Identify Attack Type
DDoS/CC: massive traffic spike (10-1000x normal), saturated bandwidth, extremely slow or unreachable. Web intrusion: content tampered, hidden links, suspicious processes, CPU abnormal (crypto mining). Ransomware: files encrypted (.locked/.encrypted), ransom note on desktop.
Emergency Steps
Step 1 Isolate: set maintenance mode immediately, pause DNS if needed, disconnect from internal network, contact cloud vendor for DDoS protection activation.
Step 2 Preserve evidence: screenshot tampered pages, export logs, record timeline.
Step 3 Clean and Restore: from clean backup (ensure not contaminated), change ALL passwords (server/DB/app/FTP/API keys), remove backdoors.
Step 4 Patch: find entry point and fix. Common causes: weak credentials, unpatched vulnerabilities, insecure code (SQL injection/XSS/file upload), third-party flaws (Log4j2/Struts2).
A food company in 益阳 Ziyang found homepage replaced with gambling ads. IT team followed this workflow: 10 min clean restore from 3-day backup, 30 min password change, 2 hours vulnerability fix. Total downtime under 2 hours. Preserved complete attack logs which helped police bust overseas hacker group.