Overview of Progent's Ransomware Forensics Analysis and Reporting Services in Campinas
Progent's ransomware forensics consultants can preserve the evidence of a ransomware assault and carry out a comprehensive forensics analysis without disrupting the processes related to business resumption and data restoration. Your Campinas organization can use Progent's post-attack forensics documentation to combat future ransomware assaults, validate the recovery of encrypted data, and comply with insurance carrier and regulatory reporting requirements.
Ransomware forensics analysis involves discovering and documenting the ransomware attack's storyline throughout the network from beginning to end. This audit trail of the way a ransomware attack travelled through the network helps your IT staff to evaluate the impact and uncovers weaknesses in policies or work habits that need to be rectified to avoid later breaches. Forensic analysis is usually given a high priority by the insurance carrier and is often required by state and industry regulations. Because forensic analysis can take time, it is essential that other key activities like business resumption are performed in parallel. Progent has a large roster of IT and security professionals with the skills needed to carry out activities for containment, business continuity, and data restoration without interfering with forensic analysis.
Ransomware forensics analysis is complicated and calls for close cooperation with the teams responsible for file cleanup and, if needed, settlement talks with the ransomware adversary. Ransomware forensics typically require the examination of all logs, registry, GPO, AD, DNS servers, routers, firewalls, schedulers, and basic Windows systems to detect changes.
Activities associated with forensics analysis include:
- Isolate but avoid shutting down all potentially suspect devices from the system. This can require closing all RDP ports and Internet connected NAS storage, modifying admin credentials and user PWs, and configuring 2FA to protect backups.
- Create forensically valid digital images of all exposed devices so your file recovery team can get started
- Save firewall, VPN, and other critical logs as soon as feasible
- Identify the version of ransomware involved in the attack
- Inspect each computer and storage device on the system as well as cloud-hosted storage for signs of compromise
- Catalog all compromised devices
- Establish the type of ransomware involved in the assault
- Study log activity and sessions in order to determine the time frame of the ransomware assault and to identify any possible lateral movement from the originally compromised machine
- Identify the attack vectors used to carry out the ransomware assault
- Look for new executables associated with the original encrypted files or system breach
- Parse Outlook web archives
- Examine email attachments
- Separate URLs from messages and determine if they are malicious
- Provide comprehensive incident reporting to meet your insurance carrier and compliance mandates
- Document recommended improvements to shore up security gaps and improve processes that lower the exposure to a future ransomware exploit
Progent's Background
Progent has delivered remote and on-premises network services throughout the United States for over 20 years and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of SMEs includes professionals who have earned high-level certifications in foundation technologies including Cisco networking, VMware, and major Linux distros. Progent's data security consultants have earned prestigious certifications such as CISA, CISSP, and CRISC. (See Progent's certifications). Progent also has top-tier support in financial and ERP applications. This broad array of skills allows Progent to identify and integrate the undamaged pieces of your network following a ransomware assault and rebuild them rapidly into a functioning system. Progent has worked with top cyber insurance carriers including Chubb to help businesses recover from ransomware assaults.
Contact Progent about Ransomware Forensics Services in Campinas
To learn more about how Progent can assist your Campinas business with ransomware forensics, call 1-800-462-8800 or visit Contact Progent.