The void has a process

An integrity check answers only the question it was built for. I treat the report that follows the trail as part of the repair.

A clean result from an integrity check means clean against what the tool knows. Everything outside that is still mine to look at.

A core checksum check compares the installed core files with the expected release. Matching core files leave the rest of the site to be examined. The first failure is trusting a tool with a question it was built to leave alone.

The site is clean and the source is still live

The second failure is older. Incident response gets treated as a technical job. Find the bad files, remove them, harden the site, move on. The site is clean, the owner is reassured, the work is done.

Infrastructure serving malicious code may remain active, able to reach other sites.

The report is part of the response

Where evidence points to infrastructure serving malicious code, a report gives the people responsible for that infrastructure something to examine. I see that as part of the response: carrying the finding beyond the site being repaired.

Reporting can fall outside the work someone was asked to do. The immediate problem is fixed, while a report adds work with an uncertain result. Sending one can feel like shouting into a void.

The void has a process. A host, a network or a national response team decides what to do with the evidence, and each can act beyond one site. I see value in making the finding available to them.

The fix protects one site. The report might protect the next one.