Malware Identification Decision Tree |
1. Suspect Worm |
1.1. Manual Analysis and Remediation Steps | |
1.2. Wipe/Restore Machine | |
1.3. Widespread? | |
1.4. Post-op Prevent Recurrence Policy |
2. Suspect Advanced Persistent Threat |
3. Incident Response Phases |
4. Suspect Virus |
5. Suspect Trojan |
6. Symantec Specific Analysis Steps |
7. Information References |