Skip to main content
Finin2minBatch 08 · Source checked 14 Aug 2026
Cyber Security & ResilienceUpdated 5 October 2026

Cyber Swachhta Kendra for Corporate Devices: Botnet Detection, Malware Cleanup and Evidence Checklist

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

India-first finance, audit and risk workflow with primary-source anchors.

2-minute summary

Current position

Cyber Swachhta Kendra is CERT-In’s Botnet Cleaning and Malware Analysis Centre. Its tools and guidance can assist endpoint cleanup, but enterprise incident closure still requires scope assessment, credential review, evidence preservation where appropriate and validation that persistence or lateral movement has been addressed.

Control and decision map

#Control / decision step
1Identify the affected device, user, network segment and detection source.
2Preserve relevant logs / artefacts before cleaning when incident severity warrants it.
3Use approved anti-malware / Cyber Swachhta tools and enterprise EDR in a controlled remediation process.
4Reset potentially compromised credentials and review persistence / lateral-movement indicators.
5Re-scan and validate that the device is clean before returning it to normal use.
6Document root cause and update preventive controls, patching or user awareness.

Evidence pack

Worked example

A botnet alert identifies an employee laptop. IT immediately removes malware, but security first captures EDR and network logs because the device had privileged VPN access. After cleanup, credentials are reset and adjacent systems are hunted for the same indicators. The case closes only after validation, not when the antivirus popup disappears.

Common mistakes

  1. Cleaning before preserving evidence in a material incident.
  2. Assuming one infected endpoint is the whole scope.
  3. Returning the device without credential reset or re-scan.
  4. Treating a free cleanup tool as a replacement for enterprise incident response.

Frequently asked questions

Can Cyber Swachhta Kendra tools be used by companies?

They can support malware cleanup, subject to enterprise security / change controls.

Does cleanup end the incident?

No. Validate scope, persistence, credentials and root cause.

Should the device always be wiped?

That is a risk-based incident decision; preserve necessary evidence first.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, contract, facts and professional judgement before acting.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.