The eradication phase of an incident response plan is where the root cause of the incident is determined and eliminated. This phase involves identifying and removing all traces of the malicious activity from the affected systems and restoring them to a secure state. References = NIST SP 800-61 Revision 2, CISM Review Manual 15th Edition