# how to do a basic malware triage on a laptop

## TL;DR
Isolate the machine first, then figure out what ran. Disconnect from the network but leave it powered on, list processes and autostart entries, and hash anything unfamiliar. The goal of triage is a yes-or-no answer plus evidence, not a full forensic teardown; escalate when you confirm something real.

```text
how to do a basic malware triage on a laptop
```

## Use this when
- a laptop shows popups, slowness, ransom notes, or other infection signs
- a user reports something weird and EDR didnt flag it
- you need to decide in an hour whether this is real or a false alarm
- you are the first responder before the IR team gets involved

## Not for this skill when
- you need a full forensic image and timeline (escalate to IR)
- the suspect machine is a server (different triage, different stakes)
- you plan to clean and return the machine yourself (reimage from known-good media instead)
- the "malware" is a browser extension behaving badly (check the variant below)

## Steps
1. Isolate the machine. Unplug ethernet and turn off Wi-Fi, but do not power it off. Memory contents and running state are evidence you lose the moment it shuts down.

2. Write down the symptoms with times. Popups, slowness, ransom notes, strange processes, what the user was doing when it started. Triage without notes becomes guesswork an hour later.

3. List running processes sorted by start time. Processes that started around symptom onset, have random-looking names, or run from temp directories are your suspects:
```bash
ps -eo pid,lstart,cmd --sort=start_time | tail -30
```
Expected: familiar system and user processes. Anything you dont recognize goes on the suspect list.

4. Check autostart locations. Malware wants to survive a reboot, so look where persistence lives: on macOS, the LaunchAgents and LaunchDaemons folders; on Linux, user systemd units and cron; on Windows, the Run registry keys and scheduled tasks:
```bash
ls -la [HOME]/... /Library/LaunchDaemons/
```
Expected: entries you recognize. Unknown items get hashed and researched, not deleted yet.

5. Hash the suspects and look them up:
```bash
sha256sum [suspicious file]
```
Expected: a hash you can search in your threat intel platform or a public hash database. A known-malicious hash confirms it in seconds; an unknown hash means keep digging.

6. Check network connections. Look for established connections to IPs you dont recognize, especially on odd ports:
```bash
ss -tunp
```
Expected: connections to known services. An unknown outbound connection from a suspect process is a strong confirmation.

7. Decide: clean, suspicious, or confirmed. Clean gets documented and the machine gets reimaged anyway if there is any doubt. Suspicious gets escalated to IR with your notes. Confirmed gets a disk image preserved and an immediate escalation.

### Variant: triage on Windows with built-in tools
Use Task Manager's Startup tab and `Get-ScheduledTask` in PowerShell for autostart, `Get-Process` for the process list, and `Get-NetTCPConnection` for network state. Same order, same decisions.

### Variant: triage when the machine wont boot
Pull the drive and mount it read-only from a clean machine, or boot from known-good external media. Check the same autostart locations and hash the same suspects. Never boot the suspect OS if you can avoid it.

### Variant: suspected browser-based infection
Check installed extensions and their permissions, look at browser profiles for unfamiliar additions, and review recent downloads. A lot of "my laptop is infected" turns out to be a malicious extension, which is a 5-minute fix.

## Why this happens
Most malware reports are adware, false alarms, or user confusion. A fast, consistent triage sorts the real infections from the noise without a forensic lab, and it gives the IR team clean notes instead of a vague "something is wrong with my laptop."

## Edge cases and pitfalls
- Rootkits can hide from process listings, so a clean ps output is not proof of clean. If symptoms persist with no visible cause, escalate.
- Dont log into sensitive accounts from the suspect machine. Assume keystrokes are watched until proven otherwise.
- Reimaging destroys evidence. If this might be a real incident, image the disk before you wipe it.
- Get the story straight before you take someone's laptop. Tell the user what you are doing and why, or the next report never comes in.
- Note the time zone on everything. Triage notes with ambiguous timestamps are useless in a timeline.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_aemKVF54IDOFmkfy51NskQ
