Overview of Progent's Ransomware Forensics Investigation and Reporting in Morgan Hill
Progent's ransomware forensics consultants can capture the evidence of a ransomware attack and carry out a detailed forensics investigation without slowing down the processes required for business continuity and data recovery. Your Morgan Hill business can use Progent's post-attack ransomware forensics report to combat subsequent ransomware attacks, assist in the restoration of lost data, and meet insurance and governmental reporting requirements.
Ransomware forensics involves tracking and documenting the ransomware attack's storyline throughout the network from beginning to end. This history of the way a ransomware attack progressed through the network helps your IT staff to assess the impact and uncovers weaknesses in rules or processes that need to be corrected to avoid later break-ins. Forensic analysis is typically given a high priority by the insurance provider and is often required by state and industry regulations. Because forensic analysis can take time, it is vital that other important recovery processes such as operational resumption are performed concurrently. Progent has a large team of information technology and cybersecurity experts with the knowledge and experience required to perform the work of containment, business continuity, and data restoration without interfering with forensic analysis.
Ransomware forensics analysis is time consuming and calls for close cooperation with the teams focused on file cleanup and, if needed, settlement talks with the ransomware adversary. Ransomware forensics typically involve the review of logs, registry, Group Policy Object (GPO), Active Directory (AD), DNS servers, routers, firewalls, schedulers, and basic Windows systems to check for anomalies.
Services associated with forensics investigation include:
- Isolate without shutting down all possibly affected devices from the network. This can require closing all Remote Desktop Protocol (RDP) ports and Internet connected NAS storage, modifying admin credentials and user PWs, and implementing two-factor authentication to guard backups.
- Preserve forensically complete digital images of all suspect devices so the file recovery team can proceed
- Save firewall, VPN, and additional critical logs as quickly as feasible
- Determine the type of ransomware used in the attack
- Survey each computer and data store on the network as well as cloud-hosted storage for signs of encryption
- Catalog all compromised devices
- Establish the kind of ransomware involved in the attack
- Study logs and sessions in order to determine the timeline of the attack and to spot any possible lateral movement from the first compromised machine
- Understand the security gaps exploited to carry out the ransomware assault
- Search for the creation of executables surrounding the original encrypted files or system breach
- Parse Outlook web archives
- Examine attachments
- Extract any URLs from messages and determine whether they are malware
- Produce detailed incident reporting to meet your insurance and compliance requirements
- Suggest recommendations to close cybersecurity gaps and improve processes that lower the risk of a future ransomware exploit
Progent's Background
Progent has delivered online and on-premises network services throughout the U.S. for more than 20 years and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of SMEs includes consultants who have been awarded advanced certifications in foundation technology platforms such as Cisco networking, VMware virtualization, and major Linux distros. Progent's cybersecurity experts have earned prestigious certifications including CISM, CISSP, and CRISC. (See certifications earned by Progent consultants). Progent also offers top-tier support in financial management and ERP applications. This broad array of skills allows Progent to identify and consolidate the surviving parts of your information system after a ransomware intrusion and reconstruct them rapidly into a viable network. Progent has collaborated with leading insurance carriers including Chubb to help businesses clean up after ransomware attacks.
Contact Progent about Ransomware Forensics Analysis Services in Morgan Hill
To learn more information about ways Progent can assist your Morgan Hill organization with ransomware forensics investigation, call 1-800-462-8800 or see Contact Progent.