The attack profiles on this site answer the question "what is this thing and does it work." The guides answer a different one: what to do, in what order, with what evidence, and when the correct action is to do nothing. They are grouped into four series that follow the order a real case actually runs in — diagnosis, remediation, prevention, and the reporting and legal picture — and the order is not arbitrary. Almost every expensive mistake in this subject comes from starting at step two.
Detection comes first because most cases end there
The detection series exists because the most common outcome of a competent triage is the discovery that nothing was done to you. A ranking drop has four possible causes: a third party acted against you, an algorithm update moved you, a human reviewer at Google penalized something on your own site, or something on your site quietly broke. Those four require completely different responses, and they are separable in about an hour with reports you already have. Search Console's manual actions report either names a penalty or says "No issues detected," and that single line closes off an entire branch of remediation. The security issues report is where a hacked-content problem surfaces. The performance report, compared against a dated list of confirmed Google updates, resolves most of what is left. These guides cover the symptoms people read as sabotage and what each usually means instead, the diagnostic order and what each report actually proves, how to distinguish an attack from a core update, what is worth monitoring continuously, and what each category of tool can and cannot see — including the fact that no third-party tool can see a manual action, which is why a toxicity score is not a diagnosis.
Recovery is mostly a sequencing problem
The recovery series assumes you have established that something real happened, and it is strict about order because the remedies interact. Removing links before you know whether there is a manual action wastes weeks. Filing a reconsideration request when there is no manual action achieves nothing at all, since there is nothing for a reviewer to reconsider. Filing a disavow file on suspicion is at best inert and at worst harmful, andGoogle's own documentation says most sites will never need the tool and sets two conditions that must both be true before you use it. These guides cover the honest link removal procedure, which begins with whether to do anything; the disavow file's format, limits and timing; what a manual action is and how reconsideration really works; how long each recovery scenario takes according to Google's published timelines and where no timeline exists at all; and how to recover attribution after your content has been copied.
Prevention, ranked honestly
The prevention series is where this subject's commercial incentives are most visible, so the guides are blunt about the hierarchy. The measures that measurably reduce risk are unglamorous and mostly not sold as negative SEO protection: keeping the CMS and its plugins patched, two-factor authentication on every account that can publish, registrar and registry locks on the domain, claiming and monitoring the Business Profile, file integrity and uptime monitoring, absolute canonical tags, and a backup you have actually restored from. The measures that are sold hardest — continuous link auditing, standing disavow maintenance, toxicity scoring — sit near the bottom, and the guides say so and explain why. Monitoring still earns its place, but for a reason worth being precise about: it buys you a dated evidentiary record, not an action. Knowing about an attack sooner rarely changes what you do about it; being able to prove when it started can change what a lawyer can do about it.
Reporting and the law, without the optimism
The legal series covers the channels that exist and what each one is actually for: the spam report form, the reviews management tool, the Business Redressal Complaint Form, the DMCA counter notice, and the difference between a report that triggers a review and a report that goes into a training corpus. It also covers the theories that have been used in real cases, their elements, and why so few cases are brought — a claim needs an identifiable defendant, provable causation and quantifiable damages, and attacks are cheap, anonymous and offshore precisely because that combination is hard to assemble. Extortion is the exception worth knowing about, because it is the branch of this subject where prosecutors have acted and where the first 24 hours matter. And evidence preservation belongs here rather than in the recovery series, because backlink indexes recrawl, review streams change, listing edit histories roll over, and the record you did not capture on day one is often gone by the time anyone asks for it.
How to read them
Each series has a hub that frames the whole problem, and the hubs are written to be read on their own rather than as tables of contents. If you are in the middle of something, start with the detection hub and follow the triage; you will either find the cause or eliminate three of the four possibilities, and either outcome is progress. If you are here because a proposal landed on your desk and you want to know whether it is worth what it costs, the prevention and recovery guides will tell you which line items do something. If a competitor is behind it and you are weighing whether to pursue it, read the legal hub before spending anything, because the answer depends far more on what you can prove than on what was done.