| Malware Identification Decision Tree |
| 2. Suspect Advanced Persistent Threat |
![]() | 2.1. Manual Analysis and Remediation Steps |
![]() | 2.2. Wipe/Restore Machine |
![]() | 2.3. Widespread? |
![]() | 2.4. Post-op Prevent Recurrence Policy |
| 1. Suspect Worm |
| 3. Incident Response Phases |
| 4. Suspect Virus |
| 5. Suspect Trojan |
| 6. Symantec Specific Analysis Steps |
| 7. Information References |