Skip to content

Reimaging

Definition

Wiping a compromised system and restoring it from a known-good operating system image. Reimaging is the most reliable eradication method for host-level compromise because it eliminates every artefact the attacker may have left, including rootkits and firmware-level implants, provided the image itself is clean.

Action
Wipe compromised system, restore from known-good OS image
Phase
Eradication, in incident response
Strength
Removes rootkits and most implants that survive lesser cleanup
Precondition
The image itself must be verified clean

Common questions

Why is reimaging considered more reliable than manually removing identified malware?+

Manual removal depends on the responder having found every persistence mechanism the attacker planted, while reimaging discards the entire compromised state and rebuilds from a source known to predate the compromise, so it does not depend on complete detection of every artefact.

What can cause reimaging to fail as an eradication method?+

If the golden image used for restoration is itself compromised, or if the attacker has persistence at the firmware or hardware level such as a malicious BIOS or network device implant, a straightforward OS reimage will not remove the threat, which is why firmware integrity is checked separately in serious compromises.

Related terms

Configuration Drift
Deviation from an approved baseline configuration, whether caused by legitimate administrative action or by an attacker modifying settings to weaken defences or...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Persistence Mechanism
The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
Rogue Account
A user or service account created by the attacker during the intrusion to maintain access independent of any compromised legitimate account. Rogue...
Web Shell
A script (typically PHP, ASP, or JSP) placed on a web server by an attacker to provide remote command execution via HTTP...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.