Reimaging removes software, not stolen credentials
Rebuilding a machine gets rid of the malware. It does not get rid of what the malware took.
Passwords, session tokens and certificates harvested from that device remain valid afterwards, so the attacker walks back in through the front door of a clean machine. Response has to include rotating what was exposed, and the order matters: rebuild first and reset afterwards and you may hand the new credentials straight over.
More on Endpoint security
- EDR visibility depends on the sensor being aliveSilence is not the same as safety
- Application allowlisting controls execution, not intentThe list checks the name
- Local admin changes the consequence of compromiseOne click, two blast radii
- Device compliance is a snapshot, not permanent healthA tick is a photograph
- Full-disk encryption protects a powered-off device bestAt rest means switched off
- USB controls are a system design problemDesign the socket, not the poster
