{"id":31941,"date":"2026-10-06T22:10:34","date_gmt":"2026-10-06T20:10:34","guid":{"rendered":"https:\/\/www.wedoback.com\/?page_id=31941"},"modified":"2026-10-07T11:00:10","modified_gmt":"2026-10-07T09:00:10","slug":"restarting-after-ransomware","status":"publish","type":"page","link":"https:\/\/www.wedoback.com\/en\/guides\/drp-bcp\/restarting-after-ransomware\/","title":{"rendered":"How do you restart your IT systems after ransomware?"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"31941\" class=\"elementor elementor-31941 elementor-31575\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9910079 e-con-full wdb-g e-flex e-con e-parent\" data-id=\"9910079\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-c298197 e-con-full wdb-g-hero e-flex e-con e-parent\" data-id=\"c298197\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-34dfafe e-con-full wdb-g-hero-in e-flex e-con e-parent\" data-id=\"34dfafe\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0e7946f elementor-widget elementor-widget-text-editor\" data-id=\"0e7946f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"wdb-g-crumb\"><a href=\"\/en\/\">Home<\/a><span>\u203a<\/span><a href=\"\/en\/guides\/\">Guides<\/a><span>\u203a<\/span><a href=\"\/en\/guides\/drp-bcp\/\">DRP and BCP<\/a><\/p><p class=\"wdb-g-pill\" style=\"--pill:#2fc7a0\">DRP and BCP<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3fa44fa elementor-widget elementor-widget-heading\" data-id=\"3fa44fa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">How do you restart your IT systems after ransomware?<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-654cdb4 elementor-widget elementor-widget-text-editor\" data-id=\"654cdb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"wdb-g-lead\">IT systems are restarted after ransomware by restoring a copy <strong>predating the intrusion<\/strong> onto <strong>new or rebuilt<\/strong> machines, after removing the attacker&#8217;s access. Do not decrypt in place to save time while the network and accounts have not been cleaned up: the goal is a clean service, not the fastest return to the infected state.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6faca4f elementor-widget elementor-widget-text-editor\" data-id=\"6faca4f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"wdb-g-meta\"><span>Updated in <b>October 2026<\/b><\/span><span><b>3 min<\/b> read<\/span><span><b>5<\/b> sources cited<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1183556 e-con-full wdb-g-body e-flex e-con e-parent\" data-id=\"1183556\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-8a00ddd e-con-full wdb-g-grid e-flex e-con e-parent\" data-id=\"8a00ddd\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-24ecb97 e-con-full wdb-g-article e-flex e-con e-parent\" data-id=\"24ecb97\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2ff190d elementor-widget elementor-widget-text-editor\" data-id=\"2ff190d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"wdb-g-key\"><h2>Key points<\/h2><ul><li>Change privileged passwords <strong>from a clean machine<\/strong> before switching anything back on.<\/li><li>Choose a copy <strong>older<\/strong> than the first sign of intrusion; if in doubt, older still.<\/li><li>Order: administration network, identity, backups, data and applications, workstations, email, users.<\/li><li>The ANSSI, France&#8217;s national cybersecurity agency, warns that a poorly rebuilt core of trust (directory) leads to a cycle of compromise that can last for months.<\/li><li>The standby environment is only disconnected after a <strong>successful backup<\/strong> of the new state.<\/li><\/ul><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ac617f6 elementor-widget elementor-widget-text-editor\" data-id=\"ac617f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Before switching anything back on<\/h2><ul><li>The compromised production network remains isolated.<\/li><li>Passwords for privileged accounts, VPNs, email, backup and firewalls are changed from a clean machine, not from a workstation that is still questionable.<\/li><li>Identify the probable date on which abnormal activity began (accounts created, scheduled tasks, volume of encryption). The copy to restore is <strong>older<\/strong> than that date. If in doubt, choose an older one, even if it means losing more data entry.<\/li><li>Confirm that this copy opens: one file, then one database, before launching the full restore.<\/li><li>The complaint is filed <strong>before<\/strong> machines are reinstalled, as recommended by Cybermalveillance.gouv.fr, the French government&#8217;s cyber-assistance platform, so that the technical evidence remains available.<\/li><\/ul><p>Paying the ransom to obtain a decryptor does not exempt you from any of these steps. Even when the decryptor works, it does not remove the access left behind by the attacker.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b7e20f elementor-widget elementor-widget-text-editor\" data-id=\"4b7e20f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>The four stages of remediation<\/h2><p>The ANSSI divides crisis exit into four phases, summarised in French under the acronym \u201cE3R\u201d:<\/p><table><thead><tr><th>Phase<\/th><th>Objective<\/th><th>Example action<\/th><\/tr><\/thead><tbody><tr><td>Containment<\/td><td>Stop the spread<\/td><td>Cut Internet access, isolate affected segments<\/td><\/tr><tr><td>Eviction<\/td><td>Remove the attacker<\/td><td>Revoke accounts and sessions, change all secrets<\/td><\/tr><tr><td>Eradication<\/td><td>Remove their tools and backdoors<\/td><td>Reinstall rather than clean<\/td><\/tr><tr><td>Rebuilding<\/td><td>Bring a clean IT system back into service<\/td><td>Restore data onto a clean base<\/td><\/tr><\/tbody><\/table><p>Restoring backups belongs to the last phase. Doing it earlier often means restoring for the attacker.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-46310e7 elementor-widget elementor-widget-text-editor\" data-id=\"46310e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>The rebuild order<\/h2><ol><li><strong>A new administration network<\/strong>, separate, from which all work is done.<\/li><li><strong>Identity<\/strong>: directory or local accounts rebuilt, not a copy of the directory as is if it may contain accounts created by the attacker. This is a point to settle with the incident response provider. The ANSSI stresses that failing to rebuild this core of trust leads to a cycle of compromise and remediation that can stretch over months.<\/li><li><strong>The backups themselves<\/strong>: check that they are still inaccessible to old accounts.<\/li><li><strong>Data and business applications<\/strong>, in order of dependency (database before application). The ANSSI asks for this restore order to be defined in advance, taking into account infrastructure services (DNS, NTP, directory) and the criticality of applications.<\/li><li><strong>Workstations<\/strong>, reinstalled rather than \u201ccleaned\u201d when there is no certainty. Reconnecting a workstation that is still infected restarts the attack.<\/li><li><strong>Email<\/strong>, often handled separately (Microsoft 365 or Google Workspace). For a compromised account, Microsoft recommends resetting the password, revoking all open sessions, deleting suspicious mailbox rules and forwarding, then enforcing multi-factor authentication.<\/li><li><strong>The return of users<\/strong>, in groups, with a business check. Cybermalveillance.gouv.fr recommends a gradual return to service, under monitoring, applying security updates before reconnection.<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b769b0 elementor-widget elementor-widget-text-editor\" data-id=\"2b769b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Where to restart<\/h2><p>Three options, from the slowest to the best prepared:<\/p><ul><li>reinstall new servers on the premises, then restore the copies: long RTO, depends on hardware;<\/li><li>start standby instances from the backed-up images (DRP): work continues off-site while rebuilding, on a chosen version;<\/li><li>fail over to a BCP that is already running: only if that standby environment has not replicated the encryption. If it has, fall back on the DRP and an older version.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5b40657 elementor-widget elementor-widget-text-editor\" data-id=\"5b40657\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Getting back to normal<\/h2><p>When the premises are ready, data is moved back from the standby environment to production, including whatever was entered during the standby period. A backup cycle is resumed the same day. The standby environment is only disconnected after a successful backup of the new state. Then the entry point is fixed and a new restore test is run: see <a href=\"\/en\/guides\/backup\/protect-backups-from-ransomware\/\">How do you protect your backups against ransomware?<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1985608 elementor-widget elementor-widget-text-editor\" data-id=\"1985608\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"wdb-g-brand\"><h2>At WeDoBack<\/h2><p>The <a href=\"\/en\/drp-offer\/\">DRP<\/a> is designed for exactly this restart: choice of version, restart of servers on standby instances, public IP addresses (0.54 \u20ac excl. VAT per address per month) if services must be reachable from outside, and activation during a disaster billed per day. The restore can cover the complete server, from a system image, or files only. The encryption key is held by the customer and must be available: without it, copies remain unreadable, whether immutable or not. The <a href=\"\/en\/immutable-offer\/\">IMMUTABLE<\/a> offer guarantees that the chosen version still exists. It does not decide, on the team&#8217;s behalf, which date predates the intrusion. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time).<\/p><div class=\"wdb-g-btns\"><a class=\"wdb-g-btn wdb-g-btn-primary\" href=\"\/en\/drp-offer\/\">Discover the DRP<\/a><a class=\"wdb-g-btn wdb-g-btn-ghost\" href=\"tel:+33972507828\">Call +33 9 72 50 78 28<\/a><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39f4bcd elementor-widget elementor-widget-text-editor\" data-id=\"39f4bcd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"wdb-g-faq\"><h2>Frequently asked questions<\/h2><details><summary>Can we simply restore yesterday&#8217;s backup?<\/summary><p>Rarely. An intrusion often precedes encryption by several days or weeks. Yesterday&#8217;s backup may contain the accounts, scheduled tasks or tools left behind by the attacker. First establish when the abnormal activity began, then restore an earlier copy onto a cleaned-up environment.<\/p><\/details><details><summary>Should Active Directory be restored from backup?<\/summary><p>This is a decision to be taken with the incident response provider. A copy of the directory may contain accounts or privileges created by the attacker. The ANSSI, France&#8217;s national cybersecurity agency, devotes an entire guide to rebuilding this \u201ccore of trust\u201d, because failing to do so restarts the compromise.<\/p><\/details><details><summary>How long does a full restart take?<\/summary><p>Critical services can be back up within a few days on a clean or standby environment. According to the ANSSI, full remediation can take several weeks or even several months after a major incident. The plan must therefore provide for a sustained degraded mode.<\/p><\/details><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-53300a5 elementor-widget elementor-widget-text-editor\" data-id=\"53300a5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Further reading<\/h2><div class=\"wdb-g-related\"><a href=\"\/en\/guides\/drp-bcp\/what-to-do-after-a-cyberattack\/\"><small>DRP and BCP<\/small>What should you do after a cyberattack?<\/a><a href=\"\/en\/guides\/what-to-do-if\/ransomware-just-struck\/\"><small>What to do if\u2026<\/small>Ransomware has just been triggered<\/a><a href=\"\/en\/guides\/what-to-do-if\/my-server-is-down\/\"><small>What to do if\u2026<\/small>My server is down: what should I do?<\/a><a href=\"\/en\/guides\/drp-bcp\/what-is-a-drp\/\"><small>DRP and BCP<\/small>What is a DRP?<\/a><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-91b7f02 elementor-widget elementor-widget-text-editor\" data-id=\"91b7f02\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"wdb-g-sources\"><h2>Sources<\/h2><p class=\"wdb-g-src-date\">Documents consulted in October 2026.<\/p><ol><li><a href=\"https:\/\/messervices.cyber.gouv.fr\/documents-guides\/20231218_Volet_strat%C3%A9gique_cyberattaquesetrem%C3%A9diation_v1g.pdf\" target=\"_blank\" rel=\"noopener\">Cyberattacks and remediation: keys to decision-making (v1.0, December 2023)<\/a> \u2014 ANSSI<\/li><li><a href=\"https:\/\/www.cybermalveillance.gouv.fr\/tous-nos-contenus\/fiches-reflexes\/32\" target=\"_blank\" rel=\"noopener\">Ransomware: what to do if your organisation falls victim to an attack (in French)<\/a> \u2014 Cybermalveillance.gouv.fr<\/li><li><a href=\"https:\/\/messervices.cyber.gouv.fr\/documents-guides\/anssi_fondamentaux_sauvegarde_systemes_dinformation_v1.1.pdf\" target=\"_blank\" rel=\"noopener\">Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025)<\/a> \u2014 ANSSI<\/li><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/responding-to-a-compromised-email-account\" target=\"_blank\" rel=\"noopener\">Respond to a compromised cloud email account<\/a> \u2014 Microsoft Learn<\/li><li><a href=\"https:\/\/www.wedoback.com\/offre-pra\/\" target=\"_blank\" rel=\"noopener\">DRP offer: recovery after a disaster<\/a> \u2014 WeDoBack<\/li><\/ol><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f3cc370 e-con-full wdb-g-aside e-flex e-con e-parent\" data-id=\"f3cc370\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-525c5ee elementor-widget elementor-widget-text-editor\" data-id=\"525c5ee\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<nav class=\"wdb-g-toc\" aria-label=\"Table of contents\"><p>On this page<\/p><ol><\/ol><\/nav>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1b7de31 elementor-widget elementor-widget-text-editor\" data-id=\"1b7de31\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"wdb-g-card\"><h3>Planning a backup, DRP or BCP project?<\/h3><p>More than 20 years of experience protecting business data.<\/p><a class=\"wdb-g-btn wdb-g-btn-primary\" href=\"\/en\/quotation\/\">Request a quote<\/a><a class=\"wdb-g-tel\" href=\"tel:+33972507828\">+33 9 72 50 78 28<\/a><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-411c59f e-con-full wdb-g-cta e-flex e-con e-parent\" data-id=\"411c59f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-3b583fb e-con-full wdb-g-cta-in e-flex e-con e-parent\" data-id=\"3b583fb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3b73db0 elementor-widget elementor-widget-text-editor\" data-id=\"3b73db0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Protect your data with WeDoBack<\/h2><p>Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.<\/p><div class=\"wdb-g-btns\"><a class=\"wdb-g-btn wdb-g-btn-primary\" href=\"\/en\/quotation\/\">Request a quote<\/a><a class=\"wdb-g-btn wdb-g-btn-ghost\" href=\"\/en\/offers-and-prices\/\">See offers and prices<\/a><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":31777,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"_seopress_titles_title":"Restarting IT after ransomware: the right order | WeDoBack","_seopress_titles_desc":"Restart from a copy predating the intrusion, on a clean network, in a set order, after removing the attacker's access.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"https:\/\/www.wedoback.com\/wp-content\/uploads\/2026\/10\/wdb-og-pra-pca.jpg","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"https:\/\/www.wedoback.com\/wp-content\/uploads\/2026\/10\/wdb-og-pra-pca.jpg","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":"","_members_access_role":[],"_members_access_error":""},"class_list":["post-31941","page","type-page","status-publish","hentry"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"_links":{"self":[{"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/pages\/31941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/comments?post=31941"}],"version-history":[{"count":1,"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/pages\/31941\/revisions"}],"predecessor-version":[{"id":32190,"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/pages\/31941\/revisions\/32190"}],"up":[{"embeddable":true,"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/pages\/31777"}],"wp:attachment":[{"href":"https:\/\/www.wedoback.com\/en\/wp-json\/wp\/v2\/media?parent=31941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}