Progent's Ransomware Forensics Investigation and Reporting in Boston
Progent's ransomware forensics experts can preserve the evidence of a ransomware assault and carry out a detailed forensics investigation without slowing down the processes required for operational continuity and data restoration. Your Boston organization can utilize Progent's post-attack ransomware forensics documentation to block subsequent ransomware assaults, validate the recovery of lost data, and meet insurance and governmental requirements.
Ransomware forensics investigation is aimed at determining and documenting the ransomware attack's progress across the targeted network from start to finish. This history of the way a ransomware attack progressed through the network helps you to evaluate the impact and uncovers vulnerabilities in policies or processes that need to be corrected to avoid later breaches. Forensics is commonly assigned a high priority by the insurance carrier and is typically required by state and industry regulations. Since forensic analysis can take time, it is critical that other key activities such as business resumption are executed in parallel. Progent maintains an extensive team of IT and security experts with the skills needed to carry out activities for containment, business resumption, and data restoration without interfering with forensics.
Ransomware forensics analysis is arduous and calls for intimate cooperation with the teams responsible for file restoration and, if necessary, payment discussions with the ransomware adversary. forensics can involve the examination of logs, registry, Group Policy Object, Active Directory, DNS servers, routers, firewalls, scheduled tasks, and basic Windows systems to detect changes.
Services involved with forensics analysis include:
- Detach but avoid shutting off all potentially impacted devices from the network. This can require closing all Remote Desktop Protocol (RDP) ports and Internet facing NAS storage, changing admin credentials and user PWs, and implementing 2FA to guard backups.
- Preserve forensically valid digital images of all suspect devices so the file recovery team can get started
- Preserve firewall, virtual private network, and additional critical logs as soon as possible
- Determine the variety of ransomware involved in the attack
- Examine each machine and data store on the system including cloud storage for signs of encryption
- Inventory all compromised devices
- Determine the type of ransomware involved in the attack
- Study logs and user sessions in order to establish the time frame of the ransomware attack and to spot any possible lateral movement from the originally compromised machine
- Identify the attack vectors exploited to carry out the ransomware attack
- Search for the creation of executables surrounding the first encrypted files or system breach
- Parse Outlook PST files
- Examine email attachments
- Extract URLs from email messages and determine if they are malicious
- Produce detailed incident documentation to satisfy your insurance carrier and compliance mandates
- List recommended improvements to shore up security vulnerabilities and enforce workflows that lower the risk of a future ransomware exploit
Progent's Qualifications
Progent has provided online and on-premises network services throughout the U.S. for over two decades and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity practice areas. Progent's team of subject matter experts (SMEs) includes consultants who have been awarded advanced certifications in core technologies including Cisco networking, VMware, and major Linux distros. Progent's cybersecurity experts have earned internationally recognized certifications including CISA, CISSP-ISSAP, and CRISC. (See Progent's certifications). Progent also has top-tier support in financial and ERP applications. This scope of expertise gives Progent the ability to salvage and integrate the undamaged parts of your IT environment after a ransomware attack and rebuild them quickly into a functioning network. Progent has collaborated with leading insurance carriers like Chubb to assist organizations recover from ransomware attacks.
Contact Progent about Ransomware Forensics Services in Boston
To find out more about how Progent can help your Boston organization with ransomware forensics investigation, call 1-800-462-8800 or visit Contact Progent.