Overview of Progent's Ransomware Forensics and Reporting in Nashville
Progent's ransomware forensics experts can preserve the system state after a ransomware attack and perform a detailed forensics investigation without impeding activity related to operational resumption and data recovery. Your Nashville organization can use Progent's post-attack ransomware forensics documentation to block subsequent ransomware attacks, validate the cleanup of lost data, and comply with insurance carrier and regulatory requirements.
Ransomware forensics involves discovering and documenting the ransomware assault's storyline across the targeted network from start to finish. This audit trail of how a ransomware assault travelled within the network helps you to evaluate the impact and uncovers weaknesses in security policies or processes that need to be corrected to prevent later breaches. Forensic analysis is commonly given a top priority by the insurance provider and is often required by government and industry regulations. Since forensics can take time, it is essential that other important recovery processes like operational continuity are executed in parallel. Progent maintains an extensive team of IT and security experts with the skills required to perform the work of containment, operational resumption, and data restoration without disrupting forensic analysis.
Ransomware forensics is complicated and calls for close interaction with the groups responsible for file cleanup and, if needed, settlement talks with the ransomware adversary. Ransomware forensics typically involve the review of logs, registry, Group Policy Object, Active Directory, DNS servers, routers, firewalls, scheduled tasks, and core Windows systems to look for changes.
Activities associated with forensics analysis include:
- Detach without shutting down all possibly affected devices from the system. This can involve closing all Remote Desktop Protocol (RDP) ports and Internet connected NAS storage, modifying admin credentials and user PWs, and setting up two-factor authentication to guard your backups.
- Create forensically complete digital images of all suspect devices so the data recovery group can get started
- Preserve firewall, virtual private network, and other key logs as quickly as possible
- Determine the variety of ransomware involved in the assault
- Survey each computer and storage device on the network including cloud storage for indications of encryption
- Catalog all encrypted devices
- Establish the kind of ransomware involved in the attack
- Review logs and sessions to determine the timeline of the ransomware attack and to spot any potential sideways migration from the first infected machine
- Identify the attack vectors exploited to perpetrate the ransomware attack
- Search for the creation of executables associated with the first encrypted files or network compromise
- Parse Outlook web archives
- Examine email attachments
- Extract URLs embedded in messages and determine if they are malware
- Provide comprehensive incident documentation to meet your insurance carrier and compliance requirements
- List recommended improvements to close security vulnerabilities and enforce processes that lower the risk of a future ransomware exploit
Progent's Background
Progent has provided remote and on-premises IT services throughout the U.S. for over two decades and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have been awarded high-level certifications in core technology platforms such as Cisco infrastructure, VMware virtualization, and popular distributions of Linux. Progent's cybersecurity consultants have earned industry-recognized certifications including CISM, CISSP, and GIAC. (See Progent's certifications). Progent also offers top-tier support in financial and Enterprise Resource Planning software. This breadth of skills allows Progent to identify and consolidate the undamaged pieces of your IT environment after a ransomware assault and reconstruct them rapidly into an operational system. Progent has worked with top insurance providers including Chubb to help businesses recover from ransomware assaults.
Contact Progent about Ransomware Forensics Services in Nashville
To find out more information about how Progent can help your Nashville business with ransomware forensics analysis, call 1-800-462-8800 or see Contact Progent.