An unexpected screenshot is a reason to investigate. It does not, by itself, establish that an attacker changed the website. A deployment, consent banner, failed asset or third-party component can also alter what a check captures.
Use a response workflow that keeps the original evidence and tests the explanation before closing the alert.
Record what the check actually observed
Save the affected URL, check time, previous approved capture and changed capture. Note the monitoring configuration and any available response information. Describe the visible difference in plain language, such as an unfamiliar sign-in form, replacement headline or missing page content.
Avoid turning a percentage difference into a security verdict. It measures a comparison under particular capture conditions. A small unauthorized change can matter; a large legitimate redesign can be harmless.
Check legitimate explanations
Compare the observation with recent deployments, content edits and changes to third-party scripts. Ask the site owner whether the page was intentionally updated. Check whether the affected state is limited to one URL or is reproducible elsewhere using your established investigation process.
If a page asks a visitor to run commands or install unfamiliar software, do not follow those instructions to test it. Preserve the evidence and involve the person responsible for security or site administration.
Treat a suspected compromise as an incident
Follow your incident response procedure to contain unauthorized access, preserve relevant logs and recover the affected application. Coordinate with the hosting provider or incident responder where appropriate. Restoring an old page without addressing the cause may leave the same access path available.
The exact recovery steps depend on the platform and evidence. Monitoring is not a substitute for access controls, patching or tested backups. CISA's ransomware guide includes broader preparation and recovery guidance, including backup testing and software updates; it is not a diagnosis of a particular website alert.
Verify the restored experience
Check the restored page and the journeys that matter to visitors. Confirm expected content, forms and navigation. Review more than one affected URL if the incident was wider than the original alert.
Approve a new visual baseline only after the site owner accepts the restored state. Record who approved it and when. Continue watching for recurrence and document the cause if it is established.
Set expectations before the next alert
Scheduled visual checks observe the page at check time. They cannot guarantee immediate detection or coverage of every user, authenticated state or personalized response. Pair them with the other checks and controls your site needs.
Read the bDifferent incident evidence for a concrete example, then use the visual monitoring methodology to understand how the published test can be reproduced. If you manage multiple clients, the portfolio setup guide covers baseline and alert ownership.