Reference:
NIST Special Publication 800-61 Revision 2: According to NIST, the eradication phase involves eliminating the components of the incident, such as deleting malware or disabling breached user accounts. Developing and using a signature based on the characteristics of the detected virus is a key part of this phase, as it helps identify and remove the virus from affected systems (NIST, 2012).
SANS Institute Incident Handling Step-by-Step: The SANS Institute also outlines that during the eradication phase, signatures and other detection tools are used to ensure that all instances of the threat are identified and removed from the network (SANS, 2019).