High severityHARDEC6 steps · 6 phases
Malicious Code Incident Response Plan
NIST incident response plan for malicious code execution events in the Execution category.
1
Prepare
1 steps- Validate the incident
Review the SIEM alert and determine scope.
2
Detect & Analyze
1 steps- Process tree analysis
Review the EDR process chain.
3
Contain
1 steps- Isolate the system
Place it under network isolation.
4
Eradicate
1 steps- Cleanup
Delete malicious files.
5
Recover
1 steps- Restore
Restore from a clean backup.
6
Post-Incident
1 steps- Lessons Learned
Update policies.