Problem Statement
Describe a safe containment and recovery plan for a malware outbreak in a mixed Windows and Linux environment.
Explanation
Isolate affected hosts at the switch or EDR while keeping a control channel. Snapshot VMs and capture memory from key systems. Reset exposed credentials and disable risky accounts. Identify patient zero and lateral paths. Rebuild from known-good images, patch aggressively, and restore data from clean backups. Keep heightened monitoring during the first week after recovery. Finally, review gaps in detection, hardening, and user training so the environment comes back stronger.
Code Solution
SolutionRead Only
Playbook: isolate → capture → credentials → eradicate → rebuild → monitor → lessons
