What evidence may show file encryption?¶
File encryption is supported when content was transformed so it no longer works normally without a key or recovery method. Changed extensions or inaccessible files can instead result from corruption, deletion, permissions or storage failure.
Link file change to a process¶
Preserve representative affected files and known-good originals, mass-modification timing, responsible processes and accounts, malware configuration, notes and errors. Content comparison and specialist analysis can distinguish encryption from other damage.
Determine the affected set, start and end times, skipped files, completion state and impact on backups or replicas. Capability in a recovered malware sample does not prove that sample changed these files.
Protect originals during recovery¶
Extension patterns are secondary to content and process evidence: some incidents retain names or affect only selected types. Preserve original encrypted examples before running recovery tools that alter data.
Successful controlled decryption can confirm a method. Failed recovery does not prove permanent loss or that an offender's decryptor would work. Record every test and preserve unchanged source copies.
Key takeaway
Prove encryption through transformed content, responsible process and timeline, while excluding corruption, deletion, permission change and general unavailability.