Skip to content

CySA+ Runbook 06 — Ransomware Incident Response

Item Details
Runbook 06
Runbook Name Ransomware Incident Response
Track CompTIA CySA+
Difficulty Advanced
Primary Role SOC Analyst / Cybersecurity Analyst / Incident Responder
Purpose Detect, investigate, contain, eradicate, and support recovery from ransomware incidents
Primary Systems SIEM, EDR/XDR, Identity Provider, Active Directory, Firewall, IDS/IPS, Email Security, Backup Systems
Primary Data Sources EDR Telemetry, Process Logs, Authentication Logs, Windows/Linux Logs, DNS, Network Flows, File Events, Backup Logs
Output False Positive / Attempted Ransomware / Contained Ransomware / Confirmed Ransomware Incident / Enterprise Incident Escalation
Related Labs Lab 13, Lab 16, Lab 17, Lab 18, Lab 20

Operational Principle: Ransomware is not simply a malware-removal problem. Modern ransomware incidents may involve identity compromise, privilege escalation, lateral movement, data theft, backup destruction, and encryption. Containment must therefore address endpoints, identities, network access, and recovery infrastructure together.

This runbook provides a repeatable procedure for responding to suspected ransomware.

The investigation should answer:

What triggered the alert?
Is encryption actually occurring?
Which host was affected first?
What executed the ransomware?
Which identity was involved?
How did the attacker gain access?
Were privileges increased?
Did the attacker move laterally?
Were backups targeted?
Was data stolen?
How many systems are affected?
Is the threat still active?
What must be isolated immediately?
How can recovery begin safely?

Use this runbook when:

  • ransomware is detected by EDR/XDR

  • mass file encryption is observed

  • unusual file-extension changes occur

  • ransom notes appear

  • large numbers of files are renamed

  • shadow copies or recovery mechanisms are unexpectedly modified

  • backup infrastructure is attacked

  • suspicious encryption processes execute

  • multiple endpoints experience simultaneous file modifications

  • network shares experience mass changes

  • destructive malware is suspected

  • known ransomware indicators are detected

  • ransomware-associated threat intelligence matches internal activity

Ransomware response priorities are:

1. Protect People and Critical Operations
2. Stop Active Spread
3. Protect Identities
4. Protect Backups
5. Preserve Evidence
6. Determine Scope
7. Eradicate Threat
8. Recover Safely
Ransomware Alert
Investigation
├── False Positive
├── Attempted Ransomware — Blocked
├── Limited Ransomware — Contained
├── Confirmed Ransomware Incident
└── Enterprise-Wide Ransomware Incident
Alert / Report
Validate Activity
Identify Initial Affected Host
Emergency Isolation
Identify Identity
Analyze Execution
Identify Persistence
Investigate Privilege
Investigate Lateral Movement
Protect Backup Infrastructure
Investigate Data Access
Assess Exfiltration
Determine Enterprise Scope
Contain Identities / Systems
Preserve Evidence
Eradicate
Recover
Enhanced Monitoring
Post-Incident Review

Capture:

Case ID:
Alert ID:
Detection Time:
Detection Source:
Hostname:
IP Address:
Username:
Process:
Parent Process:
Command Line:
Filename:
File Path:
SHA-256:
Detection Name:
EDR Action:
Affected Files:
Ransom Note:
Severity:

7. Step 2 — Determine Whether Activity Is Active

Section titled “7. Step 2 — Determine Whether Activity Is Active”

Immediately determine:

Are files currently being encrypted?
Are new hosts generating alerts?
Are network shares changing?
Are suspicious processes still running?
Are malicious identities still authenticated?
Is lateral movement continuing?
Are backups being modified?

Classify:

Threat Status:
Active
Contained
Historical
Unknown

Active ransomware requires urgent escalation.

8. Step 3 — Validate Encryption Activity

Section titled “8. Step 3 — Validate Encryption Activity”

Look for:

Rapid File Modification
File Renaming
Extension Changes
High File Write Volume
Encryption-Like Behavior
Ransom Notes
Deletion of Originals
Multiple Directories Affected

Do not rely solely on the ransom note.

9. Step 4 — Identify File Extension Changes

Section titled “9. Step 4 — Identify File Extension Changes”

Record:

Original Extension:
New Extension:
First Observed:
Affected Directories:
Number of Files:

Example:

report.docx
report.docx.<unexpected-extension>

Preserve ransom-note artifacts.

Record:

Filename:
Path:
Creation Time:
Creating Process:
Hash:
Content Summary:

Do not contact threat actors or follow payment instructions as part of analyst triage.

11. Step 6 — Identify the Initial Affected Endpoint

Section titled “11. Step 6 — Identify the Initial Affected Endpoint”

Capture:

Hostname:
IP:
Operating System:
User:
Business Function:
Criticality:
Network Segment:
EDR Status:
First Suspicious Activity:

12. Step 7 — Emergency Endpoint Isolation

Section titled “12. Step 7 — Emergency Endpoint Isolation”

For active ransomware, follow approved procedures to consider immediate network isolation.

The objective is:

Compromised Endpoint
X
Internal Network

Isolation should prevent:

Lateral Movement
Network Share Encryption
C2 Communication
Additional Payload Delivery

while preserving investigative access where possible.

13. Step 8 — Identify Other Hosts Showing Encryption

Section titled “13. Step 8 — Identify Other Hosts Showing Encryption”

Search the SIEM/EDR for:

Same Alert
Same Hash
Same Filename
Same Process
Same Extension
Same Ransom Note
Same Domain
Same IP
Same User

Build:

Host Encryption Isolation Status
HOST01 Confirmed Yes Compromised
HOST02 Suspected Pending Investigate
HOST03 No No Monitor

14. Step 9 — Identify the Responsible Process

Section titled “14. Step 9 — Identify the Responsible Process”

Record:

Process:
PID:
Path:
User:
Start Time:
Parent Process:
Command Line:
SHA-256:

Determine which process performed the mass file modifications.

Example:

Email Client
Office Application
PowerShell
Payload
Encryption Process

or:

Remote Service
Command Shell
Ransomware

Every relationship should be supported by telemetry.

16. Step 11 — Analyze the Parent Process

Section titled “16. Step 11 — Analyze the Parent Process”

Determine:

What launched the ransomware?
Was it user initiated?
Was it launched remotely?
Was it started by a service?
Was it started by a scheduled task?
Was PowerShell involved?

17. Step 12 — Analyze Command-Line Activity

Section titled “17. Step 12 — Analyze Command-Line Activity”

Review safely for evidence of:

File Enumeration
Network Share Enumeration
Security-Control Changes
Backup Interference
Recovery Interference
Remote Execution
Script Execution
Discovery
Credential-Related Activity

Do not execute suspicious commands discovered during analysis.

18. Step 13 — Investigate PowerShell and Script Activity

Section titled “18. Step 13 — Investigate PowerShell and Script Activity”

Review:

PowerShell Operational Logs
Script Block Logging
EDR Process Telemetry
Event ID 4104

Look for:

Obfuscation
Encoded Content
Payload Retrieval
Discovery
Remote Administration
Security-Control Changes

19. Step 14 — Identify the Malware Artifact

Section titled “19. Step 14 — Identify the Malware Artifact”

Capture:

Filename:
Path:
Actual File Type:
Size:
Creation Time:
Execution Time:
SHA-256:

Preserve the artifact according to evidence-handling procedures.

Using approved threat-intelligence sources, determine:

Known / Unknown:
Classification:
Malware Family:
Ransomware Family:
First Seen:
Last Seen:
Associated Infrastructure:
Confidence:

Remember:

Unknown Hash
Benign

21. Step 16 — Investigate Delivery Method

Section titled “21. Step 16 — Investigate Delivery Method”

Potential sources include:

Phishing
Malicious Attachment
Malicious Download
Compromised Credentials
Remote Access
Public-Facing Application
Third-Party Access
Software Supply Chain
Removable Media
Unknown

Do not assign initial access without supporting evidence.

If email is suspected, review:

Sender
Recipient
Subject
URLs
Attachments
Message-ID
Delivery Scope
User Interaction

Use the phishing investigation workflow where necessary.

Review:

VPN
RDP
SSH
Remote Support Tools
Remote Administration Platforms

Look for unusual:

Source IP
Device
Location
Time
Identity
Session Duration

24. Step 19 — Investigate Authentication Activity

Section titled “24. Step 19 — Investigate Authentication Activity”

Search for:

Failed Logins
Successful Logins
New Source IPs
New Devices
Privileged Logons
Service Account Usage
Remote Interactive Sessions
MFA Events

Build identity context around the earliest suspicious activity.

25. Step 20 — Identify Compromised Identities

Section titled “25. Step 20 — Identify Compromised Identities”

Create:

Identity Evidence Privilege Status
user01 Suspicious login User Suspected
admin01 Remote activity Admin Investigate
svc01 Unexpected host usage Service Investigate

26. Step 21 — Investigate Privilege Escalation

Section titled “26. Step 21 — Investigate Privilege Escalation”

Determine whether:

A standard user became privileged

or:

An already-privileged account was compromised

Look for:

Group Membership Changes
Privileged Logons
New Admin Accounts
Token/Session Abuse
Unexpected SYSTEM/root Activity

27. Step 22 — Investigate Account Creation

Section titled “27. Step 22 — Investigate Account Creation”

Review unexpected new accounts.

For Windows environments, relevant evidence may include:

Event ID 4720

Capture:

Account:
Created By:
Host:
Timestamp:
Privileges:

Look for:

Scheduled Tasks
Services
Registry Autoruns
Startup Items
New Accounts
Remote Management Tools
Cron Jobs
Systemd Services

Ransomware may be the final visible stage of a longer compromise.

29. Step 24 — Investigate Security-Control Tampering

Section titled “29. Step 24 — Investigate Security-Control Tampering”

Look for attempts to:

Disable EDR
Disable Antivirus
Add Security Exclusions
Stop Logging
Modify Firewall
Stop Security Services

Security-control tampering should significantly increase concern.

30. Step 25 — Investigate Recovery-Control Interference

Section titled “30. Step 25 — Investigate Recovery-Control Interference”

Determine whether recovery mechanisms were:

Disabled
Deleted
Modified
Made Unavailable
Tampered With

Review evidence involving:

Snapshots
Restore Points
Backup Agents
Recovery Services
Backup Repositories

31. Step 26 — Protect Backup Infrastructure

Section titled “31. Step 26 — Protect Backup Infrastructure”

Immediately determine whether the attacker can access:

Backup Servers
Backup Consoles
Backup Repositories
Cloud Backup Accounts
Recovery Credentials

Protect them using approved procedures.

The objective is:

Compromised Environment
X
Recovery Infrastructure

Record:

Backup Platform:
Last Known Good Backup:
Backup Integrity:
Offline / Immutable Copy:
Backup Account Status:
Suspicious Backup Activity:

Do not begin restoration until the threat has been sufficiently contained.

33. Step 28 — Investigate Network Shares

Section titled “33. Step 28 — Investigate Network Shares”

Review:

SMB Shares
Mapped Drives
File Servers
NAS Systems
Shared Application Storage

Look for:

Mass File Changes
Remote File Encryption
Unusual SMB Activity
Large Numbers of File Operations

34. Step 29 — Identify Network-Share Source

Section titled “34. Step 29 — Identify Network-Share Source”

Determine which endpoint and identity performed suspicious file operations.

Build:

Compromised Endpoint
Compromised Identity
SMB
File Server
Mass Encryption

35. Step 30 — Investigate Lateral Movement

Section titled “35. Step 30 — Investigate Lateral Movement”

Review:

RDP
SMB
SSH
WinRM
Remote Services
Administrative Shares
Remote Management Tools

Capture:

Source:
Destination:
Identity:
Protocol:
Timestamp:
Outcome:

36. Step 31 — Correlate Authentication with Lateral Movement

Section titled “36. Step 31 — Correlate Authentication with Lateral Movement”

Stronger evidence follows:

Network Connection
+
Authentication
+
Remote Execution
=
Likely Lateral Movement

Do not classify every internal connection as compromise.

37. Step 32 — Investigate Domain Controller Activity

Section titled “37. Step 32 — Investigate Domain Controller Activity”

If Active Directory exists, determine whether domain controllers were:

Accessed
Authenticated To
Modified
Used for Privileged Operations
Targeted by Malware

Domain-controller compromise should trigger critical escalation.

38. Step 33 — Investigate Privileged Accounts

Section titled “38. Step 33 — Investigate Privileged Accounts”

Prioritize:

Domain Admins
Enterprise Admins
Local Administrators
Cloud Administrators
Backup Administrators
Security Administrators

Determine whether any privileged credentials were used from compromised systems.

39. Step 34 — Investigate Credential Access

Section titled “39. Step 34 — Investigate Credential Access”

Look for evidence of:

Credential-Dumping Alerts
Authentication Process Access
Browser Credential Access
Token Theft
Password Store Access
Unusual Credential Tools

Classify:

Credential Access:
Confirmed
Suspected
Not Observed
Unknown

40. Step 35 — Investigate Discovery Activity

Section titled “40. Step 35 — Investigate Discovery Activity”

Look for evidence of:

Host Discovery
Network Discovery
Domain Discovery
User Discovery
Group Discovery
Share Discovery
Backup Discovery
Security-Tool Discovery

This activity can help reconstruct attacker preparation.

41. Step 36 — Investigate Data Collection

Section titled “41. Step 36 — Investigate Data Collection”

Modern ransomware incidents may include data theft before encryption.

Look for:

Sensitive File Access
Large Directory Enumeration
File Copying
Database Access
Shared Drive Access
Archive Creation

42. Step 37 — Investigate Archive Creation

Section titled “42. Step 37 — Investigate Archive Creation”

Review unexpected creation of:

ZIP
7z
RAR
tar
gzip

Record:

Archive:
Created By:
Source Files:
Size:
Timestamp:
Destination:

Archive creation indicates possible staging, not proof of exfiltration.

43. Step 38 — Investigate Potential Exfiltration

Section titled “43. Step 38 — Investigate Potential Exfiltration”

Search:

Proxy Logs
Firewall Logs
Zeek
EDR Network Telemetry
Cloud Audit Logs

for:

Large Outbound Transfers
Rare External Destinations
Cloud Storage Uploads
File Transfer Services
Long-Lived Sessions
Unusual HTTPS Uploads

44. Step 39 — Distinguish Encryption from Data Theft

Section titled “44. Step 39 — Distinguish Encryption from Data Theft”

Track separately:

Encryption:
Confirmed / Suspected / Not Observed
Data Exfiltration:
Confirmed / Suspected / Not Observed / Unknown

Do not assume encryption proves exfiltration.

Do not assume absence of encryption means data was not stolen.

45. Step 40 — Investigate DNS and External Communication

Section titled “45. Step 40 — Investigate DNS and External Communication”

Review:

DNS Queries
External Domains
External IPs
C2 Indicators
Payload Infrastructure

Correlate with the ransomware execution timeline.

46. Step 41 — Identify Command-and-Control

Section titled “46. Step 41 — Identify Command-and-Control”

Look for:

Known Malicious Infrastructure
Repeated External Connections
Rare Domains
Beaconing
Connections from Suspicious Processes

Classify:

C2:
Confirmed
Suspected
Not Observed
Unknown

Create:

Type Indicator Source Confidence
Hash <SHA-256> EDR High
File <filename> Endpoint High
Domain <domain> DNS Medium/High
IP <IP> Network Medium/High
Ransom Note <filename> Endpoint High
Extension <extension> File Events Medium
Registry <key> Endpoint Medium

48. Step 43 — Hunt Across the Enterprise

Section titled “48. Step 43 — Hunt Across the Enterprise”

Search for:

Malware Hash
Filename
Ransom Note
File Extension
Domain
IP
Process
Command-Line Pattern
Persistence Mechanism
Compromised Identity

across:

EDR
SIEM
DNS
Firewall
Email
Identity
Servers
Cloud Workloads

49. Step 44 — Hunt Behavioral Indicators

Section titled “49. Step 44 — Hunt Behavioral Indicators”

Static IOCs may change.

Also search for:

Mass File Modification
High File Rename Volume
Recovery Tampering
Backup Interference
Security-Control Disabling
Unusual Remote Execution
Share Enumeration
Archive Creation

50. Step 45 — Determine the Initial Compromise Time

Section titled “50. Step 45 — Determine the Initial Compromise Time”

Do not use encryption time as the beginning of the incident.

Example:

Day 1 — Credential compromise
Day 2 — Discovery
Day 3 — Privilege escalation
Day 4 — Lateral movement
Day 5 — Data collection
Day 6 — Encryption

Ransomware may be the final stage of a multi-day intrusion.

Create:

Time Event Host / Identity Evidence
01:15 Suspicious login user01 Identity
01:27 Internal discovery HOST01 EDR
01:45 Privileged login admin01 Security Log
02:10 Remote connection HOST01 → SERVER01 Network
02:40 Archive created SERVER01 EDR
03:05 External transfer SERVER01 Firewall
04:00 Encryption begins Multiple EDR
04:02 Ransom note created Multiple File Events

Classify only with evidence:

Phishing
Compromised Credentials
Remote Access
Exploited Application
Third-Party Access
Malicious Download
Supply Chain
Unknown

53. Step 48 — Reconstruct the Ransomware Attack Story

Section titled “53. Step 48 — Reconstruct the Ransomware Attack Story”

Example:

Compromised Credentials
Remote Access
Discovery
Privilege Escalation
Credential Access
Lateral Movement
Backup Discovery
Data Collection
Potential Exfiltration
Security-Control Tampering
Ransomware Deployment
Encryption

Every stage should have supporting evidence.

54. Step 49 — Map Activity to MITRE ATT&CK

Section titled “54. Step 49 — Map Activity to MITRE ATT&CK”

Create:

Tactic Observed Behavior Evidence
Initial Access <behavior> <source>
Execution <behavior> <source>
Persistence <behavior> <source>
Privilege Escalation <behavior> <source>
Defense Evasion <behavior> <source>
Credential Access <behavior> <source>
Discovery <behavior> <source>
Lateral Movement <behavior> <source>
Collection <behavior> <source>
C2 <behavior> <source>
Exfiltration <behavior> <source>
Impact File encryption <source>

Classify every relevant host:

Confirmed Compromised
Suspected Compromised
Encrypted
Exposed / Contacted
Unaffected
Unknown

Example:

Host Status Evidence
WS01 Confirmed Compromised Malware execution
FS01 Encrypted Mass file changes
DC01 Suspected Privileged connection
WS02 Exposed Network contact only

Classify:

Confirmed Compromised
Suspected Compromised
Used on Compromised Endpoint
Privileged Exposure
Unaffected
Unknown

Prioritize privileged identities.

Identify:

Files Accessed
Directories Accessed
Shares Accessed
Databases Accessed
Archives Created
Potentially Transferred Data
Sensitive Data Categories

Identify:

Backup Servers Affected:
Repositories Affected:
Backup Accounts Affected:
Snapshots Deleted:
Backup Jobs Modified:
Immutable Copies Available:

59. Step 54 — Assess Confidentiality Impact

Section titled “59. Step 54 — Assess Confidentiality Impact”

Ask:

Was sensitive data accessed?
Was data staged?
Was data transferred externally?
Were credentials exposed?
Were privileged credentials involved?

Ask:

Were files encrypted?
Were files modified?
Were accounts changed?
Were configurations modified?
Were backups deleted?
Were security controls altered?

61. Step 56 — Assess Availability Impact

Section titled “61. Step 56 — Assess Availability Impact”

Ask:

How many endpoints are unavailable?
Are servers unavailable?
Are critical applications unavailable?
Are file shares inaccessible?
Are business operations disrupted?

Record:

Affected Business Units:
Critical Applications:
Critical Servers:
Operational Impact:
Estimated Users Affected:
Customer Impact:
Third-Party Impact:

Ransomware should generally receive elevated priority.

Limited ransomware execution
Small number of endpoints
No critical systems affected
Containment successful
Active encryption
Multiple systems affected
Critical infrastructure affected
Domain compromise suspected
Privileged identities compromised
Backup infrastructure affected
Potential data exfiltration
Major business disruption

64. Step 59 — Activate Incident Response Escalation

Section titled “64. Step 59 — Activate Incident Response Escalation”

Confirmed ransomware should normally trigger the organization’s formal incident-response process.

Potential stakeholders include:

SOC
Incident Response
Security Leadership
IT Operations
Identity Team
Network Team
Backup / Recovery Team
Cloud Team
Legal
Privacy
Risk / Compliance
Business Continuity
Executive Leadership

Follow organizational notification procedures.

65. Step 60 — Establish Incident Command

Section titled “65. Step 60 — Establish Incident Command”

Large ransomware incidents require coordinated decision-making.

Track:

Incident Commander:
Technical Lead:
SOC Lead:
Identity Lead:
Network Lead:
Recovery Lead:
Business Contact:
Legal / Privacy Contact:

Avoid multiple teams making conflicting containment changes.

66. Step 61 — Contain Compromised Endpoints

Section titled “66. Step 61 — Contain Compromised Endpoints”

Depending on authorization:

Isolate Endpoint
Restrict Network Access
Block Malicious Indicators
Terminate Confirmed Malicious Processes
Prevent Additional Remote Access

Preserve evidence where possible.

67. Step 62 — Contain Compromised Identities

Section titled “67. Step 62 — Contain Compromised Identities”

Consider:

Disable Compromised Account
Reset Credentials
Revoke Sessions
Invalidate Tokens
Reset MFA
Remove Unauthorized Authentication Methods
Restrict Privileged Accounts

Avoid resetting only the password while leaving active attacker sessions valid.

68. Step 63 — Contain Privileged Accounts

Section titled “68. Step 63 — Contain Privileged Accounts”

If privileged credentials may be compromised:

Identify Active Sessions
Revoke Sessions
Rotate Credentials
Review Recent Privileged Actions
Restrict Remote Logon
Validate Administrative Workstations

Coordinate carefully to avoid disrupting recovery operations.

Potential measures:

Restrict SMB
Restrict RDP
Restrict WinRM
Restrict SSH
Segment Affected Networks
Block Compromised Hosts
Disable Unnecessary Remote Services

Use targeted controls wherever possible.

Prioritize:

Domain Controllers
Backup Infrastructure
Identity Systems
Virtualization Platforms
Cloud Management
Security Infrastructure
Critical Databases
Critical Applications

Increase monitoring and restrict unnecessary access.

Consider preserving:

EDR Telemetry
Memory
Process Trees
Malware Samples
File Hashes
Ransom Notes
Authentication Logs
PowerShell Logs
Network Logs
DNS Logs
Firewall Logs
Backup Logs
Cloud Audit Logs
Disk Images where required

Follow chain-of-custody procedures.

72. Step 67 — Maintain an Evidence Register

Section titled “72. Step 67 — Maintain an Evidence Register”

Create:

Evidence ID Source Collected Hash Location
EV-001 Ransom note <time> <SHA-256> <location>
EV-002 Malware <time> <SHA-256> <location>
EV-003 EDR export <time> <SHA-256> <location>

73. Step 68 — Do Not Destroy Evidence Prematurely

Section titled “73. Step 68 — Do Not Destroy Evidence Prematurely”

Avoid immediately:

Reimaging Systems
Deleting Malware
Deleting Logs
Removing Persistence
Restarting Systems

unless required for urgent containment or approved by incident leadership.

74. Step 69 — Determine Eradication Requirements

Section titled “74. Step 69 — Determine Eradication Requirements”

After containment and scope determination:

Remove Malware
Remove Persistence
Remove Unauthorized Accounts
Patch Exploited Vulnerabilities
Remove Malicious Remote Tools
Rotate Credentials
Correct Security Misconfigurations
Update Security Controls

75. Step 70 — Prefer Trusted Rebuilds for Confirmed Compromise

Section titled “75. Step 70 — Prefer Trusted Rebuilds for Confirmed Compromise”

For significantly compromised systems, rebuilding from trusted sources may provide greater assurance than attempting to remove individual artifacts.

Use:

Known-Good Image
Approved Configuration
Current Security Patches
Validated Security Agent
Hardened Configuration

76. Step 71 — Validate Backups Before Recovery

Section titled “76. Step 71 — Validate Backups Before Recovery”

Before restoring:

Confirm Backup Integrity
Confirm Backup Predates Compromise
Scan Backup
Validate Recovery Credentials
Ensure Attacker Access Is Removed
Validate Recovery Environment

Do not restore compromised systems into an environment where the attacker remains active.

Recovery should follow business priorities.

Example:

Tier 0 — Identity / Security / Recovery Infrastructure
Tier 1 — Critical Business Applications
Tier 2 — Supporting Servers
Tier 3 — User Endpoints
Tier 4 — Non-Critical Systems

Actual priorities should follow the organization’s business continuity plan.

78. Step 73 — Recover in Controlled Phases

Section titled “78. Step 73 — Recover in Controlled Phases”

Use:

Restore
Patch
Harden
Validate
Monitor
Reconnect

Avoid reconnecting large numbers of systems simultaneously without validation.

79. Step 74 — Validate Recovered Systems

Section titled “79. Step 74 — Validate Recovered Systems”

Check:

EDR Operational
Logging Operational
Patches Applied
Accounts Validated
Persistence Absent
Malware Absent
Network Behavior Normal
Critical Services Functional

80. Step 75 — Increase Monitoring After Recovery

Section titled “80. Step 75 — Increase Monitoring After Recovery”

Monitor for:

IOC Recurrence
Suspicious Authentication
Remote Access
New Persistence
C2 Communication
Mass File Changes
Backup Changes
Security-Control Tampering

81. Step 76 — Determine Whether Reinfection Occurs

Section titled “81. Step 76 — Determine Whether Reinfection Occurs”

If recovered systems become compromised again, investigate:

Unremoved Persistence
Compromised Identity
Compromised Infrastructure
Malicious Software Package
Compromised Backup
Unpatched Initial Access
Active Attacker Session

Do not repeatedly restore without finding the root cause.

82. Step 77 — Document Containment Actions

Section titled “82. Step 77 — Document Containment Actions”

Create:

Time Action Asset Owner Result
04:12 Endpoint isolated WS01 SOC Successful
04:15 Account disabled user01 IAM Successful
04:20 Domain blocked Firewall Network Successful
04:25 Backup access restricted Backup IT Successful

Create:

System Recovery Method Validation Status
DC01 <method> Passed Restored
FS01 <method> Pending Recovery
WS01 Rebuild Passed Restored

84. Step 79 — Ransomware Escalation Criteria

Section titled “84. Step 79 — Ransomware Escalation Criteria”

Immediately escalate when:

Encryption confirmed
Multiple endpoints affected
Critical server affected
Domain controller affected
Privileged identity compromised
Backup system affected
Security tools disabled
Lateral movement confirmed
Data exfiltration suspected
Critical business services unavailable
Threat remains active
Case ID:
Incident Name:
Severity:
Detection Time:
Threat Status:
Initial Host:
Initial Identity:
Ransomware Family:
Encryption:
Confirmed / Suspected
Affected Endpoints:
Affected Servers:
Critical Systems:
Privileged Accounts:
Lateral Movement:
C2:
Data Collection:
Exfiltration:
Confirmed / Suspected / Unknown
Backup Impact:
Business Impact:
Evidence Preserved:
Containment Completed:
Containment Outstanding:
Recovery Status:
Outstanding Questions:
Incident Commander:
Escalated To:
Case:
RANSOM-2026-008
Classification:
Confirmed Ransomware Incident
Severity:
Critical
Initial Host:
FIN-WS17
Initial Identity:
user01
Encryption:
Confirmed.
Affected Systems:
14 endpoints and one file server currently identified.
Lateral Movement:
Evidence of SMB and remote administrative activity
between the initial endpoint and multiple systems.
Privileged Activity:
A privileged account was used from the affected endpoint.
Backup Impact:
No confirmed backup modification.
Backup infrastructure has been isolated from affected systems.
Exfiltration:
Under investigation.
Threat Status:
Active containment.
Actions:
Affected endpoints isolated.
Compromised identities disabled.
Validated indicators blocked.
Backup access restricted.
Enterprise-wide hunting initiated.
Escalation:
Incident Response, IT Operations, Identity,
Network, Recovery, Security Leadership,
and applicable Legal/Privacy stakeholders notified.
Evidence Assessment Priority
Detection blocked before execution Attempted ransomware High
Encryption on one workstation Confirmed ransomware High
Multiple endpoints encrypting Active outbreak Critical
File server encryption Major operational impact Critical
Domain controller compromise Enterprise identity risk Critical
Backup compromise Recovery risk Critical
Data exfiltration evidence Confidentiality breach risk Critical
□ Alert preserved
□ Encryption validated
□ Threat status determined
□ Initial host identified
□ Initial identity identified
□ Affected host isolated
□ Additional hosts searched
□ Responsible process identified
□ Process tree built
□ Command line reviewed
□ Malware hash calculated
□ Threat intelligence checked
□ Initial access investigated
□ Authentication reviewed
□ Privileged activity reviewed
□ Persistence investigated
□ Security-control tampering investigated
□ Recovery interference investigated
□ Backup infrastructure protected
□ Network shares investigated
□ Lateral movement investigated
□ Domain controllers checked
□ Credential access assessed
□ Data collection assessed
□ Exfiltration assessed
□ DNS/network activity reviewed
□ C2 assessed
□ IOC inventory created
□ Enterprise hunt performed
□ Endpoint scope determined
□ Identity scope determined
□ Data scope determined
□ Backup scope determined
□ Business impact assessed
□ Severity assigned
□ Evidence preserved
□ Incident response escalated
□ Containment documented
□ Recovery coordinated

89. Ransomware Investigation Documentation Template

Section titled “89. Ransomware Investigation Documentation Template”
# Ransomware Incident Investigation
## Incident Information
Case ID:
Incident Name:
Analyst:
Date:
Severity:
Threat Status:
## Initial Detection
Detection Source:
Detection Time:
Alert:
## Initial Host
Hostname:
IP:
OS:
Criticality:
## Initial Identity
Username:
Privilege:
## Encryption
Confirmed:
First Observed:
Affected Files:
Extension:
Ransom Note:
## Malware
Filename:
Path:
SHA-256:
Family:
## Execution
Process:
Parent:
Command Line:
Execution Time:
## Initial Access
Method:
Evidence:
Confidence:
## Authentication
Document suspicious authentication.
## Privilege Activity
Document findings.
## Persistence
Document findings.
## Security-Control Tampering
Document findings.
## Recovery Interference
Document findings.
## Network Shares
Document affected shares and servers.
## Lateral Movement
Source:
Destination:
Identity:
Protocol:
Outcome:
## Credential Access
Confirmed / Suspected / Not Observed / Unknown
## Command-and-Control
Confirmed / Suspected / Not Observed / Unknown
## Data Collection
Document findings.
## Exfiltration
Confirmed / Suspected / Not Observed / Unknown
Evidence:
## IOC Inventory
Document:
- hashes
- filenames
- domains
- IPs
- ransom notes
- extensions
- persistence indicators
## Endpoint Scope
Document affected systems.
## Identity Scope
Document affected identities.
## Data Scope
Document affected data.
## Backup Scope
Document backup impact.
## Timeline
Create master incident timeline.
## Business Impact
Document affected services and operations.
## Containment
Document:
- isolated endpoints
- disabled accounts
- blocked indicators
- network restrictions
- backup protection
## Evidence
Document preserved evidence.
## Eradication
Document actions.
## Recovery
Document restoration and validation.
## Monitoring
Document enhanced monitoring.
## Outstanding Questions
Document investigation gaps.
## Final Assessment
Summarize incident.
## Disposition
Active / Contained / Eradication / Recovery / Closed
  • Alert preserved

  • Encryption confirmed or disproved

  • Threat status determined

  • Initial affected host identified

  • Initial identity identified

  • Responsible process identified

  • Parent process identified

  • Process tree constructed

  • Command line analyzed

  • Malware artifact preserved

  • SHA-256 recorded

  • Threat intelligence reviewed

  • Phishing considered

  • Remote access reviewed

  • Authentication reviewed

  • Public-facing applications considered

  • Initial access confidence documented

  • Compromised identities identified

  • Privileged activity reviewed

  • Account creation reviewed

  • Credential access assessed

  • Active sessions reviewed

  • Scheduled tasks reviewed

  • Services reviewed

  • Autoruns reviewed

  • Security-control tampering reviewed

  • Recovery interference reviewed

  • SMB reviewed

  • RDP reviewed

  • SSH reviewed

  • WinRM reviewed

  • Remote administration reviewed

  • Authentication correlated

  • Domain-controller activity reviewed

  • Backup infrastructure identified

  • Backup access restricted where necessary

  • Backup accounts reviewed

  • Backup integrity assessed

  • Immutable/offline backups identified

  • Sensitive data access reviewed

  • Archive creation reviewed

  • Data staging assessed

  • Exfiltration assessed

  • Data scope documented

  • DNS reviewed

  • External connections reviewed

  • C2 assessed

  • Internal connections reviewed

  • Network-share activity reviewed

  • Enterprise IOC hunt completed

  • Behavioral hunt completed

  • Endpoint scope established

  • Identity scope established

  • Data scope established

  • Backup scope established

  • Confidentiality assessed

  • Integrity assessed

  • Availability assessed

  • Business impact assessed

  • Severity assigned

  • Affected systems isolated

  • Compromised identities contained

  • Critical infrastructure protected

  • Backups protected

  • Evidence preserved

  • Incident response activated

  • Eradication coordinated

  • Recovery validated

  • Enhanced monitoring established

Avoid:

Treating ransomware as only an endpoint problem
Waiting for every detail before containing active spread
Assuming encryption is the beginning of the incident
Ignoring identity compromise
Ignoring privileged accounts
Ignoring lateral movement
Ignoring network shares
Ignoring backup infrastructure
Assuming encryption proves data exfiltration
Assuming no ransom note means no ransomware
Deleting malware before preserving evidence
Reimaging before understanding scope
Resetting passwords without revoking sessions
Restoring systems before attacker access is removed
Restoring potentially compromised backups blindly
Failing to hunt for related systems
Focusing on static IOCs only
Failing to document containment actions

This runbook reinforces several CySA+ skills:

Detection
Successful Encryption
Encryption
=
Impact Stage

The compromise may have begun much earlier.

Encryption
Proof of Data Theft
Connection
Compromise
Restore Backup
Incident Resolved

Recovery requires validation that attacker access and persistence have been removed.

A weak ransomware response looks like:

Ransomware Detected
Delete Malware
Restore Files

A professional response follows:

Detection
Validate Encryption
Stop Active Spread
Identify Initial Access
Investigate Identities
Analyze Execution
Privilege / Persistence
Lateral Movement
Protect Backups
Assess Data Theft
Determine Scope
Contain
Preserve Evidence
Eradicate
Recover
Monitor

The key operational lesson is:

Encryption is often the final visible stage of a ransomware intrusion. Effective response requires identifying how the attacker entered, which identities and systems were compromised, whether data was stolen, whether recovery infrastructure remains trustworthy, and whether the attacker has truly been removed before restoration begins.

CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization

Section titled “CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization”

The next runbook shifts from active incident response to vulnerability management and risk-based remediation.

You will build a repeatable procedure for:

  • vulnerability scanner findings

  • CVE validation

  • CVSS interpretation

  • EPSS analysis

  • exploit availability

  • active exploitation

  • threat-intelligence enrichment

  • asset criticality

  • internet exposure

  • compensating controls

  • vulnerability false positives

  • remediation priority

  • patching decisions

  • mitigation

  • exception handling

  • remediation validation

  • vulnerability closure

The workflow progresses from:

Scanner Finding
Validate Vulnerability
Identify CVE
Review CVSS
Review EPSS
Check Exploitability
Check Active Exploitation
Assess Asset Criticality
Assess Exposure
Review Existing Controls
Determine Risk
Prioritize Remediation
Patch / Mitigate
Validate
Close

➡️ Next: CySA+ Runbook 07 — Vulnerability Triage and Remediation Prioritization