A cyber incident may be relevant to my investigation. What happens next?¶
A logistics company reports that dispatch files are being encrypted, staff cannot access delivery schedules and a ransom note has appeared on several systems. The incident is still developing. This walkthrough separates urgent harm reduction from evidential preservation, works below the security alerts to the source events and develops the account, session and device evidence towards a suspect.
The incident can be established before the offender is known. Attribution develops by preserving and correlating what the affected systems, providers, responders and suspect devices independently recorded.
The incident report¶
INC-6207FILE-03, dispatch application and backup console.AL-88021: rapid file modifications under administrative session SES-4C18.The security alert is a lead produced by a detection rule. An alert does not by itself prove an attack, while the inaccessible files, system events and ransom note provide direct evidence of disruption that must be explained.
FILE-03 and session SES-4C18Still open the full incident scope, how the session was obtained and who controlled itWork the live incident¶
01 · Establish what is happening now
The incident is continuing on two network segments, but dispatch safety is maintained through manual procedures and the affected servers can be isolated.
Whether an incident is still happening determines the urgency and the evidence at risk. Record affected services, business impact, safety concerns, current sessions and the actions already taken. Assess continuing harm before treating preservation as a reason to leave damaging activity running.
Identify the system owner, incident lead, technical contacts and investigator. One person may perform several roles, but the decisions should remain clear. Specialist support is particularly important where live malware, encrypted systems, cloud accounts or business-critical services are involved.
02 · Preserve what response activity may change
Endpoint telemetry, active-session details, authentication records, backup audit events, the ransom note and response communications are preserved before routine retention or containment removes context.
Evidence may disappear quickly through log rollover, session termination, volatile memory loss, provider retention or system rebuild. Immediate preservation should focus on relevant volatile and short-lived records, not indiscriminately copy every system.
Isolation and account revocation may be necessary. Record the source state and action first where safely possible, then document what changed. Containment can affect remote-session evidence, but that is a reason for coordination and recording - not for allowing harm to continue.
03 · Go below the alert and ransom note
Authentication, remote-access, endpoint and backup events establish a coherent sequence before the first file-encryption alert.
Ask which underlying records support the alert. The alert explains why activity was noticed; source events describe what the systems recorded. The ransom note establishes a demand and may reveal wording or identifiers. A ransom note does not identify its author.
nv-support authenticates and creates session SES-4C18.JOB-2218.ADMIN-07 begins remote administration of FILE-03.NW-README-77 is created.Ransomware may involve more than encryption. Here the source events support deliberate disruption and attempted backup interference. They do not yet prove data theft, and encryption does not establish exfiltration.
04 · Reconstruct access, control and purpose
The active session uses a support account assigned to former contractor Nora Bell and connects through a device not enrolled to Northway.
The account was left active after Nora's contract ended. That is a control failure and a strong line of enquiry, not proof that Nora used it. A successful login does not prove the password was known; stolen sessions or credentials remain possible.
Identity records show a fresh authentication rather than a reused Northway session. Remote-access logs associate it with browser instance BR-8824 and source address 198.51.100.143. Relevant-time subscriber records resolve the connection to Nora's home service. An address identifies a connection, not the person at the keyboard, but it independently aligns the account, time and access route.
Endpoint events record the same session viewing backup status, accessing selected dispatch shares and creating the ransom note. Evidence showing the sequence of a ransomware incident and deliberate disruption is stronger than the generic label “ransomware attack”.
nv-support, session SES-4C18 and browser BR-8824 carried the recorded access and disruption sequence.05 · Join the incident to suspect evidence
A laptop lawfully recovered from Nora contains the relevant browser profile, remote-access records and a draft matching the ransom note's distinctive wording.
The browser profile records session SES-4C18 and access to Northway's support portal. Local remote-client history identifies ADMIN-07. A text file predating the incident contains the unusual phrase and payment reference used in note NW-README-77. Messages with an associate discuss Northway's backup arrangements and a share of any payment, without containing technical instructions.
No single fact carries the attribution. Assigned account, fresh authentication, relevant-time home connection, matching browser and remote-client records, distinctive note material and communications independently converge on Nora. This is strong circumstantial evidence, while the associate's role and any alternative access remain testable propositions. Ransomware attribution should distinguish incident facts, infrastructure or tooling similarities and evidence linking human actors.