Victim support guidance

Guidance for malware victims

What to submit

Provide impacted systems, timeline, suspicious files, and network indicators. Include consent for any malware sample upload and identify which systems are mission-critical to prioritize containment decisions.

Safety policy

Uploaded malware is quarantined, never executed on application servers, and reviewed in controlled analysis environments with auditable handling.

Immediate response checklist

  • Isolate impacted hosts and disable exposed privileged credentials.
  • Preserve logs, memory snapshots, and affected binaries before broad cleanup actions.
  • Record timeline milestones for legal, insurance, and executive communication.
  • Open a scoped project so researchers can map IOC and remediation priorities quickly.