{"id":13844290,"url":"https://github.com/magoo/ato-checklist","last_synced_at":"2025-07-11T22:31:20.504Z","repository":{"id":49316976,"uuid":"370438461","full_name":"magoo/ato-checklist","owner":"magoo","description":"A checklist of practices for organizations dealing with account takeover (ATO)","archived":false,"fork":false,"pushed_at":"2021-08-06T17:36:05.000Z","size":35,"stargazers_count":253,"open_issues_count":0,"forks_count":25,"subscribers_count":13,"default_branch":"master","last_synced_at":"2024-02-12T21:21:11.017Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/magoo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-05-24T17:47:33.000Z","updated_at":"2024-02-10T11:10:27.000Z","dependencies_parsed_at":"2022-09-15T20:12:59.838Z","dependency_job_id":null,"html_url":"https://github.com/magoo/ato-checklist","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/magoo/ato-checklist","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/magoo%2Fato-checklist","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/magoo%2Fato-checklist/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/magoo%2Fato-checklist/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/magoo%2Fato-checklist/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/magoo","download_url":"https://codeload.github.com/magoo/ato-checklist/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/magoo%2Fato-checklist/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264909966,"owners_count":23682096,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:39.482Z","updated_at":"2025-07-11T22:31:20.495Z","avatar_url":"https://github.com/magoo.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# Account Takeover (ATO) Checklist\nThis is a list of considerations when designing a sophisticated program to deal with account takeover threats.\n\nView the associated threat model [here](model.md).\n\n---\n\n🐑🐑🐺🐑\n\n---\n\n\n## Infrastructure 🛠\nBackend systems we rely on for detection and mitigation.\n\n- [ ] General Rate Limiting\n- [ ] User Event / Authentication Logs\n- [ ] Device Identification (Cookie)\n\t- See reference like [AuthTables](https://github.com/magoo/AuthTables)\n- [ ] Browser Fingerprinting (No Cookie)\n\t-  See [AmIUnique](https://amiunique.org/), [Cover Your Tracks](https://coveryourtracks.eff.org/)\n\t-  🚨 Do not mix with ads infra 🚨\n- [ ] Device Verification (Email confirmation, SMS, Snail Mail)\n- [ ] Customer Session, Password Reset Workflows (Backend)\n- [ ] Link Shim\n- [ ] Leaked Credential Pipeline (Backend)\n\t- [ ] Scraping (Pastebin, torrents, etc)\n\t- [ ] D a R k W e B and UnDErGroUnD\n\t- [ ] Periodically accessible dumps\n\n## ATO Indicators and Features 🕵️‍♀️\nThis section describes useful data that often needs to be acquired externally. These can be used in automated classification or to decorate investigation workflows with correlating info. \n\n- [ ] Known proxies, tor, vps \u0026 colocation\n- [ ] Observed malicious or  compromised (Paid)\n- [ ] Known Leaked Credentials\n- [ ] Recent Sim Swap\n- [ ] Domain intelligence\n\t-  [ ] New domains\n\t-  [ ] Disposable \n\t-  [ ] Previously abused\n-  [ ] Address verification\n-  [ ] Cellular verification (VoIP detection)\n\n## Product / UX 🎮\nAll user facing experiences to help reduce risk within a product.\n\n- [ ] MFA Options\n\t- Security keys, MFA, SMS, backup codes, etc.\n- [ ] Knowledge Base and self-support\n\t- Reducing outreach to support for questions.\n- [ ] Link Shim\n\t- Allows for disabling of external links when copy-pasted, emailed, or otherwise brought off platform.\n\t- Allows for warning messages before leaving platform.\n- [ ] Victim and Witness escalation (Report Abuse)\n\t- Where victims of ATO report their issue.\n\t- Where witnesses of abuse report off-platform impact of on-platform ATO.\n- [ ] Forced Password Reset Workflows\n\t- [ ] Retroactively ask users to change leaked passwords\n\t\t- Existing customers will have weak passwords.\n\t- [ ] Handle newly found customers from a leaked credential backend\n\t\t- Newly leaked credentials will cause a regular need to change customer passwords.\n\t- [ ] \"Reset the password to your email\"\n\t\t- Some investigations will indicate a customer's email is compromised, not their password.\n\t- [ ] Account re-enable\n\t\t- Self service workflows to get back online after you have intervened.\n- [ ] Enforce [password strength](https://github.com/dropbox/zxcvbn) to prevent future weak passwords \n\t- [ ] New Registration\n\t- [ ] Password Change\n\t- [ ] Ongoing leaked / Newly weak\n- [ ] Developer console prompts w/ a warning message\n\t- Example: [Facebook](https://security.stackexchange.com/questions/158106/facebooks-warning-of-self-xss)\n- [ ] Verification / Challenge workflows\n\t- When you are uncertain of the customer's location or device.\n\t\t- [ ] SMS\n\t\t- [ ] Email\n\t\t- [ ] Account / Identity Knowledge\n\t\t- [ ] ID Submission\t\n\t\t- [ ] CAPTCHA\n- [ ] Stolen Session Detection\n\t- Example: [Catching Compromised Cookies](https://slack.engineering/catching-compromised-cookies/)\n\n## Customer Service ☎️\nOperational customer service interactions (Support tickets). Support organizations often escalate abuse at scale to engineering and have the most visibility into what is, or is not, working.\n\n- [ ] Standard Org Language\n\t- What counts as ATO?\n- [ ] Metrics / KPI\n\t- Tracking abuse going up or down.\n- [ ] IR Escalation\n\t- Playbooks / Plans for creating an outage or getting engineering resources involved.\n- [ ] Reset Workflows (Administrative Frontends)\n\t- Empowering scalable operations to mitigate abuse scenarios.\n\n## Investigations \u0026 Response 🚑\nThere will be periodic deep dives into ATO attacks to ask \"what happened?\". This section pertains to that perspective of work.\n\n- [ ] Authentications are searchable by device, ip, user agent\n\t- [ ] Searches can pivot: Device to IP, IP to device, etc.\n\t- [ ] Bonus: Actions / Events are searchable\n\t- [ ] Bonus: All routes / Endpoints are searchable\n- [ ] Tooling exists to reset bulk accounts that meet criteria\n- [ ] Tooling exists to reverse transactions / changes that meet criteria.\n\n## Automation 🤖\nTying everything together for operational ATO systems. Engineering time is the least scalable, customer support hours are more scalable, fully automated systems are the most scalable.\n\n- [ ] Customer service classifies abuse cases \n- [ ] AI systems classifies authentication events\n- [ ] Suspicious cases push customers to verify activity\n- [ ] XFN meetings between groups to improve anti-abuse systematically\n\n## Anti-Phishing 🎣\nRaising the bar against trivial credential stealing attacks which cause the most problems for unprepared organizations.\n\n- [ ] SPF / DMARC / DKIM \n- [ ] Brand protection (Internet scanning for your brand being spoofed)\n- [ ] spoofed@ and customer phish reporting\n- [ ] App store hunting\n- [ ] Domain / ISP Takedowns\n- [ ] Browser blacklisting\n- [ ] Referer, hotlinks, adversary leaks\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmagoo%2Fato-checklist","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmagoo%2Fato-checklist","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmagoo%2Fato-checklist/lists"}