TechKnowSurge
NIST CSF RS.MI-01 NIST CSF RS.MI-02 NIST CSF RC.RP-01 CompTIA CySA+ 3.3 NIST 800-53 IR-4 CompTIA CySA+ 3.2 ISC2 CISSP 7.6 CompTIA Security+ 4.8
VideoSecurityFree

Containment, Eradication, and Recovery

Incident response containment, eradication, and recovery are the three core phases that follow threat detection and analysis, each serving a distinct role in neutralizing and resolving a security incident.

Complete this video to capture a CTF flag worth 1 point.

About this video

When a security incident is confirmed and initial analysis identifies the nature of the threat, the response effort shifts into three sequential phases: containment, eradication, and recovery. Each phase has a specific purpose and must be executed in order to effectively resolve the incident without causing additional damage or allowing the threat to persist. Containment is the immediate priority, focused on preventing the threat from spreading to other systems or network segments. For an endpoint infected with ransomware, this means isolating the machine from the rest of the network. For external intrusions, containment may involve deploying firewall rules, IPS or IDS signatures, ACLs, DLP policies, behavioral rules, or custom scripts to block attacker communication. These measures are documented carefully, as they are often temporary controls rather than permanent fixes. Eradication follows containment and involves fully removing the threat from the affected environment. In a ransomware scenario, this means eliminating the malware from the isolated machine. Simply running a removal tool may leave residual components behind, which is why reimaging the endpoint is often the preferred approach during the remediation process. A full wipe and restore eliminates any uncertainty about whether the system is truly clean. Once eradication is complete, recovery restores the system to full operational status, typically by reapplying data from clean backups rather than paying a ransom to recover encrypted files. In cases where a complete remediation is not immediately feasible, compensating controls drawn from risk management principles, such as reducing impact or accepting residual risk temporarily, may be applied to maintain business continuity while a longer-term fix is developed.

What you'll learn

What's covered

Containment Eradication Recovery

Aligned to

NIST CSF
RS.MI-01 Incidents are contained.
RS.MI-02 Incidents are eradicated.
RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process.
CompTIA CySA+
3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.
3.2 Given a scenario, perform incident response activities.
NIST 800-53
IR-4 Incident Handling
ISC2 CISSP
7.6 Conduct incident management
CompTIA Security+
4.8 Explain appropriate incident response activities.

Key terms

Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.
Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Intrusion Detection System
IDS
A system that monitors network or system activities for malicious behavior and generates alerts.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Access Control List
ACL
A set of rules that defines which users or systems are granted or denied access to a resource.
Reimaging
The process of wiping a compromised system and reinstalling the operating system and software from a clean image to ensure complete removal of threats.

Topics

Incident Response Threat Containment Threat Eradication Network Isolation Ids Ips System Reimaging Cybersecurity

Transcript

Containment, Eradication, and Recovery

Once we've declared that there is an incident, we're going to get into some troubleshooting and figure out what's going on. When we figure out what's going on, then we're going to move into containment, eradication, and recovery.

Once we've detected that there is an issue and done a little bit of analysis on it, figured out, hey, this is what's wrong on our system, our next step is that we want to contain the situation. We want to contain whatever is happening. Then we're going to eradicate, and then we're going to recover.

So what is the difference between containment, eradication, and recovery?

  • Containment is to prevent further spread of whatever it is. Whatever the problem is, prevent it from spreading further.
  • Eradication is removing the threat altogether.
  • Recovery is restoring it to full functionality.

A Ransomware Scenario

Let's develop a scenario to illustrate this. Let's say a machine got ransomware on it. What ransomware is, is it encrypts files on the machine and you can't access them because they're encrypted. In order for you to gain access to them again, you have to pay a ransom. You have to pay some sort of fee to the hacker, to the group that has this ransomware, and then once you pay that fee they'll decrypt it, and now you have access to those files and folders again.

So what we want to do is contain, eradicate, and recover. Containment just means we isolate that affected machine. It's got ransomware on it, so we're going to isolate it from the rest of the network so it doesn't spread anywhere else.

Once it's isolated, we're going to start eradicating it, getting rid of this threat. We have malware on this device, so we're going to get rid of it, we're going to remove it. We're going to go through the process of eliminating that on this isolated machine.

Next, once we do that, we're going to have to restore full functionality. We've gotten rid of the ransomware, but a lot of the files and folders have perhaps been removed or encrypted at this point in time, because we're not going to pay the ransom. We're just going to restore those files. So in this case we're restoring the files.

Stopping the Intrusion

A lot of times, if the issue is coming from outside, we want to stop this from happening, from whatever the intrusion is into our network. Maybe we need to disconnect the network, or maybe we just need to stop that intruder from being able to have access to our network.

There are several ways we could do this. One of the things we could do is put a firewall rule up, or some sort of intrusion protection system or intrusion detection system rule, and identify that traffic and stop it. Or ACL rules, or signature rules, or behavior rules, or DLP rules, or some sort of scripts or regular expressions. Essentially, put something in place to stop that communication from happening.

We probably want to record what it is that we did, what we put into place, so that way later on we can fix whatever issue it is. A lot of times this is just to contain the issue. Maybe it is a permanent fix, maybe it's to eradicate and recover, but a lot of times it's just a temporary measure to contain the issue so that we can fix whatever is going on and then recover.

Reimaging

With something like malware that gets on our machine, if we're going to have to remove ransomware on a machine and then reinstall the files, one of the good things to do just to make sure it's clean is to reimage the machine altogether. As part of the remediation process, just remove any chance that it's happening by wiping all the files and doing a full restore.

Of course, this reimaging takes a little more work, so sometimes maybe you just remove the virus. But when you just remove the viruses, there's a chance that it might not have got everything, and so that's why a lot of times we just go to reimage the machine.

Compensating Controls

There are times with certain incidents that maybe we want to have some sort of compensating control. So think risk management with this. With risk management we have avoidance, reduced impact, transfer, or accept.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →