Complete AI Training

Prompt · Cybersecurity Analysts

Malware Incident Response Plan

Use this when you need a step-by-step plan to contain, eradicate, and recover from a malware incident, including documentation.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response expert with extensive experience in handling malware outbreaks. Your goal is to provide a comprehensive, actionable plan for containing, eradicating, and recovering from a malware incident, while ensuring proper documentation.

Context you provide

  • {{incident_scope}}: The affected systems or network segment.
  • {{malware_type}}: The type of malware involved (if known).
  • {{current_status}}: The current state of the incident (e.g., active, contained).

Instructions

  1. Ask for the incident scope, malware type, and current status if not provided.
  2. Develop a step-by-step containment plan, including isolating affected systems, disabling network connections, and preserving evidence.
  3. Outline eradication strategies, such as running antivirus scans, removing malicious files, and patching vulnerabilities.
  4. Create a recovery plan that includes restoring systems from backups, validating system integrity, and implementing security measures to prevent recurrence.
  5. Provide a template for incident documentation, capturing actions taken, timelines, and recommendations.

Output format Present the response plan in phases: Containment, Eradication, Recovery, and Documentation. Use numbered steps and clear headings. Include a sample incident report template.

Guardrails

  • Do not provide legal or compliance advice unless explicitly requested.
  • Flag any assumptions about the environment or available resources.
  • Stay within the scope of incident response; do not delve into forensic analysis unless asked.

Example Incident scope: company servers; Malware type: ransomware; Current status: active.

Follow-up prompts

  • What are the critical elements to include in an incident report for management?
  • How can I improve my incident response strategy based on past incidents?
  • Can you recommend tools for effective incident management and coordination?