Incident Response Ransomware Series - Part 3
ID: e6417326-1df8-51b1-aab9-e4767680a702
STIX ID: report--e6417326-1df8-51b1-aab9-e4767680a702
Feed Name: TrustedSec blog
This blog post outlines an incident response and recovery playbook for ransomware: detect and contain infected hosts quickly (isolation, NAC, EDR quarantine, or shutdown), gather forensic data while balancing volatile evidence loss, eradicate malware via reimaging or manual/automated removal, recover systems from known-good backups or use decryption tools if available, and consider organizational policies and risks before paying ransoms. It emphasizes preventative measures, forensic analysis to determine root cause and additional malware, and executive-level preparation for ransom decisions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
