Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What evidence may show file encryption?

File encryption is supported when content was transformed so it no longer works normally without a key or recovery method. Changed extensions or inaccessible files can instead result from corruption, deletion, permissions or storage failure.

Preserve representative affected files and known-good originals, mass-modification timing, responsible processes and accounts, malware configuration, notes and errors. Content comparison and specialist analysis can distinguish encryption from other damage.

Determine the affected set, start and end times, skipped files, completion state and impact on backups or replicas. Capability in a recovered malware sample does not prove that sample changed these files.

Protect originals during recovery

Extension patterns are secondary to content and process evidence: some incidents retain names or affect only selected types. Preserve original encrypted examples before running recovery tools that alter data.

Successful controlled decryption can confirm a method. Failed recovery does not prove permanent loss or that an offender's decryptor would work. Record every test and preserve unchanged source copies.

Key takeaway

Prove encryption through transformed content, responsible process and timeline, while excluding corruption, deletion, permission change and general unavailability.

Reference: CIM-177Cyber Incidents & Offender Methods