Back to category

Week 1

Contain a Ransomware Outbreak at a Regional Manufacturer

Beginner
Incident Responder
Cybersecurity Analyst
NIST SP 800-61r2
MITRE ATT&CK
CISA #StopRansomware Guide
NIST SP 800-61r3
NIST CSF 2.0
Incident Triage
Ransomware Containment
Indicator Identification
Lateral Movement Analysis
Immutable Backup Verification

Client Background

Pinecrest Components is a 300-employee regional manufacturer of precision-machined metal parts for aerospace suppliers. The company runs a single-domain Windows Server 2016 Active Directory forest and operates a hybrid environment of on-prem production servers plus a small Azure file-hosting instance used by the sales team.

Business Environment

Production relies on two engineering workstations that feed CNC machines and must stay online 24/7. The corporate IT team is centralized, the company has no dedicated security staff, and after-hours support is contracted to a managed services provider. Nightly backups run to an on-prem NAS plus a cloud copy via Veeam.

Security Incident

At 02:14 on Saturday the night-shift lead reported that the file server FILESRV01 displayed a ransom note named HOW_TO_DECRYPT.txt and that production CAD/CAM drawings were unreadable. EDR retro-hunting later showed suspicious PowerShell and lateral movement starting the previous Thursday evening, mass file changes at 23:00 Friday, and an attacker-controlled scheduled task executing the ransomware binary at 02:00 Saturday.

Scope

This engagement covers the corporate Active Directory domain, FILESRV01, the two engineering workstations, and the SIEM/EDR alerts available in the platform. Business leaders' contract conversations with the MSP, insurance claim negotiation, and production-line physical safety are out of scope.

Objectives

  • Identify the attacker's initial access vector and the earliest confirmed indicator of compromise
  • Determine the scope of affected systems and which production hosts are at immediate risk of encryption
  • Recommend a prioritized containment and recovery sequence that preserves evidence for law-enforcement and insurance reporting
  • Verify immutable/air-gapped backup integrity and use XDR-driven, AI-assisted correlation to accelerate scoping and recovery against 2026 ransomware TTPs.

Required Deliverables

Incident timeline of attacker actions
Containment and risk-based recovery plan
Confirmed versus suspected indicators of compromise
3 hrs estimated