Progent's Ransomware Forensics Investigation and Reporting Services in Mexico City
Progent's ransomware forensics experts can capture the evidence of a ransomware assault and perform a comprehensive forensics analysis without interfering with activity required for operational resumption and data restoration. Your Mexico City business can utilize Progent's forensics report to counter future ransomware attacks, assist in the recovery of encrypted data, and meet insurance carrier and governmental mandates.
Ransomware forensics analysis is aimed at determining and documenting the ransomware attack's progress throughout the targeted network from start to finish. This audit trail of the way a ransomware attack travelled through the network assists your IT staff to assess the impact and uncovers shortcomings in policies or processes that need to be corrected to prevent future breaches. Forensic analysis is usually given a top priority by the insurance carrier and is often required by state and industry regulations. Since forensic analysis can take time, it is vital that other important recovery processes like business resumption are performed in parallel. Progent has an extensive team of information technology and cybersecurity experts with the skills required to carry out the work of containment, business continuity, and data recovery without disrupting forensic analysis.
Ransomware forensics is complicated and requires intimate interaction with the teams assigned to file cleanup and, if necessary, settlement talks with the ransomware threat actor. Ransomware forensics typically require the review of logs, registry, Group Policy Object, Active Directory (AD), DNS, routers, firewalls, schedulers, and core Windows systems to check for changes.
Activities associated with forensics investigation include:
- Isolate without shutting off all possibly suspect devices from the network. This can involve closing all Remote Desktop Protocol (RDP) ports and Internet connected NAS storage, modifying admin credentials and user passwords, and configuring two-factor authentication to protect backups.
- Copy forensically valid digital images of all exposed devices so the file restoration group can proceed
- Save firewall, virtual private network, and other critical logs as soon as possible
- Establish the type of ransomware involved in the attack
- Survey every machine and storage device on the system as well as cloud-hosted storage for indications of encryption
- Catalog all compromised devices
- Establish the kind of ransomware involved in the attack
- Study log activity and user sessions to determine the time frame of the assault and to spot any possible sideways migration from the first infected system
- Identify the attack vectors used to carry out the ransomware assault
- Look for the creation of executables associated with the first encrypted files or system compromise
- Parse Outlook web archives
- Analyze attachments
- Separate any URLs from email messages and determine whether they are malicious
- Provide extensive incident documentation to satisfy your insurance carrier and compliance requirements
- Document recommendations to close security gaps and improve workflows that reduce the risk of a future ransomware exploit
Progent's Background
Progent has provided online and on-premises network services throughout the U.S. for over 20 years and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity practice areas. Progent's roster of SMEs includes consultants who have been awarded advanced certifications in foundation technology platforms such as Cisco networking, VMware virtualization, and major distributions of Linux. Progent's data security consultants have earned internationally recognized certifications including CISM, CISSP-ISSAP, and GIAC. (See Progent's certifications). Progent also offers guidance in financial and Enterprise Resource Planning application software. This scope of expertise gives Progent the ability to identify and consolidate the undamaged parts of your network after a ransomware attack and reconstruct them rapidly into an operational system. Progent has collaborated with leading insurance carriers including Chubb to assist organizations recover from ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Mexico City
To find out more about how Progent can help your Mexico City organization with ransomware forensics, call 1-800-462-8800 or see Contact Progent.