Overview of Progent's Ransomware Forensics Analysis and Reporting in Fresno
Progent's ransomware forensics consultants can capture the system state after a ransomware assault and carry out a comprehensive forensics investigation without interfering with activity required for operational continuity and data recovery. Your Fresno business can utilize Progent's ransomware forensics documentation to combat subsequent ransomware assaults, validate the recovery of lost data, and comply with insurance and regulatory mandates.
Ransomware forensics analysis involves determining and documenting the ransomware attack's progress throughout the network from beginning to end. This history of how a ransomware attack progressed within the network assists you to assess the damage and brings to light gaps in policies or work habits that should be corrected to prevent future break-ins. Forensic analysis is usually assigned a top priority by the cyber insurance carrier and is typically required by state and industry regulations. Because forensics can take time, it is critical that other important recovery processes such as business resumption are performed concurrently. Progent has an extensive team of information technology and data security experts with the skills needed to perform activities for containment, operational resumption, and data recovery without interfering with forensics.
Ransomware forensics is time consuming and calls for intimate interaction with the groups responsible for file cleanup and, if needed, settlement talks with the ransomware attacker. forensics typically involve the review of logs, registry, GPO, AD, DNS servers, routers, firewalls, scheduled tasks, and core Windows systems to look for anomalies.
Activities involved with forensics investigation include:
- Disconnect without shutting off all possibly suspect devices from the network. This can require closing all RDP ports and Internet connected network-attached storage, modifying admin credentials and user PWs, and setting up two-factor authentication to guard backups.
- Create forensically sound digital images of all suspect devices so your data recovery group can get started
- Preserve firewall, VPN, and additional critical logs as quickly as possible
- Determine the variety of ransomware involved in the assault
- Survey every computer and storage device on the system including cloud-hosted storage for signs of encryption
- Catalog all encrypted devices
- Determine the type of ransomware used in the assault
- Review log activity and user sessions to establish the timeline of the assault and to spot any possible sideways migration from the originally infected machine
- Identify the security gaps used to perpetrate the ransomware assault
- Look for new executables associated with the original encrypted files or system compromise
- Parse Outlook web archives
- Analyze attachments
- Extract URLs from messages and check to see whether they are malicious
- Produce extensive attack reporting to meet your insurance carrier and compliance mandates
- List recommended improvements to close cybersecurity vulnerabilities and improve processes that lower the risk of a future ransomware breach
Progent's Background
Progent has provided online and on-premises network services across the U.S. for over 20 years and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity competencies. Progent's team of SMEs includes consultants who have earned advanced certifications in core technology platforms such as Cisco networking, VMware virtualization, and popular Linux distros. Progent's data security consultants have earned internationally recognized certifications including CISM, CISSP, and CRISC. (Refer to certifications earned by Progent consultants). Progent also offers guidance in financial management and Enterprise Resource Planning applications. This breadth of skills allows Progent to salvage and consolidate the undamaged pieces of your network after a ransomware intrusion and reconstruct them rapidly into a functioning system. Progent has worked with leading cyber insurance carriers including Chubb to assist businesses recover from ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Fresno
To learn more about how Progent can help your Fresno organization with ransomware forensics analysis, call 1-800-462-8800 or see Contact Progent.