Terminology Index
Glossary
1801 terms
Showing 1-32 of 1801 terms
Account Compromise Response
The set of actions a team takes once it confirms an attacker controls a legitimate user or service account, including locking the account, revoking sessions, resetting credentials, and tracing what the attacker did while logged in.
Because the attacker is using valid credentials, response focuses on cutting off access without destroying evidence and on reviewing the account's activity (logins, mailbox rules, data access) to scope the damage. The same playbook applies whether the account belongs to a person, a service, or an automation, though cloud and email accounts often need extra steps like revoking OAuth tokens.
Introduced in: Incident Response Operations
Examples
- Disabling a finance user's account after impossible-travel logins, then revoking all active sessions.
- Resetting a service account password and rotating its API keys after it appears in suspicious authentication logs.
- Reviewing a compromised mailbox for hidden forwarding rules added by the attacker.
No related terms linked yet.
