Triage a possible phishing infection without destroying useful evidence
Instruction: Describe your first actions, the information you capture, and the handoff to security. Explain how you protect the user without conducting an unauthorized malware investigation.
A fictional user says they opened an invoice attachment five minutes ago; the laptop now shows unfamiliar pop-ups. They have not reported entering credentials. No malware verdict is available. The approved help-desk runbook permits disconnecting this managed laptop from wired and wireless networks when active compromise is suspected, then phoning the security duty team. It says to leave power on after successful isolation and not uninstall software, delete files, or run cleanup tools unless security directs it. Security owns forensic collection and recovery decisions. The user is on a clean phone and can continue the conversation after isolation.
Updated
Official answer available
Read the opening below, then unlock the full answer and practical guidance.
I would treat the attachment and new pop-ups as a possible security incident, without telling the user that malware is confirmed. My immediate decision is to use our approved isolation procedure and call security from the clean phone. Repeated experiments on the laptop could increase harm or change evidence the responders need. I would ask the user to stop interacting with the attachment and any prompts...
Related Questions
-
easy
-
easy
-
easy
-
easy
-
easy
-
easy