Overview of Progent's Ransomware Forensics Investigation and Reporting in Shreveport
Progent's ransomware forensics experts can save the system state after a ransomware assault and perform a comprehensive forensics analysis without interfering with activity required for business continuity and data restoration. Your Shreveport organization can use Progent's forensics report to combat future ransomware attacks, validate the cleanup of lost data, and comply with insurance carrier and governmental reporting requirements.
Ransomware forensics investigation is aimed at determining and describing the ransomware assault's storyline across the targeted network from start to finish. This history of how a ransomware assault progressed through the network helps your IT staff to assess the damage and uncovers weaknesses in policies or work habits that should be rectified to avoid future break-ins. Forensic analysis is typically given a top priority by the cyber insurance provider and is often mandated by government and industry regulations. Since forensic analysis can be time consuming, it is vital that other key activities such as operational resumption are executed concurrently. Progent maintains an extensive roster of IT and security experts with the knowledge and experience needed to perform the work of containment, business continuity, and data recovery without interfering with forensic analysis.
Ransomware forensics investigation is complex and requires intimate cooperation with the teams assigned to data cleanup and, if necessary, settlement negotiation with the ransomware adversary. Ransomware forensics can involve the examination of logs, registry, GPO, Active Directory (AD), DNS, routers, firewalls, schedulers, and core Windows systems to look for anomalies.
Services involved with forensics investigation include:
- Disconnect but avoid shutting down all potentially suspect devices from the network. This may involve closing all RDP ports and Internet facing network-attached storage, modifying admin credentials and user PWs, and implementing 2FA to secure backups.
- Copy forensically sound images of all suspect devices so your file recovery team can get started
- Preserve firewall, virtual private network, and other critical logs as soon as possible
- Establish the version of ransomware used in the assault
- Survey every machine and data store on the network including cloud-hosted storage for signs of compromise
- Inventory all compromised devices
- Establish the kind of ransomware involved in the attack
- Review logs and sessions to establish the timeline of the ransomware assault and to identify any potential sideways migration from the first infected system
- Identify the security gaps exploited to carry out the ransomware attack
- Search for new executables surrounding the first encrypted files or system breach
- Parse Outlook PST files
- Analyze email attachments
- Separate any URLs embedded in email messages and determine if they are malicious
- Produce extensive attack reporting to meet your insurance and compliance mandates
- Suggest recommendations to close cybersecurity vulnerabilities and enforce processes that lower the risk of a future ransomware exploit
Progent's Background
Progent has provided remote and on-premises IT services across the U.S. for over 20 years and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have earned high-level certifications in foundation technology platforms such as Cisco networking, VMware virtualization, and major distributions of Linux. Progent's cybersecurity experts have earned prestigious certifications including CISM, CISSP-ISSAP, and GIAC. (See certifications earned by Progent consultants). Progent also offers top-tier support in financial management and ERP software. This scope of expertise gives Progent the ability to identify and integrate the undamaged parts of your information system following a ransomware attack and reconstruct them quickly into an operational network. Progent has collaborated with top insurance providers including Chubb to help businesses clean up after ransomware assaults.
Contact Progent about Ransomware Forensics Investigation Expertise in Shreveport
To learn more about how Progent can help your Shreveport business with ransomware forensics, call 1-800-462-8800 or visit Contact Progent.