Malware & RansomwareCritical SeverityEstimated SLA: 15 - 45 Minutes

Active Ransomware Outbreak & Lateral Movement Containment

Step-by-step emergency incident response playbook for active ransomware infections. Immediate host isolation, process tree termination, C2 sinkholing, and VSS recovery.

Triage Progress0 of 6 Steps (0%)

1Phase 1: Immediate Network & Host Isolation

Sever Network & Wireless Interfaces on Patient Zero

Disconnect physical Ethernet cables and disable Wi-Fi/Bluetooth immediately. Do NOT power down the machine completely yet — volatile RAM contains unencrypted encryption keys and malware execution artifacts.

Get-NetAdapter | Disable-NetAdapter -Confirm:$false
Automate with CrowdStrike Falcon:Deploy Network Containment via EDR Console

Block Malicious Lateral Ports at Firewall Perimeters

Block SMB (Port 445), RPC (Port 135), RDP (Port 3389), and WinRM (Port 5985/5986) between subnets to stop PsExec or WMI lateral movement.

iptables -A FORWARD -p tcp --dport 445 -j DROP
Automate with Cloudflare One:Isolate Segment via Zero Trust Gateway

2Phase 2: Process Triage & Cryptographic Key Preservation

Capture Volatile Memory Dump Before Reboot

Use WinPmem or LiME to dump RAM to an external sanitized write-blocked drive. In modern ransomware variants, private AES keys linger in process memory before C2 beaconing.

winpmem.exe -o memdump.raw

Terminate Ransomware Child Processes & Note Ransom Extension

Identify abnormal high-I/O processes modifying file extensions (e.g. .lockbit, .blackcat, .phobos) and suspend or kill them.

Get-Process | Where-Object { $_.CPU -gt 50 } | Stop-Process -Force
Automate with Malwarebytes:Execute 72-Hour Ransomware Rollback

3Phase 3: Eradication, Backup Verification & Identity Rotation

Verify Immutable Offline Backups

Confirm that air-gapped or immutable S3/WORM backups have not been accessed or deleted. Validate that VSS shadow copies or secondary recovery snapshots exist.

vssadmin list shadows

Global Active Directory Credential Reset

Force a password and Kerberos ticket-granting service (KRBTGT) double-reset for all domain administrators and service accounts to invalidate golden tickets.

Reset-KrbTgtKey.ps1
Share Intel:Share on XLinkedIn

Prepare Your SOC Before the Next Breach

Receive weekly threat briefings, newly published containment playbooks, and mitigation scripts.

Weekly Executive Briefing

Top critical & high-severity threats, every week.

No spam. Unsubscribe anytime. SecOpsPulse may include sponsored security tool recommendations.