Reports and research

Published reports: real investigations, sanitized for public reading.

Every report here is drawn from real engagement work, sanitized so it protects clients while showing exactly how findings, evidence, remediation, and retesting are documented. No email address or account is required to read or download anything.

Access
Free to read — no email, form, or account
Sanitization
Client identifiers and attacker-useful detail removed
Evidence standard
Confirmed, likely, and possible are kept distinct
Author
G. Schad, WordPress and Linux security specialist

The reports

What is currently published

Incident report · September 2026

A Hidden ELF Backdoor on a 261-Account WHM Server

Wordfence reported 283 infected files, ImunifyAV agreed, and the database export was completely clean. The backdoor was a packed ELF binary hidden above the web root — with the detection method, the artifact properties, the file hash, and the triage checks for your own server.

  • gsocket
  • WHM and cPanel
  • IOC triage
Read the WHM server backdoor report

Incident report · August 2026

ClickFix Malware Across 30+ WordPress Sites

A coordinated infection investigated layer by layer: obfuscated PHP, database persistence, theme injection, and PHP startup directives, with IOC triage, MITRE ATT&CK mapping, and a fleet retest protocol. Includes a free PDF.

  • ClickFix
  • Multi-site
  • MITRE ATT&CK
Read the full incident report

Sample deliverable

Sample WordPress Security Audit Report

A sanitized, representative audit deliverable: how findings are written, how severity and business impact are argued, what positive controls look like, and how retest status is tracked to closure.

  • Audit deliverable
  • Findings format
  • Retest status
Review the sample audit report