If you have ever asked “show me they were inside,” the answer that arrives is almost always a screenshot. Leak sites and negotiation blogs are full of admin UI, not poetry. “We have your files” lands harder with a picture of the files. That format is already a public habit on the adversary side.
This page is the quieter half of the same format: the record you create. A PNG of the same panel, taken by a defender during incident response, can become counsel’s exhibit, an insurer’s appendix, or a vendor ticket that gets copied into a status page. Treat every war-room capture as if it will leave the company, because it will. Why crews post dashboard pictures as leak-site theater is the sibling piece: why they post them.
In May 2026, BleepingComputer reported that RansomHouse claimed a Trellix source-code breach and offered leak-site screenshots as proof of access. That coverage is the citation for “screenshots as evidence,” not a claim that a named defender paid because they forgot to blur a table. This page stays on the format becoming a record, including records you create. It is not a catalog of crews and not a how-to for anyone’s intrusion.
Why “proof of hack” is usually a screenshot
Open larger image in a new tabSpeed and readability. A dump is work. A screenshot of an admin console is a shape a reader understands. Microsoft’s incident-response guidance tells teams to be careful when sharing information publicly and to involve legal before you brief customers. A thumbnail of the admin UI “for authenticity” is the opposite of that care. Authenticity is the statement. The thumbnail is hostnames and rows.
Other crews do the same genre. This post is not a catalog of those groups. It is a warning about the format. If the only artifact you keep from a war room is a folder of unbarred PNGs, you have built a proof pack that anyone with access to the channel can forward.
Your screenshots can become that evidence
Incident Slack is still Slack. It is forwarded, screenshotted again, dropped into email, dropped into a ticket. Counsel forwards. Forwarded PNGs become exhibits. Exhibits get copied. Start from the barred export, not from “we will redact in the press deck later.” That later file is how the unredacted original becomes the file that leaks.
Vendor Zoom calls collect the same panels in a shared desktop. A live share is a screenshot that keeps updating. Stop sharing, bar, then share a window that is already clean. Keys in chrome: API keys.
Prepare an IR snip that can survive forwarding
- Write the timeline and the counts in text first. Use the image only for the layout you cannot describe.
- Capture one window, not the whole desktop. Wait out toasts. Hide the SSO switcher if it names the org.
- Fill customer columns, URLs, and seat counts with Black bar. Do not smear a name column with light Blur.
- Export PNG. Open the download at 100% zoom. Confirm no glyph ghosts at the bar edges.
- Attach the export. Keep the original off the thread, off email, and off the shared drive that “everyone in IR” can browse.
Open larger image in a new tabWhat you should see in counsel’s folder: one cropped panel, identifiers filled, and a written timeline next to it. What you should not see: a zip of Recents from someone’s laptop with every admin tab still live.
What to cover on a “we got owned?” snip
- Customer names in the table
- Internal URLs
- SSO tiles
- Anything that proves which plant or which hospital
- License and seat counts that identify the tenant
- Backup product plus a hostname in the same frame
You can still show a panel exists. You can describe impact in text. You do not need live customer rows in the PNG that will be forwarded to a lawyer, a journalist, or a vendor. Status pages and public statements are not the place for a thumbnail of the admin UI. CISA’s StopRansomware resources emphasize reporting, backups, and containment, not pasting a live tenant into chat.
Is a blur over a customer column enough for IR?
Customer names and account numbers are short secrets. A polite smear is the wrong tool. Use a fill. This is not a PETS recreation in the SOC. It is the same operational rule: leftover structure is leftover data. If you would not put the column in the status page, do not put it in the PNG.
How do you brief counsel without handing them a proof pack?
Written timeline. Counts. Systems named in the vocabulary they already use. If an image is required, one cropped panel with customer columns filled, URLs filled, and SSO tiles filled. Microsoft’s IR notes also say not to upload files to random online scanners during an incident. The same instinct applies to consumer “redact this PNG” upload sites. Paint locally. Keep the chain short.
What is not in this article: a named victim whose only mistake was blur. A claim that Trellix staff posted the leak-site images. A tutorial for running a leak site. The documented hook is narrower: crews already use screenshots as proof, and defender screenshots of the same class of UI should be barred before they travel.
When the exhibit looks dirty
If Slack showed a preview of the unbarred original because you pasted twice, delete the first paste if you still can, then treat the key or tenant ID as exposed to everyone who loaded the thumbnail. If a JPEG attachment rings around a bar, re-export PNG and attach as a file. If someone screenshotted your screen share, the fix is process: share the already-barred window, not the live console.
Recap
Proof of access is usually a picture because pictures are easy to believe. Your pictures can become that proof, or an exhibit that repeats it. Bar before the first paste. Assume counsel, vendors, and a second channel will see the PNG: redact before you paste into Slack.





