Week 1
Contain a Ransomware Outbreak at a Regional Manufacturer
Client Background
Pinecrest Components is a 300-employee regional manufacturer of precision-machined metal parts for aerospace suppliers. The company runs a single-domain Windows Server 2016 Active Directory forest and operates a hybrid environment of on-prem production servers plus a small Azure file-hosting instance used by the sales team.
Business Environment
Production relies on two engineering workstations that feed CNC machines and must stay online 24/7. The corporate IT team is centralized, the company has no dedicated security staff, and after-hours support is contracted to a managed services provider. Nightly backups run to an on-prem NAS plus a cloud copy via Veeam.
Security Incident
At 02:14 on Saturday the night-shift lead reported that the file server FILESRV01 displayed a ransom note named HOW_TO_DECRYPT.txt and that production CAD/CAM drawings were unreadable. EDR retro-hunting later showed suspicious PowerShell and lateral movement starting the previous Thursday evening, mass file changes at 23:00 Friday, and an attacker-controlled scheduled task executing the ransomware binary at 02:00 Saturday.
Scope
This engagement covers the corporate Active Directory domain, FILESRV01, the two engineering workstations, and the SIEM/EDR alerts available in the platform. Business leaders' contract conversations with the MSP, insurance claim negotiation, and production-line physical safety are out of scope.
Objectives
- Identify the attacker's initial access vector and the earliest confirmed indicator of compromise
- Determine the scope of affected systems and which production hosts are at immediate risk of encryption
- Recommend a prioritized containment and recovery sequence that preserves evidence for law-enforcement and insurance reporting
- Verify immutable/air-gapped backup integrity and use XDR-driven, AI-assisted correlation to accelerate scoping and recovery against 2026 ransomware TTPs.
Required Deliverables