logo

The Role of Endpoint Forensics in Ransomware Investigations

ID: d6202051-8b28-5b61-8b01-ee5a35f2f2b0

STIX ID: report--d6202051-8b28-5b61-8b01-ee5a35f2f2b0

Feed Name: Fidelis Security

Threat Score
70/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Sarika Sharma

...
...

The report outlines a full staged ransomware operation on endpoints, covering persistence via registry changes, credential extraction with tools like Mimikatz, network mapping, lateral movement using RDP or PsExec, data staging and exfiltration, disabling security tools, and deletion of shadow copies; it emphasizes that each phase leaves forensic artifacts investigators can recover to reconstruct the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.