent wire instructions to the other side of a real estate deal. We contained it in under three hours. 05 SecurityOneStart Browser Hijacker: Complete Removal from 30 Infected Machines
How to uninstall OneStart: the Windows uninstaller leaves scheduled tasks that put it back. Kill the processes, delete the tasks, then wipe the files. 06 SecurityLaptop Stolen at Airport: Emergency Remote Wipe via RMM
Friday 4:47 PM. Sales rep's laptop stolen with customer data. Device online on a different network. We had minutes to act. 07 SecurityLocked Out of Client PC: Emergency Local Admin via RMM
IT director quit and changed every admin password on the way out. Domain locked, DSRM locked, 85 users dead in the water. RMM saved the day. 08 SecuritySecurity Audit: Passwords Found in Spreadsheets and Documents
Compliance audit required proving no plaintext passwords on endpoints. Scan found 23 files with 'password' in the name containing actual credentials.
Advertisement, ours, permanently
Dealing with something like this right now?
Book fifteen minutes with Corey, the person who wrote every report on this page.