Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options. Use immediately after discovering ransomware encryption, when scoping the incident forensically, or when documenting evidence for law enforcement and insurance claims.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options. Use immediately after discovering ransomware encryption, when scoping the incident forensically, or when documenting evidence for law enforcement and insurance claims.
{"version":"1.1","tactics":["initial-access","stealth","monetization"],"techniques":[{"id":"T1110","name":"Brute Force","tactic":"initial-access","source":"attack"},{"id":"T1660","name":"Phishing","tactic":"initial-access","source":"attack"},{"id":"T1070","name":"Indicator Removal","tactic":"stealth","source":"attack"},{"id":"F1018","name":"Convert to Cryptocurrency","tactic":"monetization","source":"f3"},{"id":"F1017.001","name":"Conversion to Physical Monetary Instruments: Cash","tactic":"monetization","source":"f3"}]}
Investigating Ransomware Attack Artifacts
When to Use
Immediately after discovering ransomware encryption on systems
When performing forensic analysis to understand the full scope of a ransomware incident
For identifying the ransomware variant and determining if decryption is possible
When tracing the attack chain from initial access to encryption
For documenting evidence to support law enforcement and insurance claims
Prerequisites
Forensic images of affected systems (preserve before remediation)
Memory dumps captured before system shutdown (if available)
Ransom notes and encrypted file samples
Network traffic captures from the attack period
Windows Event Logs, Prefetch files, and registry hives
Access to ransomware identification tools (ID Ransomware, No More Ransom)
Isolated sandbox environment for malware analysis
Workflow
Step 1: Preserve Evidence and Identify the Ransomware Variant
Pattern matching for ransomware variant identification
Any.Run/Joe Sandbox
Online malware sandboxes for ransomware behavior analysis
Capa
Mandiant tool identifying malware capabilities from static analysis
Common Scenarios
Scenario 1: LockBit Attack via RDP
Trace initial access through RDP brute force in event logs, identify attacker IP and compromised account, follow lateral movement through network logons, find LockBit deployment via PsExec or GPO, document encryption timeline from file timestamps, check for data exfiltration before encryption.
Scenario 2: Phishing-Initiated Ransomware
Trace phishing email through browser history and email artifacts, identify malicious attachment execution in Prefetch, follow Cobalt Strike beacon communication in network logs, trace privilege escalation and domain compromise, document ransomware deployment across the network.
Scenario 3: Supply Chain Ransomware Attack
Identify the compromised software update mechanism, trace the malicious update distribution in application logs, analyze the ransomware payload delivered via the trusted channel, assess which systems received the update, determine if the vendor was notified.
Scenario 4: Recovery from Partial Encryption
Determine which systems and files were encrypted before containment, check for surviving volume shadow copies, verify backup integrity and restoration capability, attempt memory-based key recovery, contact law enforcement for potential decryptor availability.
Output Format
Ransomware Investigation Summary:
Variant: LockBit 3.0
First Seen: 2024-01-18 02:00:00 UTC
Encryption Duration: 4 hours 23 minutes
Systems Encrypted: 45 out of 200 (containment stopped spread)
Attack Timeline:
2024-01-10 14:32 - RDP brute force from 203.0.113.45 (1,234 attempts)
2024-01-10 15:00 - Successful RDP login as admin_backup
2024-01-12 02:00 - Mimikatz executed (credential dump)
2024-01-12 02:30 - Domain Admin credentials obtained
2024-01-15 03:00 - Data exfiltration (45 GB to 185.x.x.x)
2024-01-18 02:00 - LockBit deployed via PsExec to 45 systems
2024-01-18 06:23 - Encryption completed on affected systems
Recovery Options:
Decryptor: Not available (LockBit 3.0)
Shadow Copies: Deleted on all systems
Backups: Last clean backup 2024-01-09 (9 days of data loss)
Memory Keys: Not recovered (systems rebooted)
IOCs:
Ransomware Hash: a1b2c3d4e5f6...
C2 IP: 185.x.x.x
Bitcoin: bc1q...
Tor: http://lockbit...onion