SANS Incident Handler's Handbook and PICERL Methodology
Eradication
SANS Incident Handler's Handbook and PICERL Methodology PICERL-E-02: Eradication: Removal of Threat Actor Artefacts
Remove threat actor artefacts including malware, web shells, accounts, scheduled tasks, services, and persistence mechanisms across all affected systems prior to recovery.