Skip to content

What about forensics when ransomware hits?

Forensics starts with not doing things. Do not power off, do not clean up, do not reinstall. The value is in memory dumps, log snapshots and file-system images as they are right now. Reboot wipes most.

Try this first

  1. 1Pull the network cable or disable Wi-Fi on infected devices rather than powering them off. Hibernate or shutdown wipes memory where the attacker tools live.
  2. 2Call cyber insurance or the IR retainer before doing anything else. They send someone with the right tools (FTK Imager, KAPE, Velociraptor) and the legal track to preserve evidence for insurance and police.
  3. 3Preserve logs now, not in an hour. Defender for Endpoint, Sentinel, firewall, AD events, mail server. Default rotation can wipe within 24 hours. Snapshot Log Analytics to a separate storage account.
  4. 4Take full-disk images of infected systems where possible, or at least a memory dump with DumpIt or Belkasoft RAM Capturer. On SSDs that is quick, on HDD servers plan a couple of hours.
  5. 5Keep a timeline with who did what when, from minute zero. Tools, IPs, accounts, decisions. The forensic investigator gets two days of work back if your timeline is clean.

When to bring us in

Production or customer files are down and pressure rises to be back fast, do not let pressure justify destroying evidence. Agree a sequence with the IR partner, image first, then restore. Otherwise the insurance claim is half-supportable.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.