Threat-Specific
Malware Triage Fundamentals
Step-by-step guide for initial malware response, including isolation, basic analysis, and evidence collection.
Threat-Specific · beginner · 1-2 hours
Basic procedures for initial malware analysis and containment when malware is detected on a system.
Steps
6
01
Initial Detection Confirmation
Confirm the malware alert is a true positive.
- Review the alert details from your security tool
- Identify the file path, hash, and detection name
- Check if the file is known malware or potentially unwanted program
- Determine if the malware was blocked or executed
EDR console · VirusTotal · Malware databases
02
System Isolation
Isolate the affected system to prevent spread.
- Use EDR to network-isolate the endpoint (preferred)
- If no EDR, disconnect from network (disable NIC, not power off)
- Do NOT power off the system (preserves volatile data)
- Notify the user about the isolation
Document the exact time of isolation If user is remote, coordinate isolation carefully
03
Basic Analysis
Gather initial information about the malware.
- Collect file hash (MD5, SHA1, SHA256)
- Submit to VirusTotal for detection names
- Check file signature and publisher
- Identify how the malware arrived (email, download, USB)
- Check for persistence mechanisms
VirusTotal · File hash utilities · Autoruns · Process Explorer
04
Scope Assessment
Determine if other systems are affected.
- Search EDR for same file hash across environment
- Check network logs for communication with known C2
- Search for related IOCs (IPs, domains, file names)
- Identify lateral movement indicators
05
Evidence Collection
Preserve evidence for deeper analysis.
- Capture memory dump if possible
- Collect the malware sample securely
- Export relevant logs (event logs, security logs)
- Screenshot running processes and network connections
FTK Imager · WinPmem · Event log export
Store evidence on write-protected media Maintain chain of custody documentation
06
Remediation
Remove the malware and restore normal operations.
- Use EDR/AV to remove or quarantine the malware
- Remove persistence mechanisms
- Check for and remove any dropped files
- Verify system integrity
- Restore from backup if necessary
- Gradually restore network access
Checklist
- Alert verified as true positive
- System isolated from network
- File hash and basic details collected
- VirusTotal/malware analysis completed
- Scope assessed across environment
- Evidence preserved
- Malware removed/quarantined
- Persistence mechanisms removed
- System returned to service
- Incident documented
Evidence
- Malware sample (password-protected ZIP)
- File hashes (MD5, SHA1, SHA256)
- Memory dump
- System event logs
- Network connection logs
- Process listing at time of detection