Progent's Ransomware Forensics Investigation and Reporting in Winston-Salem
Progent's ransomware forensics consultants can preserve the evidence of a ransomware assault and perform a comprehensive forensics analysis without interfering with activity required for business resumption and data restoration. Your Winston-Salem organization can utilize Progent's post-attack forensics report to block subsequent ransomware assaults, assist in the cleanup of lost data, and comply with insurance carrier and governmental requirements.
Ransomware forensics is aimed at discovering and describing the ransomware assault's progress across the targeted network from start to finish. This audit trail of how a ransomware attack travelled through the network helps you to assess the impact and highlights shortcomings in security policies or work habits that should be corrected to avoid future break-ins. Forensics is commonly assigned a top priority by the insurance carrier and is typically mandated by government and industry regulations. Since forensics can be time consuming, it is essential that other important recovery processes like operational continuity are executed in parallel. Progent has a large roster of information technology and data security experts with the knowledge and experience required to carry out the work of containment, operational continuity, and data restoration without disrupting forensics.
Ransomware forensics investigation is arduous and requires intimate interaction with the teams assigned to data restoration and, if needed, settlement negotiation with the ransomware adversary. Ransomware forensics typically involve the review of all logs, registry, Group Policy Object (GPO), Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and basic Windows systems to look for anomalies.
Activities associated with forensics analysis include:
- Disconnect without shutting down all potentially affected devices from the network. This can require closing all Remote Desktop Protocol (RDP) ports and Internet facing NAS storage, changing admin credentials and user passwords, and setting up 2FA to secure your backups.
- Create forensically valid digital images of all exposed devices so the data restoration team can proceed
- Preserve firewall, VPN, and other key logs as quickly as possible
- Establish the strain of ransomware involved in the assault
- Examine each machine and storage device on the network as well as cloud-hosted storage for indications of compromise
- Inventory all compromised devices
- Establish the type of ransomware involved in the attack
- Study logs and sessions in order to establish the time frame of the ransomware assault and to identify any potential sideways movement from the originally compromised machine
- Understand the security gaps exploited to perpetrate the ransomware attack
- Look for the creation of executables associated with the original encrypted files or network compromise
- Parse Outlook web archives
- Analyze attachments
- Extract URLs from email messages and determine if they are malicious
- Produce comprehensive incident documentation to satisfy your insurance and compliance regulations
- Document recommended improvements to shore up security gaps and enforce processes that lower the exposure to a future ransomware breach
Progent's Qualifications
Progent has provided online and onsite network services throughout the United States for more than two decades and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's team of subject matter experts includes consultants who have been awarded advanced certifications in core technology platforms including Cisco networking, VMware, and popular distributions of Linux. Progent's data security consultants have earned internationally recognized certifications including CISA, CISSP-ISSAP, and GIAC. (See certifications earned by Progent consultants). Progent also offers guidance in financial management and ERP software. This broad array of skills allows Progent to identify and integrate the surviving parts of your information system following a ransomware attack and reconstruct them quickly into a functioning system. Progent has collaborated with top insurance carriers including Chubb to help organizations clean up after ransomware assaults.
Contact Progent about Ransomware Forensics Services in Winston-Salem
To find out more about ways Progent can assist your Winston-Salem organization with ransomware forensics analysis, call 1-800-462-8800 or visit Contact Progent.