๐Ÿงฏ Compromised account responder

Pick the account and get the playbook: what to check first, how to cut the attacker off, and how to recover cleanly.

๐Ÿ”’ Built in your browser. The account name never leaves this page, and every change in the script is a dry run until you say otherwise.

Safe by default: phase 1 only reads. Every change in phase 2 is a dry run with -WhatIf; remove it line by line once you have read what it will do.


  

Why this matters

When an account is compromised, the instinct is to reset the password. That does not end the sessions and refresh tokens the attacker already holds, and it does nothing about the app they consented to, the inbox rule forwarding mail, or the new MFA method they registered.

Infostealers steal session cookies, not just passwords. The order matters: block sign-in, revoke every session, then clean up persistence, then restore access with phishing-resistant MFA.