Victim support guidance
Guidance for malware victims
What to submit
Provide impacted systems, timeline, suspicious files, and network indicators. Include consent for any malware sample upload and identify which systems are mission-critical to prioritize containment decisions.
Safety policy
Uploaded malware is quarantined, never executed on application servers, and reviewed in controlled analysis environments with auditable handling.
Immediate response checklist
- Isolate impacted hosts and disable exposed privileged credentials.
- Preserve logs, memory snapshots, and affected binaries before broad cleanup actions.
- Record timeline milestones for legal, insurance, and executive communication.
- Open a scoped project so researchers can map IOC and remediation priorities quickly.