Cyber Swachhta Kendra for Corporate Devices: Botnet Detection, Malware Cleanup and Evidence Checklist
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
India-first finance, audit and risk workflow with primary-source anchors.
2-minute summary
- Cyber Swachhta Kendra is CERT-In’s Botnet Cleaning and Malware Analysis Centre and provides cleaning tools and security guidance. For enterprises, those tools can support remediation but should sit inside managed endpoint, forensic and change-control processes.
- Running a cleanup utility does not establish that an incident is fully contained. Security teams still need to determine initial access, persistence, credential theft, lateral movement and whether other assets were affected.
- For regulated or evidentiary incidents, preserve logs and forensic artefacts before destructive cleanup where practical; otherwise remediation can erase facts needed for reporting or root-cause analysis.
Current position
Control and decision map
| # | Control / decision step |
|---|---|
| 1 | Identify the affected device, user, network segment and detection source. |
| 2 | Preserve relevant logs / artefacts before cleaning when incident severity warrants it. |
| 3 | Use approved anti-malware / Cyber Swachhta tools and enterprise EDR in a controlled remediation process. |
| 4 | Reset potentially compromised credentials and review persistence / lateral-movement indicators. |
| 5 | Re-scan and validate that the device is clean before returning it to normal use. |
| 6 | Document root cause and update preventive controls, patching or user awareness. |
Evidence pack
- Detection alert
- Forensic / log preservation note
- Cleanup tool / EDR result
- Credential reset and re-scan evidence
- Root-cause / preventive-action record
Worked example
A botnet alert identifies an employee laptop. IT immediately removes malware, but security first captures EDR and network logs because the device had privileged VPN access. After cleanup, credentials are reset and adjacent systems are hunted for the same indicators. The case closes only after validation, not when the antivirus popup disappears.
Common mistakes
- Cleaning before preserving evidence in a material incident.
- Assuming one infected endpoint is the whole scope.
- Returning the device without credential reset or re-scan.
- Treating a free cleanup tool as a replacement for enterprise incident response.
Frequently asked questions
Can Cyber Swachhta Kendra tools be used by companies?
They can support malware cleanup, subject to enterprise security / change controls.
Does cleanup end the incident?
No. Validate scope, persistence, credentials and root cause.
Should the device always be wiped?
That is a risk-based incident decision; preserve necessary evidence first.
Official sources
- Indian Computer Emergency Response Team (CERT-In) - Cyber Swachhta Kendra - Botnet Cleaning and Malware Analysis Centre (Cyber Swachhta Kendra; current)
- Indian Computer Emergency Response Team (CERT-In) - 15 Elemental Cyber Defense Controls (Version 1.0; 1 Sep 2025)
- Indian Computer Emergency Response Team (CERT-In) - Directions under section 70B on cyber security practices and incident reporting (No. 20(3)/2022-CERT-In; 28 Apr 2022; current)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.