Case studies

Case studies: real engagements, anonymized.

Each case study describes a real engagement with client-identifying and attacker-useful details removed: the starting condition, the investigation, and the verified outcome — including what earlier attempts had missed. Published so a prospective client can see how the work actually goes before providing any access.

Basis
Real engagement work, anonymized for publication
Sanitization
Client identifiers and attacker-useful detail removed
Outcomes
Verified through retesting, not declared at cleanup
Author
G. Schad, WordPress and Linux security specialist

The case studies

What is currently published

Incident response · E-commerce

The WordPress Site That Kept Getting Reinfected

Three cleanups by other parties had not held. The fourth engagement treated the recurrence itself as the finding: every persistence layer was enumerated, access was reset, the likely entry condition was closed, and recovery was verified past the points where earlier cleanups had stopped.

  • Reinfection
  • Persistence
  • Verified recovery
Read the reinfection case study

Server audit · Membership site

Turning a Cyber-Insurance Questionnaire into Verified Controls

An insurer questionnaire full of questions the business could not answer with evidence became a Linux server audit: every relevant answer was mapped to a verified control or an honestly recorded gap, then remediated and retested.

  • Cyber insurance
  • Linux server audit
  • Evidence
Read the insurance-review case study