Below is a brief guide on some basic steps you should follow if your website is compromised by hackers.
1. If the operation of your website is not fully essential to your main business activity, disconnect the server from the network.
2. Before disconnecting the server, keep a copy of the volatile memory. This information is useful for forensic investigation.
3. Examine the logs to learn information about the attackers' modus operandi, the source of the attack, and whether hackers have potentially gained access to other resources.
4. Scan your server to see if it is infected with rootkits, trojans, and backdoors.
5. Make sure the server software is up to date.
6. Make sure your servers are properly configured, according to best business practices.
7. If possible, disable Web Content Publishing.
8. Attackers may use some common tools, so it may be a good idea to block some utilities, such as cmd.exe and ftp.exe.
If you follow the steps above, you can not only limit the damage that could be caused after your website is compromised, but you can also prevent future attacks.

