Contain a confirmed malware incident

Practice the NIST 800-61 order from IR training: analyze, contain, eradicate, recover, then lessons learned. Evidence is preserved before the host is rebuilt.

  1. Confirm the alert against a second telemetry source.
  2. Isolate the host from the network using the approved control.
  3. Snapshot or collect volatile evidence per the playbook.
  4. Reset credentials that may have been used on that host.
  5. Block the known indicators at the perimeter.
  6. Eradicate the malware from the environment.
  7. Rebuild the host from a known-good image.
  8. Recover service and verify it is clean.
  9. Schedule the lessons-learned review.