Overview of Progent's Ransomware Forensics Investigation and Reporting in Santos
Progent's ransomware forensics experts can preserve the evidence of a ransomware attack and carry out a detailed forensics investigation without disrupting activity required for operational resumption and data restoration. Your Santos business can use Progent's ransomware forensics documentation to combat future ransomware attacks, assist in the cleanup of lost data, and meet insurance carrier and governmental mandates.
Ransomware forensics analysis involves determining and describing the ransomware assault's progress throughout the network from start to finish. This history of how a ransomware assault travelled within the network helps you to assess the impact and uncovers gaps in security policies or work habits that need to be corrected to avoid later break-ins. Forensics is usually assigned a top priority by the cyber insurance carrier and is often required by government and industry regulations. Because forensic analysis can be time consuming, it is essential that other important activities such as operational continuity are performed in parallel. Progent maintains a large team of information technology and security experts with the skills required to carry out activities for containment, operational resumption, and data recovery without interfering with forensic analysis.
Ransomware forensics analysis is time consuming and requires close interaction with the groups assigned to file cleanup and, if necessary, settlement negotiation with the ransomware attacker. Ransomware forensics typically require the examination of logs, registry, Group Policy Object, Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and core Windows systems to look for changes.
Activities associated with forensics include:
- Disconnect but avoid shutting off all possibly affected devices from the system. This can require closing all Remote Desktop Protocol (RDP) ports and Internet connected network-attached storage, changing admin credentials and user passwords, and configuring 2FA to guard backups.
- Capture forensically valid digital images of all exposed devices so your data recovery group can get started
- Save firewall, VPN, and additional critical logs as soon as possible
- Identify the kind of ransomware used in the attack
- Inspect every computer and storage device on the system including cloud storage for indications of compromise
- Catalog all compromised devices
- Establish the type of ransomware involved in the assault
- Study log activity and sessions in order to determine the time frame of the assault and to identify any possible lateral migration from the originally compromised system
- Identify the security gaps exploited to perpetrate the ransomware attack
- Search for the creation of executables associated with the original encrypted files or network breach
- Parse Outlook web archives
- Examine attachments
- Separate URLs embedded in email messages and check to see if they are malicious
- Provide comprehensive attack reporting to satisfy your insurance carrier and compliance regulations
- Suggest recommended improvements to close cybersecurity gaps and improve processes that reduce the risk of a future ransomware exploit
Progent's Qualifications
Progent has delivered online and on-premises IT services across the United States for over 20 years and has been awarded Microsoft's Partner certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes consultants who have been awarded high-level certifications in core technologies such as Cisco networking, VMware virtualization, and popular Linux distros. Progent's data security experts have earned internationally recognized certifications such as CISA, CISSP, and GIAC. (Refer to Progent's certifications). Progent also offers guidance in financial and ERP application software. This breadth of expertise allows Progent to salvage and consolidate the undamaged parts of your information system following a ransomware intrusion and reconstruct them rapidly into an operational network. Progent has worked with leading cyber insurance carriers including Chubb to help organizations recover from ransomware attacks.
Contact Progent about Ransomware Forensics Analysis Expertise in Santos
To find out more about how Progent can help your Santos business with ransomware forensics investigation, call 1-800-462-8800 or see Contact Progent.