1. PreparationLessons learntIdentification and AnalysisRecoveryContainmentEradication 2. Elevated cmd and WMIC tasklist /v /fo csv tasklist /svc /fo…