| name | cleanup-template |
| description | Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification. |
| allowed-tools | Read Write Edit |
| metadata | {"subdomain":"planning","when_to_use":"create cleanup plan, artifact inventory, persistence removal, post-engagement teardown, restoration plan","tags":"cleanup, restoration, persistence, post-engagement, hygiene","upstream_ref":"Soundwave cleanup template — artifact inventory, persistence removal, restoration plan"} |
Cleanup & Restoration Plan Generator
The cleanup plan is the anti-foothold roster — every artifact the kill chain will create must have a concrete removal command and a verifier, or dummy accounts / scheduled tasks / beacons routinely outlive the engagement.
When to Use
- After CONOPS is written (the kill chain phases dictate what artifacts will exist)
- User says "create cleanup plan", "list what we'll leave behind", "post-engagement teardown"
Workflow
Step 1: Map Kill Chain Phases → Expected Artifact Types
For every phase in CONOPS.kill_chain, infer which CleanupArtifact.artifact_type entries will be produced:
| Kill Chain Phase | Likely artifact_types |
|---|
| recon | tool (installed scanners), (firewall whitelist) |