how to do a basic malware triage on a laptop
A basic malware triage workflow for laptops: isolating the machine, listing processes and autostart entries, hashing suspects, and checking network connections to reach a clean-or-escalate decision. Use when a laptop shows signs of infection. Triggers: 'malware triage', 'infected laptop', 'suspicious process'. Not for: full forensic analysis, server incidents, or removing the malware yourself.
how to do a basic malware triage on a laptop
TL;DR
Isolate the machine first, then figure out what ran. Disconnect from the network but leave it powered on, list processes and autostart entries, and hash anything unfamiliar. The goal of triage is a yes-or-no answer plus evidence, not a full forensic teardown; escalate when you confirm something real.
how to do a basic malware triage on a laptopUse this when
- a laptop shows popups, slowness, ransom notes, or other infection signs
- a user reports something weird and EDR didnt flag it
- you need to decide in an hour whether this is real or a false alarm
- you are the first responder before the IR team gets involved
Not for this skill when
- you need a full forensic image and timeline (escalate to IR)
- the suspect machine is a server (different triage, different stakes)
- you plan to clean and return the machine yourself (reimage from known-good media instead)
- the "malware" is a browser extension behaving badly (check the variant below)
Steps
- Isolate the machine. Unplug ethernet and turn off Wi-Fi, but do not power it off. Memory contents and running state are evidence you lose the moment it shuts down.
- Write down the symptoms with times. Popups, slowness, ransom notes, strange processes, what the user was doing when it started. Triage without notes becomes guesswork an hour later.
- List running processes sorted by start time. Processes that started around symptom onset, have random-looking names, or run from temp directories are your suspects:
ps -eo pid,lstart,cmd --sort=start_time | tail -30Expected: familiar system and user processes. Anything you dont recognize goes on the suspect list.
- Check autostart locations. Malware wants to survive a reboot, so look where persistence lives: on macOS, the LaunchAgents and LaunchDaemons folders; on Linux, user systemd units and cron; on Windows, the Run registry keys and scheduled tasks:
ls -la [HOME]/... /Library/LaunchDaemons/Expected: entries you recognize. Unknown items get hashed and researched, not deleted yet.
- Hash the suspects and look them up:
sha256sum [suspicious file]Expected: a hash you can search in your threat intel platform or a public hash database. A known-malicious hash confirms it in seconds; an unknown hash means keep digging.
- Check network connections. Look for established connections to IPs you dont recognize, especially on odd ports:
ss -tunpExpected: connections to known services. An unknown outbound connection from a suspect process is a strong confirmation.
- Decide: clean, suspicious, or confirmed. Clean gets documented and the machine gets reimaged anyway if there is any doubt. Suspicious gets escalated to IR with your notes. Confirmed gets a disk image preserved and an immediate escalation.
Variant: triage on Windows with built-in tools
Use Task Manager's Startup tab and Get-ScheduledTask in PowerShell for autostart, Get-Process for the process list, and Get-NetTCPConnection for network state. Same order, same decisions.
Variant: triage when the machine wont boot
Pull the drive and mount it read-only from a clean machine, or boot from known-good external media. Check the same autostart locations and hash the same suspects. Never boot the suspect OS if you can avoid it.
Variant: suspected browser-based infection
Check installed extensions and their permissions, look at browser profiles for unfamiliar additions, and review recent downloads. A lot of "my laptop is infected" turns out to be a malicious extension, which is a 5-minute fix.
Why this happens
Most malware reports are adware, false alarms, or user confusion. A fast, consistent triage sorts the real infections from the noise without a forensic lab, and it gives the IR team clean notes instead of a vague "something is wrong with my laptop."
Edge cases and pitfalls
- Rootkits can hide from process listings, so a clean ps output is not proof of clean. If symptoms persist with no visible cause, escalate.
- Dont log into sensitive accounts from the suspect machine. Assume keystrokes are watched until proven otherwise.
- Reimaging destroys evidence. If this might be a real incident, image the disk before you wipe it.
- Get the story straight before you take someone's laptop. Tell the user what you are doing and why, or the next report never comes in.
- Note the time zone on everything. Triage notes with ambiguous timestamps are useless in a timeline.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_aemKVF54IDOFmkfy51NskQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.