Progent's Ransomware Forensics Investigation and Reporting in Indianapolis
Progent's ransomware forensics consultants can save the system state after a ransomware attack and carry out a detailed forensics investigation without disrupting activity required for operational resumption and data recovery. Your Indianapolis business can use Progent's post-attack ransomware forensics report to combat subsequent ransomware attacks, validate the cleanup of encrypted data, and meet insurance and governmental requirements.
Ransomware forensics involves tracking and documenting the ransomware attack's progress throughout the targeted network from beginning to end. This audit trail of how a ransomware attack progressed within the network helps your IT staff to evaluate the impact and uncovers vulnerabilities in rules or processes that need to be corrected to avoid future break-ins. Forensic analysis is commonly assigned a high priority by the insurance carrier and is often required by state and industry regulations. Because forensic analysis can be time consuming, it is vital that other key activities such as business resumption are pursued concurrently. Progent has an extensive roster of IT and cybersecurity experts with the skills needed to perform the work of containment, operational resumption, and data restoration without disrupting forensic analysis.
Ransomware forensics is time consuming and requires close interaction with the groups assigned to file restoration and, if necessary, payment negotiation with the ransomware adversary. forensics typically involve the examination of all logs, registry, Group Policy Object (GPO), Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and core Windows systems to detect changes.
Activities associated with forensics include:
- Detach without shutting off all possibly suspect devices from the network. This can involve closing all RDP ports and Internet connected network-attached storage, modifying admin credentials and user PWs, and setting up 2FA to guard your backups.
- Create forensically sound images of all exposed devices so the file recovery team can get started
- Preserve firewall, VPN, and additional critical logs as quickly as feasible
- Determine the version of ransomware involved in the attack
- Inspect each machine and storage device on the system as well as cloud storage for indications of encryption
- Inventory all encrypted devices
- Determine the type of ransomware involved in the attack
- Review logs and sessions in order to establish the timeline of the assault and to spot any possible lateral movement from the first infected system
- Understand the attack vectors exploited to perpetrate the ransomware attack
- Search for the creation of executables associated with the original encrypted files or network breach
- Parse Outlook PST files
- Analyze attachments
- Extract URLs embedded in messages and determine if they are malicious
- Produce detailed incident documentation to satisfy your insurance and compliance regulations
- Suggest recommendations to close cybersecurity vulnerabilities and improve processes that reduce the exposure to a future ransomware breach
Progent's Background
Progent has delivered remote and onsite IT services across the U.S. for over two decades and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's team of subject matter experts (SMEs) includes consultants who have been awarded high-level certifications in core technology platforms such as Cisco networking, VMware virtualization, and popular Linux distros. Progent's data security consultants have earned industry-recognized certifications including CISM, CISSP, and CRISC. (Refer to Progent's certifications). Progent also has top-tier support in financial management and ERP application software. This breadth of expertise gives Progent the ability to salvage and consolidate the undamaged parts of your network after a ransomware intrusion and rebuild them rapidly into a functioning network. Progent has worked with leading insurance carriers like Chubb to help businesses recover from ransomware attacks.
Contact Progent about Ransomware Forensics Analysis Expertise in Indianapolis
To find out more information about how Progent can help your Indianapolis business with ransomware forensics, call 1-800-462-8800 or visit Contact Progent.