Handling Ransomware Incidents: What YOU Need to Know!

  Рет қаралды 17,090

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

Handling ransomware incidents is different from handling other types of incidents. What do you need to know and/or verify as you scope the incident? Have you established both an Incident Response Team team AND a Business Incident Response Team (BIRT)? Did you identify the threat actor pre-encryption or post-encryption? If pre, what steps do you take to avoid encryption? What steps do you take NOW to avoid further damage? Do you use a wait-and-see approach, or do you kick the actor out of your environment immediately? Join SANS FOR528: Ransomware for Incident Responders (sans.org/FOR528) course author Ryan Chapman in this conversational-style talk to discuss the how, what, and when when it comes to handling ransomware incidents.

Пікірлер: 8
@itguy1
@itguy1 3 ай бұрын
Awesome speaker, learned a lot and laughed my butt off quite a few times 😂😂
@PtolemyPetrie
@PtolemyPetrie 26 күн бұрын
It's actually very simple. Pull the drive of the affected machine, and plug into known good machine as a non booting drive, point your scanners at the affected drive, probably labeled e: or f: remove the ransomware once detected by your scanner. Alternatively you can boot a malware removal disc like Dr web, and point it at scanning the drive.
@TheRaghav12345678910
@TheRaghav12345678910 18 күн бұрын
??? You do know that ransomware encrypts the files right? Do you want to remove all the encrypted files? That defeats the whole purpose
@PtolemyPetrie
@PtolemyPetrie 18 күн бұрын
doesn't matter, you're not booting the drive. there are tools you can run to remove the infection, i have removed ransomware and free av and many scareware this way. The encrypted files are not removed.
@user-se1pt3mk3z
@user-se1pt3mk3z 4 ай бұрын
Absolutely Fantastic !! Learnt a lot.
@kacatley9258
@kacatley9258 3 ай бұрын
Tremendous work... great info and entertaining! Thanks!
@ByteBudsBites
@ByteBudsBites Ай бұрын
❤thank you
@MISTYEYED.
@MISTYEYED. 2 ай бұрын
❤🎉
FOR528: Ransomware & Cyber Extortion Course | SANS
3:57
SANS Digital Forensics and Incident Response
Рет қаралды 1,3 М.
Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think!
1:21:16
SANS Digital Forensics and Incident Response
Рет қаралды 25 М.
Joker can't swim!#joker #shorts
00:46
Untitled Joker
Рет қаралды 41 МЛН
Пройди игру и получи 5 чупа-чупсов (2024)
00:49
Екатерина Ковалева
Рет қаралды 4,3 МЛН
小丑把天使丢游泳池里#short #angel #clown
00:15
Super Beauty team
Рет қаралды 48 МЛН
When you discover a family secret
00:59
im_siowei
Рет қаралды 24 МЛН
The Truth about Ransomware: Its not Complicated!
1:26:09
SANS Digital Forensics and Incident Response
Рет қаралды 14 М.
Keynote: Cobalt Strike Threat Hunting | Chad Tilbury
45:45
SANS Digital Forensics and Incident Response
Рет қаралды 30 М.
APT 101: Understanding Advanced Persistent Threats
41:25
Hive Systems
Рет қаралды 10 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,6 МЛН
My “Aha!” Moment - Methods, Tips, & Lessons Learned in Threat Hunting - SANS THIR Summit 2019
33:41
SANS Digital Forensics and Incident Response
Рет қаралды 14 М.
Thinking DFIRently From Entry to Specialty
1:37:51
SANS Digital Forensics and Incident Response
Рет қаралды 2,8 М.
EDR, MDR & XDR Explained
10:33
Pro Tech Show
Рет қаралды 37 М.
What is a Zero Day Threat?
13:45
IBM Technology
Рет қаралды 13 М.
Google Pixel 9/Pro Review: Gimmick or Good?
24:05
Marques Brownlee
Рет қаралды 3,5 МЛН
Смартфоны миллиардеров 🤑
0:53
serg1us
Рет қаралды 1,2 МЛН
Yanlışlıkla Telefonumu Parçaladım!😱
0:18
Safak Novruz
Рет қаралды 7 МЛН
Сделал из зарядного устройства нечто!
0:48