Progent's Ransomware Forensics Analysis and Reporting Services in Salt Lake City
Progent's ransomware forensics experts can save the system state after a ransomware attack and carry out a detailed forensics analysis without disrupting activity related to business resumption and data recovery. Your Salt Lake City organization can utilize Progent's post-attack forensics report to combat future ransomware assaults, assist in the cleanup of encrypted data, and meet insurance and governmental requirements.
Ransomware forensics investigation is aimed at determining and describing the ransomware assault's storyline throughout the network from start to finish. This history of the way a ransomware assault travelled within the network helps your IT staff to assess the damage and brings to light shortcomings in policies or processes that should be corrected to avoid future breaches. Forensic analysis is typically assigned a high priority by the cyber insurance carrier and is often required by government and industry regulations. Since forensic analysis can be time consuming, it is critical that other important activities like operational resumption are performed concurrently. Progent maintains an extensive team of information technology and cybersecurity experts with the skills needed to perform activities for containment, operational continuity, and data recovery without interfering with forensics.
Ransomware forensics is complicated and calls for close cooperation with the groups assigned to data recovery and, if needed, settlement discussions with the ransomware threat actor. forensics can involve the review of logs, registry, Group Policy Object (GPO), Active Directory, DNS, routers, firewalls, scheduled tasks, and core Windows systems to look for anomalies.
Activities associated with forensics include:
- Disconnect without shutting off all potentially impacted devices from the network. This can involve closing all RDP ports and Internet connected NAS storage, modifying admin credentials and user PWs, and implementing 2FA to protect backups.
- Copy forensically sound duplicates of all exposed devices so the data recovery group can proceed
- Preserve firewall, virtual private network, and additional key logs as soon as possible
- Determine the version of ransomware used in the attack
- Examine every machine and storage device on the network including cloud storage for signs of encryption
- Inventory all compromised devices
- Determine the kind of ransomware involved in the assault
- Review logs and sessions in order to determine the timeline of the assault and to spot any possible lateral movement from the first infected system
- Identify the security gaps exploited to carry out the ransomware attack
- Search for new executables surrounding the first encrypted files or system breach
- Parse Outlook PST files
- Analyze email attachments
- Extract any URLs embedded in email messages and check to see if they are malicious
- Produce comprehensive incident documentation to meet your insurance and compliance requirements
- Document recommended improvements to close security vulnerabilities and enforce workflows that lower the risk of a future ransomware exploit
Progent's Qualifications
Progent has delivered online and onsite network services throughout the United States for over 20 years and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity practice areas. Progent's roster of SMEs includes consultants who have earned advanced certifications in core technology platforms such as Cisco infrastructure, VMware, and major Linux distros. Progent's data security consultants have earned industry-recognized certifications including CISA, CISSP-ISSAP, and GIAC. (See Progent's certifications). Progent also has guidance in financial management and Enterprise Resource Planning software. This scope of expertise allows Progent to salvage and consolidate the surviving pieces of your information system after a ransomware intrusion and rebuild them rapidly into an operational network. Progent has collaborated with top insurance carriers including Chubb to assist businesses recover from ransomware attacks.
Contact Progent about Ransomware Forensics Investigation Expertise in Salt Lake City
To find out more about ways Progent can help your Salt Lake City business with ransomware forensics, call 1-800-462-8800 or see Contact Progent.