BetterShield

Respond to incidents automatically

4 min read

Let BetterShield Ultra act on a correlated incident with the response actions you choose, and re-check unpublished code every hour.

BetterShield › Ultra › Automatic response holds what BetterShield Ultra does on its own, on a schedule, within limits you set. This guide covers its Automatic incident response card and its Unpublished code, checked hourly card.

Automatic incident response

Incidents join related changes, such as a new administrator and a new PHP file on the same day. Normally you prepare a response plan and apply it yourself. This card lets Ultra apply some of those same actions for you, on an hourly schedule.

Note: This can lock a colleague out on a mistaken correlation. An incident is a correlation, not a verdict.

Choose the action types

Tick the kinds of action a run may take, then press Save incident response policy. Nothing is ticked at first, and the card reads Off until you select and save action types. Once saved, it reads On for the action types saved below.

Action typeWhat it doesReversible
Remove site roles and individual capabilitiesTakes the incident account’s roles and capabilities off this site.Yes, if the account has not changed since
End sessions (marked irreversible on screen)Signs the account out everywhere.No
Revoke credentials created in the incident window (marked irreversible on screen)Revokes the account’s application passwords created within 24 hours either side of the incident.No
Unschedule unanswered occurrences without argumentsUnschedules a scheduled task that nothing answers.Yes, though it may then run at once

Saving needs a working recovery link or printed recovery codes, and is recorded in the activity log.

What a run does

  • It runs hourly from WordPress’s scheduled tasks, never while someone loads a page.
  • Each run takes one incident with at least two anchors, the records that can open an incident. That includes one that reaches its second anchor after an earlier run looked at it.
  • It prepares the same plan as Prepare response plan on the incident, and applies at most three of the actions you saved, leaving out any the plan refuses. Review the rest yourself.
  • It acts as the account that saved the policy, with that account’s current permissions, and never acts against that account.
  • Saving sets the starting point: incidents opened before you saved are left to you.
  • It never writes files or rotates sign-in keys. Those can affect recovery itself, so they stay manual.

The card then names the Last incident considered. Signed in as the account that saved the policy, open Activity › Incidents to read its response receipt.

When it pauses

The card shows Paused with the reason whenever a run would do nothing:

  • Safe mode is on, so nothing changes while somebody gets back in.
  • No recovery link or printed recovery codes are ready.
  • Whoever saved it can no longer manage this site. Save it again to have it act as you.

Unpublished code, checked hourly

BetterShield compares published code with the official copies, and the code nobody publishes with its own earlier state once a day (see File changes). With Ultra, these are read again every hour:

  • Drop-ins
  • Must-use plugins
  • The active theme
  • wp-config.php
  • The root .htaccess
  • Plugins the directory has no list of files for

There is nothing to set: it runs while Ultra is active. A change it finds lands on Activity › File changes beside everything the daily check found, and in an alert if you have asked for one, as it would have the next day.

The card shows Last checked, Last change found, how many checks have run and how many changes they found, and Open the file report. While safe mode is on, nothing is checked; the hourly check resumes when it ends.

It runs only from WordPress’s scheduled tasks. On a site where those have stopped, the daily check still covers these files.

Good to know

  • With Ask for my password before an action that removes a protection on (Settings › General), saving the incident policy asks for your password.
  • On multisite, each site sets its own policy.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield