Week 2
Investigate Ransomware Activity
Client Background
A manufacturing client's file server shows signs of mass file encryption overnight.
Business Environment
The client runs a single manufacturing facility where a centralized Windows file server is shared by roughly 80 employees across production, engineering, and finance. Nightly backups are stored on a network-attached storage device on the same subnet.
Security Incident
Employees arriving Monday morning found shared-drive files renamed with unfamiliar extensions and a ransom note demanding cryptocurrency payment. IT confirmed the encryption began overnight and the full scope is still unknown.
Scope
This engagement covers the affected file server, its authentication and process logs, and any hosts identified as part of the lateral movement chain. The client's third-party cloud backup provider is out of scope.
Objectives
- Trace the attack timeline
- Identify patient zero
- Document containment steps
Required Deliverables