Ransomware Preparation and Response
With the availability of cryptocurrency, threat actors have been given the necessary tools to extract payment from victims without fear of being caught. This has led directly to the rise of ransomware, an attack where threat actors deploy malware that encrypts the victim’s files and extorts payment for the victim to get them back. Over the last 10 years, the development of more sophisticated tools and techniques to compromise victims has led to ransomware attacks impacting governments, large healthcare institutions, and major corporations, all to extract the maximum amount of ransom to enrich the various threat actors.
Given the prolific nature of ransomware, it is a good bet that incident responders will have to respond to these types of attacks. To address incidents involving ransomware more effectively, analysts should be familiar with the tactics and techniques, along with the response actions, that will bring them back up and running...