Back to category

Week 2

Investigate Ransomware Activity

Advanced
SOC Analyst
Cybersecurity Analyst
MITRE ATT&CK
NIST CSF
Ransomware Analysis
Lateral Movement Detection
Incident Containment

Client Background

A manufacturing client's file server shows signs of mass file encryption overnight.

Business Environment

The client runs a single manufacturing facility where a centralized Windows file server is shared by roughly 80 employees across production, engineering, and finance. Nightly backups are stored on a network-attached storage device on the same subnet.

Security Incident

Employees arriving Monday morning found shared-drive files renamed with unfamiliar extensions and a ransom note demanding cryptocurrency payment. IT confirmed the encryption began overnight and the full scope is still unknown.

Scope

This engagement covers the affected file server, its authentication and process logs, and any hosts identified as part of the lateral movement chain. The client's third-party cloud backup provider is out of scope.

Objectives

  • Trace the attack timeline
  • Identify patient zero
  • Document containment steps

Required Deliverables

Incident Timeline
Patient Zero Analysis
Containment & Recovery Plan
4 hrs estimated