ChecklistCONSTRUCTEDUntested

First 15 minutes: a ransom note, or files that suddenly will not open

Encryption is under way or has just finished. Contain without destroying the memory that holds the operator's tools, protect the backups, and start the clocks that legal and your insurer will ask about.

critical severityImpactT1486T1490

The clock starts when

A ransom note appears, files across a share change extension or will not open, or shadow copies and backup catalogues are deleted.

0 of 10 done
minutes 0 to 5

Stop the spread, keep the machines on

minutes 5 to 10

Find where it is coming from

minutes 10 to 15

Bring in the people who decide

Do not

  • Do not reboot or power off encrypted machines.
  • Do not restore from backup until you know how they got in, or you will restore into an open door.
  • Do not contact the operator, and do not let anybody else, until legal has decided.
  • Do not run a decryptor from the internet on the only copy of the data.

Escalate now if

  • Domain controllers, hypervisors or backup servers are affected.
  • Backups are deleted, encrypted or unreachable.
  • More than one site or business unit is affected.
  • There is evidence that data left before encryption.

Minute sixteen. The checklist ends here and the response does not.

Open the ransomware response plan

Why this order

Two instincts cause most of the lasting damage here. The first is to switch things off, which stops nothing that network isolation would not also stop and destroys the memory evidence. The second is to start restoring, which feels like progress and restores into an estate where the way in is still open.

The CISA guide says to power down only if you cannot disconnect. That is the line this checklist follows.

What this does not cover

Everything after the first fifteen minutes: scoping, eradication, recovery and notification. The response plan linked above takes it from here, and the first-hour playbook covers the rest of the first hour for whoever is at the keyboard.

sources

  1. CISA, MS-ISAC, NSA and FBI: #StopRansomware Guide · primary
  2. MITRE ATT&CK T1486, Data Encrypted for Impact
  3. NCSC (UK): mitigating malware and ransomware attacks

Tags: first-15 · ransomware · containment · backups · T1486 · T1490