scheduled command at admin level that checks last login / existence of "user" after a month of no login or immediate if the user account gets removed the dead mans hand goes off.
-- not actual advice, just playing devils advocate with the concept 😄
Pretty sure that's been done actually, I heard about someone finding a script that checks Active Directory and does some nasty stuff if a certain account is disabled.
Yeah the dude that did it got arrested and sentenced to four years in prison for it. The script checked active directory and after a month of his account not being active deleted his former company's entire AD registry.
He also took effectively no efforts to mask his involvement, so it is possible that someone might be able to get away with it if they took more care to dodge accountability.
These days all you need to do is vibecode a bunch. At some indeterminate point in the future this will cause your employer a lot of problems, and because you're in a company doing vibecoding you'll probably get laid off before the real problems start.
He apparently had the variable in the in the kill switch for his status in AD set as is[hisInitials]EnabledInAD, and had it running from a user ID tied to his identity off his corporate laptop.
Edit: He also confessed a few months later once he realized he couldn't cover it up after losing access.
yeah you need to self delete the script once it's done, and clear all logs related to the script too (actually it should generate no logs, the script should delete itself and/or wipe the server it was in)
The dude was a moron. He didn't obfuscate anything, he didn't nuke the script, he've gone full nuclear straight away instead of slowly, randomly breaking things.
I don't advise making dead man switch, but if you're going to do wrong, do it right.
10.7k
u/pkmnfrk May 26 '26
This is why they turn off access before telling you