Reimaging
Definition
Wiping a compromised system and restoring it from a known-good operating system image. Reimaging is the most reliable eradication method for host-level compromise because it eliminates every artefact the attacker may have left, including rootkits and firmware-level implants, provided the image itself is clean.
- Action
- Wipe compromised system, restore from known-good OS image
- Phase
- Eradication, in incident response
- Strength
- Removes rootkits and most implants that survive lesser cleanup
- Precondition
- The image itself must be verified clean
Common questions
Why is reimaging considered more reliable than manually removing identified malware?+
Manual removal depends on the responder having found every persistence mechanism the attacker planted, while reimaging discards the entire compromised state and rebuilds from a source known to predate the compromise, so it does not depend on complete detection of every artefact.
What can cause reimaging to fail as an eradication method?+
If the golden image used for restoration is itself compromised, or if the attacker has persistence at the firmware or hardware level such as a malicious BIOS or network device implant, a straightforward OS reimage will not remove the threat, which is why firmware integrity is checked separately in serious compromises.
Related terms
- Configuration Drift
- Deviation from an approved baseline configuration, whether caused by legitimate administrative action or by an attacker modifying settings to weaken defences or...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Persistence Mechanism
- The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
- Rogue Account
- A user or service account created by the attacker during the intrusion to maintain access independent of any compromised legitimate account. Rogue...
- Web Shell
- A script (typically PHP, ASP, or JSP) placed on a web server by an attacker to provide remote command execution via HTTP...