Incident Response Checklist 🚨 Immediate Actions (0-24 hours) Isolate affected endpoints from the network Block Discord API traffic at the network perimeter Disable compromised VPN and Active Directory accounts Alert users to phishing email threat Enable multi-factor authentication for all users Notify eSentire and other relevant security partners 🔄 Recovery Actions Rebuild compromised systems from clean backups Rotate all potentially compromised credentials Restore VPN and Active Directory services securely Update endpoint protection solutions Conduct a full security audit of cloud services