Skip to content

Eradication

Definition

The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised credentials, and removing unauthorised accounts or persistence mechanisms. Eradication follows containment and precedes recovery.

Position in lifecycle
Follows containment, precedes recovery
Framework
NIST SP 800-61, SANS PICERL model
Typical actions
Deleting malware, patching exploited vulnerabilities, revoking credentials
Also removes
Unauthorised accounts and persistence mechanisms

Common questions

Why is eradication kept separate from containment?+

Containment stops an incident from spreading while the environment is still under attacker control, whereas eradication removes the attacker's foothold entirely; skipping straight to eradication before containment risks tipping off the attacker or losing evidence.

What happens if eradication is incomplete?+

A missed persistence mechanism, such as a scheduled task or a backdoor account, lets the attacker regain access after recovery, which is why responders verify eradication before restoring systems to production.

Related terms

Containment Strategy
A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting...
After-Action Report (AAR)
The formal document produced during Lessons Learned that records the incident timeline, decisions made, outcomes, and recommended improvements. The AAR drives updates...
Incident Declaration
The formal decision, made during the Identification stage, that a detected event meets the organisation's criteria for a security incident. Declaration triggers...
Incident Response Lifecycle
The structured sequence of phases NIST SP 800-61 defines for handling computer security incidents: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity....
Incident Response Plan
A formal document that defines an organisation's approach to incident handling: roles and responsibilities, escalation paths, communication procedures, legal and regulatory obligations,...
Indicators of Compromise (IoCs)
Artefacts observed on a network or system that suggest an intrusion or malicious activity has occurred, such as unusual outbound connections, known-malicious...
Lessons-Learned Meeting
A structured post-incident review, recommended by NIST within approximately two weeks of incident resolution, that examines what happened, what the response did...
NIST SP 800-61
The US National Institute of Standards and Technology's Computer Security Incident Handling Guide. It defines a four-phase IR lifecycle: Preparation; Detection and...
PICERL
Acronym for the six SANS IR stages: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The model is cyclical: the final stage...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.