Incident report: Kesterline Components, 8 May 2026

A full DFIR report on a constructed ransomware incident, written the way one gets handed to a board. Three hours twenty from first execution to encryption, four separate points where it could have been stopped, and the write-up that follows.

This is a complete incident report on an invented company. The organisation, the people, the hashes and the addresses do not exist. Everything else, the technique sequence, the artifacts, the timings, the four points at which it could have been stopped, is how these actually go.

It is written the way a report gets handed over: an executive summary somebody will read in a lift, a timeline somebody will argue with, and a set of recommendations somebody will be asked to cost. Read it as a worked example of the writing as much as of the analysis. The evidence behind it is loaded in the lab console, so you can work the data first and then compare what you concluded against what went in the report.

Budget about two hours if you do both.


1. Executive summary

[!] members only

The rest of this teardown: the full timeline, the complete IOC list and the detection rule with its tuning notes, is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included