Overview of Progent's Ransomware Forensics and Reporting Services in Salt Lake City
Progent's ransomware forensics experts can save the evidence of a ransomware assault and perform a comprehensive forensics investigation without interfering with the processes required for operational continuity and data recovery. Your Salt Lake City organization can utilize Progent's forensics documentation to combat subsequent ransomware assaults, assist in the cleanup of lost data, and comply with insurance carrier and regulatory reporting requirements.
Ransomware forensics involves tracking and describing the ransomware attack's storyline throughout the network from beginning to end. This audit trail of the way a ransomware assault travelled within the network helps your IT staff to assess the impact and uncovers shortcomings in security policies or work habits that should be corrected to avoid future break-ins. Forensic analysis is typically given a high priority by the cyber insurance carrier and is typically required by government and industry regulations. Because forensic analysis can be time consuming, it is vital that other important activities like operational resumption are executed concurrently. Progent has a large team of IT and security experts with the skills needed to carry out the work of containment, operational continuity, and data recovery without disrupting forensic analysis.
Ransomware forensics is complicated and requires close cooperation with the teams assigned to data cleanup and, if needed, payment negotiation with the ransomware threat actor. forensics typically require the examination of all logs, registry, Group Policy Object (GPO), Active Directory, DNS servers, routers, firewalls, schedulers, and core Windows systems to look for variations.
Activities involved with forensics investigation include:
- Isolate but avoid shutting off all possibly suspect devices from the network. This may require closing all RDP ports and Internet connected NAS storage, modifying admin credentials and user passwords, and configuring two-factor authentication to guard backups.
- Preserve forensically sound duplicates of all exposed devices so the file recovery team can get started
- Preserve firewall, virtual private network, and additional critical logs as quickly as possible
- Establish the type of ransomware involved in the attack
- Survey each computer and storage device on the network including cloud storage for signs of encryption
- Inventory all encrypted devices
- Establish the kind of ransomware involved in the assault
- Study log activity and user sessions in order to establish the timeline of the ransomware attack and to spot any possible sideways migration from the first compromised system
- Understand the attack vectors exploited to carry out the ransomware assault
- Look for the creation of executables surrounding the first encrypted files or system breach
- Parse Outlook PST files
- Analyze email attachments
- Extract any URLs from messages and check to see whether they are malicious
- Produce extensive incident documentation to satisfy your insurance carrier and compliance regulations
- Suggest recommended improvements to shore up security gaps and enforce processes that reduce the exposure to a future ransomware breach
Progent's Qualifications
Progent has provided remote and on-premises IT services throughout the U.S. for more than two decades and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's roster of SMEs includes consultants who have earned high-level certifications in foundation technologies including Cisco networking, VMware, and popular distributions of Linux. Progent's data security consultants have earned industry-recognized certifications including CISM, CISSP, and GIAC. (See Progent's certifications). Progent also offers guidance in financial management and Enterprise Resource Planning applications. This broad array of skills gives Progent the ability to salvage and consolidate the surviving pieces of your IT environment after a ransomware intrusion and rebuild them rapidly into a functioning network. Progent has collaborated with leading cyber insurance carriers including Chubb to assist organizations clean up after ransomware assaults.
Contact Progent about Ransomware Forensics Investigation Expertise in Salt Lake City
To learn more information about how Progent can assist your Salt Lake City organization with ransomware forensics analysis, call 1-800-462-8800 or visit Contact Progent.