What problem does it solve?
Responding to a malware infection requires coordinating detection validation, scoping, containment, analysis, eradication, and recovery across many endpoints, and missing a single persistence mechanism or secondary payload guarantees reinfection. This Skill provides a structured, end-to-end playbook so responders eradicate malware completely instead of triaging alerts piecemeal.
Core Features & Use Cases
- Full Lifecycle Workflow: Six-step process covering detection confirmation, infection scoping, containment, sandbox analysis, eradication, and validated recovery with a 72-hour monitoring window.
- IOC Extraction & ATT&CK Mapping: Identifies persistence mechanisms, C2 infrastructure, dropped files, and maps observed behaviors to MITRE ATT&CK techniques.
- Anti-Pattern Guidance: Flags common mistakes such as eradicating before capturing memory, scoping by hash alone, and missing backup persistence mechanisms.
- Use Case: An EDR alert fires on a Qakbot infection delivered via a phishing attachment. Follow the workflow to isolate hosts, quarantine the email, extract C2 indicators, remove all persistence, and produce a structured incident report.
Quick Start
Respond to the Qakbot infection detected on workstation WKSTN-087 by scoping affected endpoints, containing the hosts, and producing an eradication and recovery report.