Summary
Ransomware is a threat that will be around us for the foreseeable future. In this chapter, we looked at the history of ransomware, the common TTPs in use by threat actors such as Conti, how to align our incident response to that threat, and finally how to contain, eradicate, and recover from it. Understanding these TTPs gives us insight into how to detect and prevent such attacks. Understanding the response element allows us to respond appropriately and limit the impact.
In the next chapter, we will examine specific investigative and analysis techniques.