Overview of Progent's Ransomware Forensics and Reporting in Chicago
Progent's ransomware forensics experts can save the system state after a ransomware attack and carry out a detailed forensics analysis without interfering with the processes required for operational resumption and data recovery. Your Chicago business can use Progent's post-attack ransomware forensics report to block future ransomware attacks, validate the restoration of lost data, and comply with insurance and governmental requirements.
Ransomware forensics investigation involves tracking and documenting the ransomware assault's storyline throughout the network from start to finish. This history of how a ransomware assault travelled through the network assists you to assess the damage and highlights weaknesses in policies or work habits that should be rectified to avoid later break-ins. Forensics is typically assigned a top priority by the insurance carrier and is typically required by state and industry regulations. Because forensic analysis can take time, it is essential that other important activities such as business resumption are pursued concurrently. Progent maintains an extensive roster of information technology and data security professionals with the knowledge and experience needed to perform the work of containment, business resumption, and data restoration without disrupting forensics.
Ransomware forensics analysis is complicated and requires close interaction with the teams assigned to file restoration and, if needed, payment discussions with the ransomware adversary. Ransomware forensics can require the examination of logs, registry, Group Policy Object (GPO), Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and core Windows systems to detect changes.
Activities associated with forensics analysis include:
- Isolate but avoid shutting down all possibly impacted devices from the system. This can involve closing all RDP ports and Internet facing network-attached storage, changing admin credentials and user PWs, and setting up two-factor authentication to secure your backups.
- Create forensically valid duplicates of all exposed devices so your file restoration group can get started
- Save firewall, virtual private network, and additional key logs as quickly as possible
- Identify the variety of ransomware used in the attack
- Inspect each machine and storage device on the network as well as cloud-hosted storage for signs of compromise
- Inventory all compromised devices
- Establish the kind of ransomware involved in the attack
- Review logs and user sessions in order to establish the time frame of the ransomware assault and to spot any potential lateral movement from the originally infected machine
- Understand the attack vectors used to perpetrate the ransomware assault
- Search for new executables surrounding the first encrypted files or system compromise
- Parse Outlook web archives
- Analyze attachments
- Separate any URLs embedded in messages and determine if they are malware
- Produce comprehensive incident documentation to meet your insurance carrier and compliance mandates
- Suggest recommended improvements to shore up security vulnerabilities and enforce processes that reduce the risk of a future ransomware exploit
Progent's Background
Progent has provided online and on-premises IT services throughout the U.S. for over two decades and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's roster of subject matter experts includes consultants who have earned advanced certifications in foundation technologies such as Cisco networking, VMware, and major distributions of Linux. Progent's cybersecurity consultants have earned industry-recognized certifications including CISA, CISSP, and GIAC. (See Progent's certifications). Progent also has guidance in financial management and ERP application software. This breadth of expertise allows Progent to identify and integrate the undamaged pieces of your network following a ransomware intrusion and rebuild them rapidly into an operational system. Progent has worked with top cyber insurance providers including Chubb to assist organizations clean up after ransomware attacks.
Contact Progent about Ransomware Forensics Investigation Expertise in Chicago
To find out more information about how Progent can assist your Chicago organization with ransomware forensics investigation, call 1-800-462-8800 or visit Contact Progent.