Contain a confirmed malware incident
Practice the NIST 800-61 order from IR training: analyze, contain, eradicate, recover, then lessons learned. Evidence is preserved before the host is rebuilt.
- Confirm the alert against a second telemetry source.
- Isolate the host from the network using the approved control.
- Snapshot or collect volatile evidence per the playbook.
- Reset credentials that may have been used on that host.
- Block the known indicators at the perimeter.
- Eradicate the malware from the environment.
- Rebuild the host from a known-good image.
- Recover service and verify it is clean.
- Schedule the lessons-learned review.