Recognize and declare
Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.
- Confirmed malicious process, file, script, service, task, extension, or persistence
- Multiple endpoints share suspicious hashes, domains, behaviors, or parent processes
- Security tooling is disabled, tampered with, or bypassed
Preserve the evidence
Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.
- EDR telemetry, memory, process trees, command lines, modules, handles, and connections
- Files, hashes, signatures, scripts, persistence, quarantine records, and sandbox output
- Email, browser, download, proxy, DNS, firewall, identity, and software-deployment logs
- Host, user, privilege, first/last seen, prevalence, related alerts, and UTC timeline
IR-06 · FIRST 15 MINUTES
Reduce immediate uncertainty
- Isolate confirmed systems while retaining EDR or forensic connectivity.
- Capture volatile evidence and quarantine representative samples under controlled access.
- Block validated hashes, domains, IPs, URLs, certificates, and execution paths.
- Identify patient zero, delivery mechanism, privilege, persistence, and lateral movement.
- Hunt the same behaviors across endpoints, identities, servers, cloud workloads, and images.
Contain → eradicate → recover
PHASE / 01Contain
- Disable compromised identities and abused remote-management or software-delivery paths.
- Segment affected assets and prevent removable-media or shared-drive propagation.
- Protect security management, identity, backup, and deployment systems from tampering.
PHASE / 02Eradicate
- Reimage systems when integrity cannot be proven; remove unauthorized persistence and tooling.
- Patch the exploited path and replace compromised packages, images, installers, or policies.
- Rotate exposed credentials from known-clean systems.
PHASE / 03Recover
- Restore from trusted images and validate EDR, patching, logging, and application integrity.
- Reconnect staged cohorts and watch for recurring indicators or control tampering.
- Confirm business function, asset ownership, and rollback readiness.
Decision gates
Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.
Containment gate
Malicious execution and propagation are stopped, with representative evidence preserved.
Eradication gate
Delivery, execution, privilege, persistence, and affected population are understood and removed.
Recovery gate
Trusted rebuilds pass security and service checks under enhanced monitoring.
Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.
AUTHORSHIP & REVIEW
How to trust and adapt this guide
- Author & accountable editor
- Leandro Rocha
- Version
- 1.0
- Published / reviewed
- 18 August 2026
- Review status
- Maintainer-reviewed; independent peer review is not claimed.
Reference basis
- NIST SP 800-61 Rev. 3
- CISA malware analysis and containment guidance
- MITRE ATT&CK Enterprise techniques
Assumptions
- The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
- Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.
Limitations
- This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
- Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.