SANS Incident Handler's Handbook and PICERL Methodology
Eradication

SANS Incident Handler's Handbook and PICERL Methodology PICERL-E-02: Eradication: Removal of Threat Actor Artefacts

Remove threat actor artefacts including malware, web shells, accounts, scheduled tasks, services, and persistence mechanisms across all affected systems prior to recovery.

Maintained by Gerard BlokdykControl text last updated

Other controls in Eradication

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.