CySA+ Runbook 06 — Ransomware Incident Response
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook | 06 |
| Runbook Name | Ransomware Incident Response |
| Track | CompTIA CySA+ |
| Difficulty | Advanced |
| Primary Role | SOC Analyst / Cybersecurity Analyst / Incident Responder |
| Purpose | Detect, investigate, contain, eradicate, and support recovery from ransomware incidents |
| Primary Systems | SIEM, EDR/XDR, Identity Provider, Active Directory, Firewall, IDS/IPS, Email Security, Backup Systems |
| Primary Data Sources | EDR Telemetry, Process Logs, Authentication Logs, Windows/Linux Logs, DNS, Network Flows, File Events, Backup Logs |
| Output | False Positive / Attempted Ransomware / Contained Ransomware / Confirmed Ransomware Incident / Enterprise Incident Escalation |
| Related Labs | Lab 13, Lab 16, Lab 17, Lab 18, Lab 20 |
Operational Principle: Ransomware is not simply a malware-removal problem. Modern ransomware incidents may involve identity compromise, privilege escalation, lateral movement, data theft, backup destruction, and encryption. Containment must therefore address endpoints, identities, network access, and recovery infrastructure together.
1. Purpose
Section titled “1. Purpose”This runbook provides a repeatable procedure for responding to suspected ransomware.
The investigation should answer:
What triggered the alert? ↓Is encryption actually occurring? ↓Which host was affected first? ↓What executed the ransomware? ↓Which identity was involved? ↓How did the attacker gain access? ↓Were privileges increased? ↓Did the attacker move laterally? ↓Were backups targeted? ↓Was data stolen? ↓How many systems are affected? ↓Is the threat still active? ↓What must be isolated immediately? ↓How can recovery begin safely?2. When to Use This Runbook
Section titled “2. When to Use This Runbook”Use this runbook when:
-
ransomware is detected by EDR/XDR
-
mass file encryption is observed
-
unusual file-extension changes occur
-
ransom notes appear
-
large numbers of files are renamed
-
shadow copies or recovery mechanisms are unexpectedly modified
-
backup infrastructure is attacked
-
suspicious encryption processes execute
-
multiple endpoints experience simultaneous file modifications
-
network shares experience mass changes
-
destructive malware is suspected
-
known ransomware indicators are detected
-
ransomware-associated threat intelligence matches internal activity
3. Ransomware Response Priorities
Section titled “3. Ransomware Response Priorities”Ransomware response priorities are:
1. Protect People and Critical Operations ↓2. Stop Active Spread ↓3. Protect Identities ↓4. Protect Backups ↓5. Preserve Evidence ↓6. Determine Scope ↓7. Eradicate Threat ↓8. Recover Safely4. Expected Outcomes
Section titled “4. Expected Outcomes”Ransomware Alert ↓Investigation ↓├── False Positive│├── Attempted Ransomware — Blocked│├── Limited Ransomware — Contained│├── Confirmed Ransomware Incident│└── Enterprise-Wide Ransomware Incident5. Ransomware Incident Workflow
Section titled “5. Ransomware Incident Workflow”Alert / Report ↓Validate Activity ↓Identify Initial Affected Host ↓Emergency Isolation ↓Identify Identity ↓Analyze Execution ↓Identify Persistence ↓Investigate Privilege ↓Investigate Lateral Movement ↓Protect Backup Infrastructure ↓Investigate Data Access ↓Assess Exfiltration ↓Determine Enterprise Scope ↓Contain Identities / Systems ↓Preserve Evidence ↓Eradicate ↓Recover ↓Enhanced Monitoring ↓Post-Incident Review6. Step 1 — Record the Initial Alert
Section titled “6. Step 1 — Record the Initial Alert”Capture:
Case ID:
Alert ID:
Detection Time:
Detection Source:
Hostname:
IP Address:
Username:
Process:
Parent Process:
Command Line:
Filename:
File Path:
SHA-256:
Detection Name:
EDR Action:
Affected Files:
Ransom Note:
Severity:7. Step 2 — Determine Whether Activity Is Active
Section titled “7. Step 2 — Determine Whether Activity Is Active”Immediately determine:
Are files currently being encrypted?
Are new hosts generating alerts?
Are network shares changing?
Are suspicious processes still running?
Are malicious identities still authenticated?
Is lateral movement continuing?
Are backups being modified?Classify:
Threat Status:
ActiveContainedHistoricalUnknownActive ransomware requires urgent escalation.
8. Step 3 — Validate Encryption Activity
Section titled “8. Step 3 — Validate Encryption Activity”Look for:
Rapid File Modification
File Renaming
Extension Changes
High File Write Volume
Encryption-Like Behavior
Ransom Notes
Deletion of Originals
Multiple Directories AffectedDo not rely solely on the ransom note.
9. Step 4 — Identify File Extension Changes
Section titled “9. Step 4 — Identify File Extension Changes”Record:
Original Extension:
New Extension:
First Observed:
Affected Directories:
Number of Files:Example:
report.docx ↓report.docx.<unexpected-extension>10. Step 5 — Identify Ransom Notes
Section titled “10. Step 5 — Identify Ransom Notes”Preserve ransom-note artifacts.
Record:
Filename:
Path:
Creation Time:
Creating Process:
Hash:
Content Summary:Do not contact threat actors or follow payment instructions as part of analyst triage.
11. Step 6 — Identify the Initial Affected Endpoint
Section titled “11. Step 6 — Identify the Initial Affected Endpoint”Capture:
Hostname:
IP:
Operating System:
User:
Business Function:
Criticality:
Network Segment:
EDR Status:
First Suspicious Activity:12. Step 7 — Emergency Endpoint Isolation
Section titled “12. Step 7 — Emergency Endpoint Isolation”For active ransomware, follow approved procedures to consider immediate network isolation.
The objective is:
Compromised Endpoint XInternal NetworkIsolation should prevent:
Lateral Movement
Network Share Encryption
C2 Communication
Additional Payload Deliverywhile preserving investigative access where possible.
13. Step 8 — Identify Other Hosts Showing Encryption
Section titled “13. Step 8 — Identify Other Hosts Showing Encryption”Search the SIEM/EDR for:
Same Alert
Same Hash
Same Filename
Same Process
Same Extension
Same Ransom Note
Same Domain
Same IP
Same UserBuild:
| Host | Encryption | Isolation | Status |
|---|---|---|---|
| HOST01 | Confirmed | Yes | Compromised |
| HOST02 | Suspected | Pending | Investigate |
| HOST03 | No | No | Monitor |
14. Step 9 — Identify the Responsible Process
Section titled “14. Step 9 — Identify the Responsible Process”Record:
Process:
PID:
Path:
User:
Start Time:
Parent Process:
Command Line:
SHA-256:Determine which process performed the mass file modifications.
15. Step 10 — Build the Process Tree
Section titled “15. Step 10 — Build the Process Tree”Example:
Email Client ↓Office Application ↓PowerShell ↓Payload ↓Encryption Processor:
Remote Service ↓Command Shell ↓RansomwareEvery relationship should be supported by telemetry.
16. Step 11 — Analyze the Parent Process
Section titled “16. Step 11 — Analyze the Parent Process”Determine:
What launched the ransomware?
Was it user initiated?
Was it launched remotely?
Was it started by a service?
Was it started by a scheduled task?
Was PowerShell involved?17. Step 12 — Analyze Command-Line Activity
Section titled “17. Step 12 — Analyze Command-Line Activity”Review safely for evidence of:
File Enumeration
Network Share Enumeration
Security-Control Changes
Backup Interference
Recovery Interference
Remote Execution
Script Execution
Discovery
Credential-Related ActivityDo not execute suspicious commands discovered during analysis.
18. Step 13 — Investigate PowerShell and Script Activity
Section titled “18. Step 13 — Investigate PowerShell and Script Activity”Review:
PowerShell Operational Logs
Script Block Logging
EDR Process Telemetry
Event ID 4104Look for:
Obfuscation
Encoded Content
Payload Retrieval
Discovery
Remote Administration
Security-Control Changes19. Step 14 — Identify the Malware Artifact
Section titled “19. Step 14 — Identify the Malware Artifact”Capture:
Filename:
Path:
Actual File Type:
Size:
Creation Time:
Execution Time:
SHA-256:Preserve the artifact according to evidence-handling procedures.
20. Step 15 — Enrich the Hash
Section titled “20. Step 15 — Enrich the Hash”Using approved threat-intelligence sources, determine:
Known / Unknown:
Classification:
Malware Family:
Ransomware Family:
First Seen:
Last Seen:
Associated Infrastructure:
Confidence:Remember:
Unknown Hash≠Benign21. Step 16 — Investigate Delivery Method
Section titled “21. Step 16 — Investigate Delivery Method”Potential sources include:
Phishing
Malicious Attachment
Malicious Download
Compromised Credentials
Remote Access
Public-Facing Application
Third-Party Access
Software Supply Chain
Removable Media
UnknownDo not assign initial access without supporting evidence.
22. Step 17 — Investigate Phishing
Section titled “22. Step 17 — Investigate Phishing”If email is suspected, review:
Sender
Recipient
Subject
URLs
Attachments
Message-ID
Delivery Scope
User InteractionUse the phishing investigation workflow where necessary.
23. Step 18 — Investigate Remote Access
Section titled “23. Step 18 — Investigate Remote Access”Review:
VPN
RDP
SSH
Remote Support Tools
Remote Administration PlatformsLook for unusual:
Source IP
Device
Location
Time
Identity
Session Duration24. Step 19 — Investigate Authentication Activity
Section titled “24. Step 19 — Investigate Authentication Activity”Search for:
Failed Logins
Successful Logins
New Source IPs
New Devices
Privileged Logons
Service Account Usage
Remote Interactive Sessions
MFA EventsBuild identity context around the earliest suspicious activity.
25. Step 20 — Identify Compromised Identities
Section titled “25. Step 20 — Identify Compromised Identities”Create:
| Identity | Evidence | Privilege | Status |
|---|---|---|---|
| user01 | Suspicious login | User | Suspected |
| admin01 | Remote activity | Admin | Investigate |
| svc01 | Unexpected host usage | Service | Investigate |
26. Step 21 — Investigate Privilege Escalation
Section titled “26. Step 21 — Investigate Privilege Escalation”Determine whether:
A standard user became privilegedor:
An already-privileged account was compromisedLook for:
Group Membership Changes
Privileged Logons
New Admin Accounts
Token/Session Abuse
Unexpected SYSTEM/root Activity27. Step 22 — Investigate Account Creation
Section titled “27. Step 22 — Investigate Account Creation”Review unexpected new accounts.
For Windows environments, relevant evidence may include:
Event ID 4720Capture:
Account:
Created By:
Host:
Timestamp:
Privileges:28. Step 23 — Investigate Persistence
Section titled “28. Step 23 — Investigate Persistence”Look for:
Scheduled Tasks
Services
Registry Autoruns
Startup Items
New Accounts
Remote Management Tools
Cron Jobs
Systemd ServicesRansomware may be the final visible stage of a longer compromise.
29. Step 24 — Investigate Security-Control Tampering
Section titled “29. Step 24 — Investigate Security-Control Tampering”Look for attempts to:
Disable EDR
Disable Antivirus
Add Security Exclusions
Stop Logging
Modify Firewall
Stop Security ServicesSecurity-control tampering should significantly increase concern.
30. Step 25 — Investigate Recovery-Control Interference
Section titled “30. Step 25 — Investigate Recovery-Control Interference”Determine whether recovery mechanisms were:
Disabled
Deleted
Modified
Made Unavailable
Tampered WithReview evidence involving:
Snapshots
Restore Points
Backup Agents
Recovery Services
Backup Repositories31. Step 26 — Protect Backup Infrastructure
Section titled “31. Step 26 — Protect Backup Infrastructure”Immediately determine whether the attacker can access:
Backup Servers
Backup Consoles
Backup Repositories
Cloud Backup Accounts
Recovery CredentialsProtect them using approved procedures.
The objective is:
Compromised Environment XRecovery Infrastructure32. Step 27 — Validate Backup Status
Section titled “32. Step 27 — Validate Backup Status”Record:
Backup Platform:
Last Known Good Backup:
Backup Integrity:
Offline / Immutable Copy:
Backup Account Status:
Suspicious Backup Activity:Do not begin restoration until the threat has been sufficiently contained.
33. Step 28 — Investigate Network Shares
Section titled “33. Step 28 — Investigate Network Shares”Review:
SMB Shares
Mapped Drives
File Servers
NAS Systems
Shared Application StorageLook for:
Mass File Changes
Remote File Encryption
Unusual SMB Activity
Large Numbers of File Operations34. Step 29 — Identify Network-Share Source
Section titled “34. Step 29 — Identify Network-Share Source”Determine which endpoint and identity performed suspicious file operations.
Build:
Compromised Endpoint ↓Compromised Identity ↓SMB ↓File Server ↓Mass Encryption35. Step 30 — Investigate Lateral Movement
Section titled “35. Step 30 — Investigate Lateral Movement”Review:
RDP
SMB
SSH
WinRM
Remote Services
Administrative Shares
Remote Management ToolsCapture:
Source:
Destination:
Identity:
Protocol:
Timestamp:
Outcome:36. Step 31 — Correlate Authentication with Lateral Movement
Section titled “36. Step 31 — Correlate Authentication with Lateral Movement”Stronger evidence follows:
Network Connection +Authentication +Remote Execution =Likely Lateral MovementDo not classify every internal connection as compromise.
37. Step 32 — Investigate Domain Controller Activity
Section titled “37. Step 32 — Investigate Domain Controller Activity”If Active Directory exists, determine whether domain controllers were:
Accessed
Authenticated To
Modified
Used for Privileged Operations
Targeted by MalwareDomain-controller compromise should trigger critical escalation.
38. Step 33 — Investigate Privileged Accounts
Section titled “38. Step 33 — Investigate Privileged Accounts”Prioritize:
Domain Admins
Enterprise Admins
Local Administrators
Cloud Administrators
Backup Administrators
Security AdministratorsDetermine whether any privileged credentials were used from compromised systems.
39. Step 34 — Investigate Credential Access
Section titled “39. Step 34 — Investigate Credential Access”Look for evidence of:
Credential-Dumping Alerts
Authentication Process Access
Browser Credential Access
Token Theft
Password Store Access
Unusual Credential ToolsClassify:
Credential Access:
ConfirmedSuspectedNot ObservedUnknown40. Step 35 — Investigate Discovery Activity
Section titled “40. Step 35 — Investigate Discovery Activity”Look for evidence of:
Host Discovery
Network Discovery
Domain Discovery
User Discovery
Group Discovery
Share Discovery
Backup Discovery
Security-Tool DiscoveryThis activity can help reconstruct attacker preparation.
41. Step 36 — Investigate Data Collection
Section titled “41. Step 36 — Investigate Data Collection”Modern ransomware incidents may include data theft before encryption.
Look for:
Sensitive File Access
Large Directory Enumeration
File Copying
Database Access
Shared Drive Access
Archive Creation42. Step 37 — Investigate Archive Creation
Section titled “42. Step 37 — Investigate Archive Creation”Review unexpected creation of:
ZIP
7z
RAR
tar
gzipRecord:
Archive:
Created By:
Source Files:
Size:
Timestamp:
Destination:Archive creation indicates possible staging, not proof of exfiltration.
43. Step 38 — Investigate Potential Exfiltration
Section titled “43. Step 38 — Investigate Potential Exfiltration”Search:
Proxy Logs
Firewall Logs
Zeek
EDR Network Telemetry
Cloud Audit Logsfor:
Large Outbound Transfers
Rare External Destinations
Cloud Storage Uploads
File Transfer Services
Long-Lived Sessions
Unusual HTTPS Uploads44. Step 39 — Distinguish Encryption from Data Theft
Section titled “44. Step 39 — Distinguish Encryption from Data Theft”Track separately:
Encryption:Confirmed / Suspected / Not Observed
Data Exfiltration:Confirmed / Suspected / Not Observed / UnknownDo not assume encryption proves exfiltration.
Do not assume absence of encryption means data was not stolen.
45. Step 40 — Investigate DNS and External Communication
Section titled “45. Step 40 — Investigate DNS and External Communication”Review:
DNS Queries
External Domains
External IPs
C2 Indicators
Payload InfrastructureCorrelate with the ransomware execution timeline.
46. Step 41 — Identify Command-and-Control
Section titled “46. Step 41 — Identify Command-and-Control”Look for:
Known Malicious Infrastructure
Repeated External Connections
Rare Domains
Beaconing
Connections from Suspicious ProcessesClassify:
C2:
ConfirmedSuspectedNot ObservedUnknown47. Step 42 — Build the IOC Inventory
Section titled “47. Step 42 — Build the IOC Inventory”Create:
| Type | Indicator | Source | Confidence |
|---|---|---|---|
| Hash | <SHA-256> |
EDR | High |
| File | <filename> |
Endpoint | High |
| Domain | <domain> |
DNS | Medium/High |
| IP | <IP> |
Network | Medium/High |
| Ransom Note | <filename> |
Endpoint | High |
| Extension | <extension> |
File Events | Medium |
| Registry | <key> |
Endpoint | Medium |
48. Step 43 — Hunt Across the Enterprise
Section titled “48. Step 43 — Hunt Across the Enterprise”Search for:
Malware Hash
Filename
Ransom Note
File Extension
Domain
IP
Process
Command-Line Pattern
Persistence Mechanism
Compromised Identityacross:
EDR
SIEM
DNS
Firewall
Email
Identity
Servers
Cloud Workloads49. Step 44 — Hunt Behavioral Indicators
Section titled “49. Step 44 — Hunt Behavioral Indicators”Static IOCs may change.
Also search for:
Mass File Modification
High File Rename Volume
Recovery Tampering
Backup Interference
Security-Control Disabling
Unusual Remote Execution
Share Enumeration
Archive Creation50. Step 45 — Determine the Initial Compromise Time
Section titled “50. Step 45 — Determine the Initial Compromise Time”Do not use encryption time as the beginning of the incident.
Example:
Day 1 — Credential compromise
Day 2 — Discovery
Day 3 — Privilege escalation
Day 4 — Lateral movement
Day 5 — Data collection
Day 6 — EncryptionRansomware may be the final stage of a multi-day intrusion.
51. Step 46 — Build the Master Timeline
Section titled “51. Step 46 — Build the Master Timeline”Create:
| Time | Event | Host / Identity | Evidence |
|---|---|---|---|
| 01:15 | Suspicious login | user01 | Identity |
| 01:27 | Internal discovery | HOST01 | EDR |
| 01:45 | Privileged login | admin01 | Security Log |
| 02:10 | Remote connection | HOST01 → SERVER01 | Network |
| 02:40 | Archive created | SERVER01 | EDR |
| 03:05 | External transfer | SERVER01 | Firewall |
| 04:00 | Encryption begins | Multiple | EDR |
| 04:02 | Ransom note created | Multiple | File Events |
52. Step 47 — Determine Initial Access
Section titled “52. Step 47 — Determine Initial Access”Classify only with evidence:
Phishing
Compromised Credentials
Remote Access
Exploited Application
Third-Party Access
Malicious Download
Supply Chain
Unknown53. Step 48 — Reconstruct the Ransomware Attack Story
Section titled “53. Step 48 — Reconstruct the Ransomware Attack Story”Example:
Compromised Credentials ↓Remote Access ↓Discovery ↓Privilege Escalation ↓Credential Access ↓Lateral Movement ↓Backup Discovery ↓Data Collection ↓Potential Exfiltration ↓Security-Control Tampering ↓Ransomware Deployment ↓EncryptionEvery stage should have supporting evidence.
54. Step 49 — Map Activity to MITRE ATT&CK
Section titled “54. Step 49 — Map Activity to MITRE ATT&CK”Create:
| Tactic | Observed Behavior | Evidence |
|---|---|---|
| Initial Access | <behavior> |
<source> |
| Execution | <behavior> |
<source> |
| Persistence | <behavior> |
<source> |
| Privilege Escalation | <behavior> |
<source> |
| Defense Evasion | <behavior> |
<source> |
| Credential Access | <behavior> |
<source> |
| Discovery | <behavior> |
<source> |
| Lateral Movement | <behavior> |
<source> |
| Collection | <behavior> |
<source> |
| C2 | <behavior> |
<source> |
| Exfiltration | <behavior> |
<source> |
| Impact | File encryption | <source> |
55. Step 50 — Determine Endpoint Scope
Section titled “55. Step 50 — Determine Endpoint Scope”Classify every relevant host:
Confirmed Compromised
Suspected Compromised
Encrypted
Exposed / Contacted
Unaffected
UnknownExample:
| Host | Status | Evidence |
|---|---|---|
| WS01 | Confirmed Compromised | Malware execution |
| FS01 | Encrypted | Mass file changes |
| DC01 | Suspected | Privileged connection |
| WS02 | Exposed | Network contact only |
56. Step 51 — Determine Identity Scope
Section titled “56. Step 51 — Determine Identity Scope”Classify:
Confirmed Compromised
Suspected Compromised
Used on Compromised Endpoint
Privileged Exposure
Unaffected
UnknownPrioritize privileged identities.
57. Step 52 — Determine Data Scope
Section titled “57. Step 52 — Determine Data Scope”Identify:
Files Accessed
Directories Accessed
Shares Accessed
Databases Accessed
Archives Created
Potentially Transferred Data
Sensitive Data Categories58. Step 53 — Determine Backup Scope
Section titled “58. Step 53 — Determine Backup Scope”Identify:
Backup Servers Affected:
Repositories Affected:
Backup Accounts Affected:
Snapshots Deleted:
Backup Jobs Modified:
Immutable Copies Available:59. Step 54 — Assess Confidentiality Impact
Section titled “59. Step 54 — Assess Confidentiality Impact”Ask:
Was sensitive data accessed?
Was data staged?
Was data transferred externally?
Were credentials exposed?
Were privileged credentials involved?60. Step 55 — Assess Integrity Impact
Section titled “60. Step 55 — Assess Integrity Impact”Ask:
Were files encrypted?
Were files modified?
Were accounts changed?
Were configurations modified?
Were backups deleted?
Were security controls altered?61. Step 56 — Assess Availability Impact
Section titled “61. Step 56 — Assess Availability Impact”Ask:
How many endpoints are unavailable?
Are servers unavailable?
Are critical applications unavailable?
Are file shares inaccessible?
Are business operations disrupted?62. Step 57 — Determine Business Impact
Section titled “62. Step 57 — Determine Business Impact”Record:
Affected Business Units:
Critical Applications:
Critical Servers:
Operational Impact:
Estimated Users Affected:
Customer Impact:
Third-Party Impact:63. Step 58 — Assign Severity
Section titled “63. Step 58 — Assign Severity”Ransomware should generally receive elevated priority.
Limited ransomware execution
Small number of endpoints
No critical systems affected
Containment successfulCritical
Section titled “Critical”Active encryption
Multiple systems affected
Critical infrastructure affected
Domain compromise suspected
Privileged identities compromised
Backup infrastructure affected
Potential data exfiltration
Major business disruption64. Step 59 — Activate Incident Response Escalation
Section titled “64. Step 59 — Activate Incident Response Escalation”Confirmed ransomware should normally trigger the organization’s formal incident-response process.
Potential stakeholders include:
SOC
Incident Response
Security Leadership
IT Operations
Identity Team
Network Team
Backup / Recovery Team
Cloud Team
Legal
Privacy
Risk / Compliance
Business Continuity
Executive LeadershipFollow organizational notification procedures.
65. Step 60 — Establish Incident Command
Section titled “65. Step 60 — Establish Incident Command”Large ransomware incidents require coordinated decision-making.
Track:
Incident Commander:
Technical Lead:
SOC Lead:
Identity Lead:
Network Lead:
Recovery Lead:
Business Contact:
Legal / Privacy Contact:Avoid multiple teams making conflicting containment changes.
66. Step 61 — Contain Compromised Endpoints
Section titled “66. Step 61 — Contain Compromised Endpoints”Depending on authorization:
Isolate Endpoint
Restrict Network Access
Block Malicious Indicators
Terminate Confirmed Malicious Processes
Prevent Additional Remote AccessPreserve evidence where possible.
67. Step 62 — Contain Compromised Identities
Section titled “67. Step 62 — Contain Compromised Identities”Consider:
Disable Compromised Account
Reset Credentials
Revoke Sessions
Invalidate Tokens
Reset MFA
Remove Unauthorized Authentication Methods
Restrict Privileged AccountsAvoid resetting only the password while leaving active attacker sessions valid.
68. Step 63 — Contain Privileged Accounts
Section titled “68. Step 63 — Contain Privileged Accounts”If privileged credentials may be compromised:
Identify Active Sessions
Revoke Sessions
Rotate Credentials
Review Recent Privileged Actions
Restrict Remote Logon
Validate Administrative WorkstationsCoordinate carefully to avoid disrupting recovery operations.
69. Step 64 — Restrict Lateral Movement
Section titled “69. Step 64 — Restrict Lateral Movement”Potential measures:
Restrict SMB
Restrict RDP
Restrict WinRM
Restrict SSH
Segment Affected Networks
Block Compromised Hosts
Disable Unnecessary Remote ServicesUse targeted controls wherever possible.
70. Step 65 — Protect Critical Systems
Section titled “70. Step 65 — Protect Critical Systems”Prioritize:
Domain Controllers
Backup Infrastructure
Identity Systems
Virtualization Platforms
Cloud Management
Security Infrastructure
Critical Databases
Critical ApplicationsIncrease monitoring and restrict unnecessary access.
71. Step 66 — Preserve Evidence
Section titled “71. Step 66 — Preserve Evidence”Consider preserving:
EDR Telemetry
Memory
Process Trees
Malware Samples
File Hashes
Ransom Notes
Authentication Logs
PowerShell Logs
Network Logs
DNS Logs
Firewall Logs
Backup Logs
Cloud Audit Logs
Disk Images where requiredFollow chain-of-custody procedures.
72. Step 67 — Maintain an Evidence Register
Section titled “72. Step 67 — Maintain an Evidence Register”Create:
| Evidence ID | Source | Collected | Hash | Location |
|---|---|---|---|---|
| EV-001 | Ransom note | <time> |
<SHA-256> |
<location> |
| EV-002 | Malware | <time> |
<SHA-256> |
<location> |
| EV-003 | EDR export | <time> |
<SHA-256> |
<location> |
73. Step 68 — Do Not Destroy Evidence Prematurely
Section titled “73. Step 68 — Do Not Destroy Evidence Prematurely”Avoid immediately:
Reimaging Systems
Deleting Malware
Deleting Logs
Removing Persistence
Restarting Systemsunless required for urgent containment or approved by incident leadership.
74. Step 69 — Determine Eradication Requirements
Section titled “74. Step 69 — Determine Eradication Requirements”After containment and scope determination:
Remove Malware
Remove Persistence
Remove Unauthorized Accounts
Patch Exploited Vulnerabilities
Remove Malicious Remote Tools
Rotate Credentials
Correct Security Misconfigurations
Update Security Controls75. Step 70 — Prefer Trusted Rebuilds for Confirmed Compromise
Section titled “75. Step 70 — Prefer Trusted Rebuilds for Confirmed Compromise”For significantly compromised systems, rebuilding from trusted sources may provide greater assurance than attempting to remove individual artifacts.
Use:
Known-Good Image
Approved Configuration
Current Security Patches
Validated Security Agent
Hardened Configuration76. Step 71 — Validate Backups Before Recovery
Section titled “76. Step 71 — Validate Backups Before Recovery”Before restoring:
Confirm Backup Integrity
Confirm Backup Predates Compromise
Scan Backup
Validate Recovery Credentials
Ensure Attacker Access Is Removed
Validate Recovery EnvironmentDo not restore compromised systems into an environment where the attacker remains active.
77. Step 72 — Prioritize Recovery
Section titled “77. Step 72 — Prioritize Recovery”Recovery should follow business priorities.
Example:
Tier 0 — Identity / Security / Recovery Infrastructure
Tier 1 — Critical Business Applications
Tier 2 — Supporting Servers
Tier 3 — User Endpoints
Tier 4 — Non-Critical SystemsActual priorities should follow the organization’s business continuity plan.
78. Step 73 — Recover in Controlled Phases
Section titled “78. Step 73 — Recover in Controlled Phases”Use:
Restore ↓Patch ↓Harden ↓Validate ↓Monitor ↓ReconnectAvoid reconnecting large numbers of systems simultaneously without validation.
79. Step 74 — Validate Recovered Systems
Section titled “79. Step 74 — Validate Recovered Systems”Check:
EDR Operational
Logging Operational
Patches Applied
Accounts Validated
Persistence Absent
Malware Absent
Network Behavior Normal
Critical Services Functional80. Step 75 — Increase Monitoring After Recovery
Section titled “80. Step 75 — Increase Monitoring After Recovery”Monitor for:
IOC Recurrence
Suspicious Authentication
Remote Access
New Persistence
C2 Communication
Mass File Changes
Backup Changes
Security-Control Tampering81. Step 76 — Determine Whether Reinfection Occurs
Section titled “81. Step 76 — Determine Whether Reinfection Occurs”If recovered systems become compromised again, investigate:
Unremoved Persistence
Compromised Identity
Compromised Infrastructure
Malicious Software Package
Compromised Backup
Unpatched Initial Access
Active Attacker SessionDo not repeatedly restore without finding the root cause.
82. Step 77 — Document Containment Actions
Section titled “82. Step 77 — Document Containment Actions”Create:
| Time | Action | Asset | Owner | Result |
|---|---|---|---|---|
| 04:12 | Endpoint isolated | WS01 | SOC | Successful |
| 04:15 | Account disabled | user01 | IAM | Successful |
| 04:20 | Domain blocked | Firewall | Network | Successful |
| 04:25 | Backup access restricted | Backup | IT | Successful |
83. Step 78 — Document Recovery Actions
Section titled “83. Step 78 — Document Recovery Actions”Create:
| System | Recovery Method | Validation | Status |
|---|---|---|---|
| DC01 | <method> |
Passed | Restored |
| FS01 | <method> |
Pending | Recovery |
| WS01 | Rebuild | Passed | Restored |
84. Step 79 — Ransomware Escalation Criteria
Section titled “84. Step 79 — Ransomware Escalation Criteria”Immediately escalate when:
Encryption confirmed
Multiple endpoints affected
Critical server affected
Domain controller affected
Privileged identity compromised
Backup system affected
Security tools disabled
Lateral movement confirmed
Data exfiltration suspected
Critical business services unavailable
Threat remains active85. Ransomware Escalation Template
Section titled “85. Ransomware Escalation Template”Case ID:
Incident Name:
Severity:
Detection Time:
Threat Status:
Initial Host:
Initial Identity:
Ransomware Family:
Encryption:Confirmed / Suspected
Affected Endpoints:
Affected Servers:
Critical Systems:
Privileged Accounts:
Lateral Movement:
C2:
Data Collection:
Exfiltration:Confirmed / Suspected / Unknown
Backup Impact:
Business Impact:
Evidence Preserved:
Containment Completed:
Containment Outstanding:
Recovery Status:
Outstanding Questions:
Incident Commander:
Escalated To:86. Example Ransomware Escalation
Section titled “86. Example Ransomware Escalation”Case:RANSOM-2026-008
Classification:Confirmed Ransomware Incident
Severity:Critical
Initial Host:FIN-WS17
Initial Identity:user01
Encryption:Confirmed.
Affected Systems:14 endpoints and one file server currently identified.
Lateral Movement:Evidence of SMB and remote administrative activitybetween the initial endpoint and multiple systems.
Privileged Activity:A privileged account was used from the affected endpoint.
Backup Impact:No confirmed backup modification.Backup infrastructure has been isolated from affected systems.
Exfiltration:Under investigation.
Threat Status:Active containment.
Actions:Affected endpoints isolated.Compromised identities disabled.Validated indicators blocked.Backup access restricted.Enterprise-wide hunting initiated.
Escalation:Incident Response, IT Operations, Identity,Network, Recovery, Security Leadership,and applicable Legal/Privacy stakeholders notified.87. Ransomware Decision Matrix
Section titled “87. Ransomware Decision Matrix”| Evidence | Assessment | Priority |
|---|---|---|
| Detection blocked before execution | Attempted ransomware | High |
| Encryption on one workstation | Confirmed ransomware | High |
| Multiple endpoints encrypting | Active outbreak | Critical |
| File server encryption | Major operational impact | Critical |
| Domain controller compromise | Enterprise identity risk | Critical |
| Backup compromise | Recovery risk | Critical |
| Data exfiltration evidence | Confidentiality breach risk | Critical |
88. Rapid Ransomware Triage Checklist
Section titled “88. Rapid Ransomware Triage Checklist”□ Alert preserved
□ Encryption validated
□ Threat status determined
□ Initial host identified
□ Initial identity identified
□ Affected host isolated
□ Additional hosts searched
□ Responsible process identified
□ Process tree built
□ Command line reviewed
□ Malware hash calculated
□ Threat intelligence checked
□ Initial access investigated
□ Authentication reviewed
□ Privileged activity reviewed
□ Persistence investigated
□ Security-control tampering investigated
□ Recovery interference investigated
□ Backup infrastructure protected
□ Network shares investigated
□ Lateral movement investigated
□ Domain controllers checked
□ Credential access assessed
□ Data collection assessed
□ Exfiltration assessed
□ DNS/network activity reviewed
□ C2 assessed
□ IOC inventory created
□ Enterprise hunt performed
□ Endpoint scope determined
□ Identity scope determined
□ Data scope determined
□ Backup scope determined
□ Business impact assessed
□ Severity assigned
□ Evidence preserved
□ Incident response escalated
□ Containment documented
□ Recovery coordinated89. Ransomware Investigation Documentation Template
Section titled “89. Ransomware Investigation Documentation Template”# Ransomware Incident Investigation
## Incident Information
Case ID:
Incident Name:
Analyst:
Date:
Severity:
Threat Status:
## Initial Detection
Detection Source:
Detection Time:
Alert:
## Initial Host
Hostname:
IP:
OS:
Criticality:
## Initial Identity
Username:
Privilege:
## Encryption
Confirmed:
First Observed:
Affected Files:
Extension:
Ransom Note:
## Malware
Filename:
Path:
SHA-256:
Family:
## Execution
Process:
Parent:
Command Line:
Execution Time:
## Initial Access
Method:
Evidence:
Confidence:
## Authentication
Document suspicious authentication.
## Privilege Activity
Document findings.
## Persistence
Document findings.
## Security-Control Tampering
Document findings.
## Recovery Interference
Document findings.
## Network Shares
Document affected shares and servers.
## Lateral Movement
Source:
Destination:
Identity:
Protocol:
Outcome:
## Credential Access
Confirmed / Suspected / Not Observed / Unknown
## Command-and-Control
Confirmed / Suspected / Not Observed / Unknown
## Data Collection
Document findings.
## Exfiltration
Confirmed / Suspected / Not Observed / Unknown
Evidence:
## IOC Inventory
Document:- hashes- filenames- domains- IPs- ransom notes- extensions- persistence indicators
## Endpoint Scope
Document affected systems.
## Identity Scope
Document affected identities.
## Data Scope
Document affected data.
## Backup Scope
Document backup impact.
## Timeline
Create master incident timeline.
## Business Impact
Document affected services and operations.
## Containment
Document:- isolated endpoints- disabled accounts- blocked indicators- network restrictions- backup protection
## Evidence
Document preserved evidence.
## Eradication
Document actions.
## Recovery
Document restoration and validation.
## Monitoring
Document enhanced monitoring.
## Outstanding Questions
Document investigation gaps.
## Final Assessment
Summarize incident.
## Disposition
Active / Contained / Eradication / Recovery / Closed90. Runbook Validation Checklist
Section titled “90. Runbook Validation Checklist”Detection
Section titled “Detection”-
Alert preserved
-
Encryption confirmed or disproved
-
Threat status determined
-
Initial affected host identified
-
Initial identity identified
Execution
Section titled “Execution”-
Responsible process identified
-
Parent process identified
-
Process tree constructed
-
Command line analyzed
-
Malware artifact preserved
-
SHA-256 recorded
-
Threat intelligence reviewed
Initial Access
Section titled “Initial Access”-
Phishing considered
-
Remote access reviewed
-
Authentication reviewed
-
Public-facing applications considered
-
Initial access confidence documented
Identity
Section titled “Identity”-
Compromised identities identified
-
Privileged activity reviewed
-
Account creation reviewed
-
Credential access assessed
-
Active sessions reviewed
Persistence & Defense Evasion
Section titled “Persistence & Defense Evasion”-
Scheduled tasks reviewed
-
Services reviewed
-
Autoruns reviewed
-
Security-control tampering reviewed
-
Recovery interference reviewed
Lateral Movement
Section titled “Lateral Movement”-
SMB reviewed
-
RDP reviewed
-
SSH reviewed
-
WinRM reviewed
-
Remote administration reviewed
-
Authentication correlated
-
Domain-controller activity reviewed
Backups
Section titled “Backups”-
Backup infrastructure identified
-
Backup access restricted where necessary
-
Backup accounts reviewed
-
Backup integrity assessed
-
Immutable/offline backups identified
-
Sensitive data access reviewed
-
Archive creation reviewed
-
Data staging assessed
-
Exfiltration assessed
-
Data scope documented
Network
Section titled “Network”-
DNS reviewed
-
External connections reviewed
-
C2 assessed
-
Internal connections reviewed
-
Network-share activity reviewed
-
Enterprise IOC hunt completed
-
Behavioral hunt completed
-
Endpoint scope established
-
Identity scope established
-
Data scope established
-
Backup scope established
Impact
Section titled “Impact”-
Confidentiality assessed
-
Integrity assessed
-
Availability assessed
-
Business impact assessed
-
Severity assigned
Response
Section titled “Response”-
Affected systems isolated
-
Compromised identities contained
-
Critical infrastructure protected
-
Backups protected
-
Evidence preserved
-
Incident response activated
-
Eradication coordinated
-
Recovery validated
-
Enhanced monitoring established
91. Common Analyst Mistakes
Section titled “91. Common Analyst Mistakes”Avoid:
Treating ransomware as only an endpoint problem
Waiting for every detail before containing active spread
Assuming encryption is the beginning of the incident
Ignoring identity compromise
Ignoring privileged accounts
Ignoring lateral movement
Ignoring network shares
Ignoring backup infrastructure
Assuming encryption proves data exfiltration
Assuming no ransom note means no ransomware
Deleting malware before preserving evidence
Reimaging before understanding scope
Resetting passwords without revoking sessions
Restoring systems before attacker access is removed
Restoring potentially compromised backups blindly
Failing to hunt for related systems
Focusing on static IOCs only
Failing to document containment actions92. Key CySA+ Investigation Concepts
Section titled “92. Key CySA+ Investigation Concepts”This runbook reinforces several CySA+ skills:
Detection vs Impact
Section titled “Detection vs Impact”Detection≠Successful EncryptionEncryption vs Compromise
Section titled “Encryption vs Compromise”Encryption=Impact StageThe compromise may have begun much earlier.
Encryption vs Exfiltration
Section titled “Encryption vs Exfiltration”Encryption≠Proof of Data TheftNetwork Contact vs Lateral Movement
Section titled “Network Contact vs Lateral Movement”Connection≠CompromiseRestoration vs Recovery
Section titled “Restoration vs Recovery”Restore Backup≠Incident ResolvedRecovery requires validation that attacker access and persistence have been removed.
93. Runbook Summary
Section titled “93. Runbook Summary”A weak ransomware response looks like:
Ransomware Detected ↓Delete Malware ↓Restore FilesA professional response follows:
Detection ↓Validate Encryption ↓Stop Active Spread ↓Identify Initial Access ↓Investigate Identities ↓Analyze Execution ↓Privilege / Persistence ↓Lateral Movement ↓Protect Backups ↓Assess Data Theft ↓Determine Scope ↓Contain ↓Preserve Evidence ↓Eradicate ↓Recover ↓MonitorThe key operational lesson is:
Encryption is often the final visible stage of a ransomware intrusion. Effective response requires identifying how the attacker entered, which identities and systems were compromised, whether data was stolen, whether recovery infrastructure remains trustworthy, and whether the attacker has truly been removed before restoration begins.
What’s Next?
Section titled “What’s Next?”CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization
Section titled “CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization”The next runbook shifts from active incident response to vulnerability management and risk-based remediation.
You will build a repeatable procedure for:
-
vulnerability scanner findings
-
CVE validation
-
CVSS interpretation
-
EPSS analysis
-
exploit availability
-
active exploitation
-
threat-intelligence enrichment
-
asset criticality
-
internet exposure
-
compensating controls
-
vulnerability false positives
-
remediation priority
-
patching decisions
-
mitigation
-
exception handling
-
remediation validation
-
vulnerability closure
The workflow progresses from:
Scanner Finding ↓Validate Vulnerability ↓Identify CVE ↓Review CVSS ↓Review EPSS ↓Check Exploitability ↓Check Active Exploitation ↓Assess Asset Criticality ↓Assess Exposure ↓Review Existing Controls ↓Determine Risk ↓Prioritize Remediation ↓Patch / Mitigate ↓Validate ↓Close➡️ Next: CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization