Active Ransomware Outbreak & Lateral Movement Containment
Step-by-step emergency incident response playbook for active ransomware infections. Immediate host isolation, process tree termination, C2 sinkholing, and VSS recovery.
1Phase 1: Immediate Network & Host Isolation
Sever Network & Wireless Interfaces on Patient Zero
Disconnect physical Ethernet cables and disable Wi-Fi/Bluetooth immediately. Do NOT power down the machine completely yet — volatile RAM contains unencrypted encryption keys and malware execution artifacts.
Block Malicious Lateral Ports at Firewall Perimeters
Block SMB (Port 445), RPC (Port 135), RDP (Port 3389), and WinRM (Port 5985/5986) between subnets to stop PsExec or WMI lateral movement.
2Phase 2: Process Triage & Cryptographic Key Preservation
Capture Volatile Memory Dump Before Reboot
Use WinPmem or LiME to dump RAM to an external sanitized write-blocked drive. In modern ransomware variants, private AES keys linger in process memory before C2 beaconing.
Terminate Ransomware Child Processes & Note Ransom Extension
Identify abnormal high-I/O processes modifying file extensions (e.g. .lockbit, .blackcat, .phobos) and suspend or kill them.
3Phase 3: Eradication, Backup Verification & Identity Rotation
Verify Immutable Offline Backups
Confirm that air-gapped or immutable S3/WORM backups have not been accessed or deleted. Validate that VSS shadow copies or secondary recovery snapshots exist.
Global Active Directory Credential Reset
Force a password and Kerberos ticket-granting service (KRBTGT) double-reset for all domain administrators and service accounts to invalidate golden tickets.
Prepare Your SOC Before the Next Breach
Receive weekly threat briefings, newly published containment playbooks, and mitigation scripts.
Weekly Executive Briefing
Top critical & high-severity threats, every week.
No spam. Unsubscribe anytime. SecOpsPulse may include sponsored security tool recommendations.