Assess whether to pay, restore, or rebuild from known-good (b83202)
August 31, 2026
SITUATION The working file is phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller. Threat-intel lead in a law firm with a client-matter data store has to name To pay, restore, or Rebuild from known-good for this Cybersecurity Incident Response file.
DECISION Threat-intel lead in a law firm with a client-matter data store must choose To pay, restore, / Rebuild from known-good using phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller.
HYPOTHESES TO TEST 1. The population in phishing kit targeting finance wire clerks is the one an EDR agent uninstalled on the domain controller named, so To pay, restore, follows for this Incident Response file. 2. The population in phishing kit targeting finance wire clerks is adjacent only to an EDR agent uninstalled on the domain controller; Rebuild from known-good is the honest Cybersecurity call. 3. A law firm with a client-matter data store already contained an EDR agent uninstalled on the domain controller before phishing kit targeting finance wire clerks arrived; no new Incident Response path. 4. Provenance on phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller is broken; do not pick To pay, restore, or Rebuild from known-good yet.
ANALYSIS REQUIRED 1. Name the compensating control that would let threat-intel lead release a reversible hold. 2. Test whether access is still live, already rotated, or only written as closed. 3. Check SIEM or identity logs in phishing kit targeting finance wire clerks for reuse after an EDR agent uninstalled on the domain controller. 4. For this Cybersecurity Incident Response file, read phishing kit targeting finance wire clerks against an EDR agent uninstalled on the domain controller and write the one fact that would move to pay, restore, or rebuild for threat-intel lead.
RECOMMENDATION Choose To pay, restore, / Rebuild from known-good on this Cybersecurity / Incident Response packet (phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller). If phishing kit targeting finance wire clerks cannot force a Cybersecurity label under Incident Response, stop. Do not invent missing evidence a law firm with a client-matter data store does not have.
COMMAND RETURNS - Bottom-line Cybersecurity option on to pay, restore, or rebuild, then the evidence in phishing kit targeting finance wire clerks, then the action for threat-intel lead - Hypothesis scorecard against phishing kit targeting finance wire clerks: supported / rejected / untestable - Incident Response finding in phishing kit targeting finance wire clerks that a second reviewer can re-perform - Missing page in phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller, if any
Explore more
More Cybersecurity prompts
- Assess whether to isolate a plant or keep production running (cfc9af)
- Ransomware negotiator's technical counterpart must resolve whether cyber
- Whether backups are clean enough to restore from phishing kit targeting
- Incident commander must resolve whether to pay, restore, or rebuild
- Ransomware negotiator's technical counterpart must resolve whether legal hold
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

