Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may show the sequence of a ransomware incident?

Reconstruct ransomware from the earliest supported foothold through disruption, extortion and response. The first encrypted file is usually an impact time, not necessarily the incident start.

Build linked system timelines

Align authentication, remote access, privilege changes, discovery, movement, defensive tampering, backup access, collection, staging, transfer, encryption, note creation, communications and payment activity. Preserve native time zones, clock drift, accounts, hosts and process chains.

In a large environment, one host may preserve entry, another staging and a management system encryption deployment. Separate system timelines avoid false organisation-wide precision.

Allow multiple sessions and actors

Do not force gaps into one continuous operator session. Some stages may be automated, absent or performed by different accounts or people. Simultaneous deployment may still appear at slightly different host times.

Keep event, alert, discovery and response times separate. If entry remains uncertain, state the earliest proved event and alternatives while continuing to report later stages confidently where supported.

Key takeaway

Reconstruct linked, clock-aware timelines from first supported access to extortion, preserving gaps, multiple systems and distinct detection and response times.

Reference: CIM-179Cyber Incidents & Offender Methods