OPERATIONAL PLAYBOOK · IR-06

Malware outbreak

Contain malicious execution, preserve volatile evidence, identify delivery and persistence, and restore affected assets from trusted state.

SEVERITY / HIGHFIRST ACTION / ISOLATE CONFIRMED EXECUTIONFORMAT / PRINT-READY

Recognize and declare

Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.

  • Confirmed malicious process, file, script, service, task, extension, or persistence
  • Multiple endpoints share suspicious hashes, domains, behaviors, or parent processes
  • Security tooling is disabled, tampered with, or bypassed

Preserve the evidence

Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.

  • EDR telemetry, memory, process trees, command lines, modules, handles, and connections
  • Files, hashes, signatures, scripts, persistence, quarantine records, and sandbox output
  • Email, browser, download, proxy, DNS, firewall, identity, and software-deployment logs
  • Host, user, privilege, first/last seen, prevalence, related alerts, and UTC timeline

IR-06 · FIRST 15 MINUTES

Reduce immediate uncertainty

  1. Isolate confirmed systems while retaining EDR or forensic connectivity.
  2. Capture volatile evidence and quarantine representative samples under controlled access.
  3. Block validated hashes, domains, IPs, URLs, certificates, and execution paths.
  4. Identify patient zero, delivery mechanism, privilege, persistence, and lateral movement.
  5. Hunt the same behaviors across endpoints, identities, servers, cloud workloads, and images.

Contain → eradicate → recover

PHASE / 01

Contain

  • Disable compromised identities and abused remote-management or software-delivery paths.
  • Segment affected assets and prevent removable-media or shared-drive propagation.
  • Protect security management, identity, backup, and deployment systems from tampering.
PHASE / 02

Eradicate

  • Reimage systems when integrity cannot be proven; remove unauthorized persistence and tooling.
  • Patch the exploited path and replace compromised packages, images, installers, or policies.
  • Rotate exposed credentials from known-clean systems.
PHASE / 03

Recover

  • Restore from trusted images and validate EDR, patching, logging, and application integrity.
  • Reconnect staged cohorts and watch for recurring indicators or control tampering.
  • Confirm business function, asset ownership, and rollback readiness.

Decision gates

Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.

Containment gate

Malicious execution and propagation are stopped, with representative evidence preserved.

Eradication gate

Delivery, execution, privilege, persistence, and affected population are understood and removed.

Recovery gate

Trusted rebuilds pass security and service checks under enhanced monitoring.

Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.

AUTHORSHIP & REVIEW

How to trust and adapt this guide

Author & accountable editor
Leandro Rocha
Version
1.0
Published / reviewed
18 August 2026
Review status
Maintainer-reviewed; independent peer review is not claimed.

Reference basis

  • NIST SP 800-61 Rev. 3
  • CISA malware analysis and containment guidance
  • MITRE ATT&CK Enterprise techniques

Assumptions

  • The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
  • Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.

Limitations

  • This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
  • Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.