Terminology Index
Glossary
64 terms starting with "E"
Showing 1-32 of 64 terms
Eradication Verification
Confirming that an attacker and all their footholds, malware, accounts, persistence, have actually been removed from the environment before declaring an incident resolved, rather than assuming eradication succeeded.
After eradication, responders must verify it worked: that all malware is gone, every attacker account and persistence mechanism is removed, and no overlooked foothold remains, because a single missed backdoor lets the attacker return. Verification combines checking the specific artifacts removed with broader hunting for anything missed. Only verified eradication justifies moving to recovery, so skipping it risks reinfection and a recurring incident.
Introduced in: Incident Response Operations
Examples
- Confirming every attacker-created account and persistence entry is gone.
- Hunting for any overlooked backdoor before declaring the incident resolved.
- Verifying malware is fully removed across all affected hosts.
No related terms linked yet.
