RANSOMWARE & CYBER EXTORTION RESPONSE
Ransomware Response
Built on Evidence.
Cyber Centaurs helps organizations respond to ransomware and cyber-extortion incidents by preserving critical evidence, investigating threat-actor activity, determining affected systems and accounts, evaluating potential data exfiltration, and supporting informed containment and recovery decisions.
24/7 Incident Response
WHEN TO ENGAGE
When Ransomware
Disrupts the Environment.
Ransomware incidents can involve far more than encrypted systems. Threat actors may obtain credentials, establish persistence, move through the network, access sensitive information, stage data, or maintain access before encryption becomes visible. Early investigation helps preserve the evidence needed to understand the incident.
Encrypted Servers or Workstations
Ransom Note or Extortion Demand
Threat Actor Claims of Data Theft
Suspicious Remote Access Activity
Compromised Administrative Credentials
Uncertain Scope or Initial Access
RESPONSE OBJECTIVES
Stabilize the Incident.
Preserve the Evidence.
The first priorities are to reduce ongoing risk, protect the available evidentiary record, determine the scope of threat-actor access, and support recovery without unnecessarily destroying evidence needed to understand what occurred.
Stabilize
Reduce immediate risk, identify known affected systems, and support containment decisions appropriate to the environment.
Preserve
Protect volatile and persistent evidence, logs, affected systems, cloud records, security telemetry, and other sources relevant to the investigation.
Investigate
Reconstruct initial access, credential use, persistence, lateral movement, execution, data access, and other threat-actor activity where evidence permits.
Support Recovery
Provide evidence-based findings that help inform eradication, restoration, credential resets, system recovery, and other remediation decisions.
INVESTIGATIVE EVIDENCE
Evidence Across the
Compromised Environment.
Ransomware investigations may require evidence from endpoints, servers, identity systems, cloud platforms, security tools, network infrastructure, and data repositories. Correlating those sources can help reconstruct threat-actor activity before, during, and after encryption. Related incident-response work may involve data breach investigation and incident response.
Endpoints & Servers
event logs
execution artifacts
services
scheduled tasks
persistence
file-system evidence
Identity & Authentication
account activity
authentication logs
MFA events
privileged access
credential use
Cloud & Email
Microsoft 365
Entra ID
cloud storage
audit records
account activity
Network & Security Telemetry
firewalls
EDR / XDR
DNS
proxy
network logs
security alerts
Data Access & Exfiltration
file access
staging
archive creation
cloud transfer
external sharing
potential exfiltration activity
Remote Access & Administration
VPN
RDP
remote-management tools
MSP access
administrative utilities
INVESTIGATIVE QUESTIONS
What Happened Before
the Encryption?
Encryption is often the final visible stage of a longer intrusion. The investigation should examine the activity that preceded it, determine what systems and accounts were involved, and evaluate what the available evidence supports concerning access, persistence, and data exposure.
How Did the Threat Actor Gain Access?
Evaluate available evidence concerning compromised credentials, exposed services, remote access, vulnerabilities, phishing, third-party access, or other potential entry activity.
Which Systems and Accounts Were Affected?
Determine the endpoints, servers, identities, administrative accounts, cloud resources, and other systems implicated by the available evidence.
How Did the Threat Actor Move Through the Environment?
Reconstruct relevant credential use, remote sessions, administrative tools, lateral movement, privilege changes, and other activity.
Was Persistence Established?
Examine evidence of services, scheduled tasks, accounts, remote tools, malware, configuration changes, or other mechanisms that may have enabled continued access.
Was Sensitive Data Accessed or Removed?
Evaluate evidence of file access, staging, archive creation, cloud transfers, external sharing, or other potential data-exfiltration activity.
What Must Be Addressed Before Recovery?
Identify supported indicators of compromise, affected accounts or systems, persistence concerns, and other findings relevant to eradication and restoration decisions.
RANSOMWARE RESPONSE PROCESS
Controlled Response.
Evidence-Based Recovery.
The response process is structured to establish control, preserve evidence, investigate the intrusion, determine impact, and support recovery decisions according to what the available technical record supports.
01
Triage & Stabilize
Establish immediate priorities, identify known affected systems, understand current containment actions, and assess ongoing risk.
02
Preserve & Collect
Protect and acquire relevant endpoint, server, identity, cloud, network, security, and other evidence before remediation changes the record.
03
Investigate Threat Activity
Analyze initial access, credential use, persistence, execution, lateral movement, administrative activity, data access, and encryption-related events.
04
Determine Scope & Impact
Correlate evidence to establish affected systems and accounts, evaluate potential data exposure, identify unresolved risks, and define the supported scope of the incident.
05
Support Recovery & Report
Provide findings relevant to eradication and restoration, document investigative conclusions and limitations, and communicate results to technical teams, leadership, counsel, and other authorized stakeholders.
BREACH IMPACT
Encryption Is Only
Part of the Question.
Modern ransomware incidents frequently include claims that sensitive information was accessed or removed before encryption. Those claims should be evaluated against the available evidence rather than accepted or dismissed without investigation.
File Access Activity
Evidence concerning access to sensitive folders, shares, repositories, or data sources.
Data Staging
Evidence of files being collected, reorganized, copied, or prepared for potential transfer.
Archive Creation
Creation or use of compressed archives and other mechanisms associated with data preparation.
External Transfers
Cloud uploads, file-transfer utilities, external sharing, remote destinations, or other potential transfer activity.
Threat Actor Claims
Comparison of extortion statements, sample files, leak claims, or other assertions against the available technical record.
Supported Breach Scope
Findings concerning confirmed activity, potential exposure, evidentiary limitations, and questions that remain unresolved.
RECOVERY DECISIONS
Recover With a Clearer
Understanding of the Incident.
Recovery should address more than encrypted files. Organizations need to understand what access the threat actor obtained, whether persistence remains, which credentials or systems require remediation, and what risks may remain when services return to operation.
Eradication Priorities
Identify supported indicators, persistence mechanisms, malicious tooling, compromised accounts, or other findings relevant to removing threat-actor access.
Credential & Identity Actions
Support decisions concerning password resets, privileged accounts, MFA, service accounts, remote-access credentials, and identity remediation.
System Restoration
Provide investigative context to help prioritize restoration, rebuilding, validation, and return-to-service decisions.
Residual Risk
Identify unresolved questions, unavailable evidence, remaining investigative concerns, or other factors decision-makers should understand during recovery.
WHY CYBER CENTAURS
Technical Depth.
Investigative Judgment.
Recovery decisions are stronger when the intrusion is understood.
Cyber Centaurs combines incident response, digital forensics, and cybersecurity expertise to investigate ransomware incidents, establish supported findings, and help organizations and counsel make informed containment, recovery, and breach-impact decisions.
Incident Response & Forensic Expertise
Technical investigation across endpoints, servers, identity, cloud, network, security telemetry, and other evidence sources.
Evidence-Driven Investigation
Findings are developed through collection, preservation, analysis, correlation, and validation rather than assumptions about threat-actor activity.
Breach Impact Analysis
Technical evidence is evaluated to help determine affected systems, account activity, potential data exposure, and the supported scope of the incident.
Support for Leadership & Counsel
Findings are communicated clearly to technical teams, executives, legal counsel, insurers, and other authorized stakeholders.
RANSOMWARE RESPONSE FAQ
Practical Questions
During a Ransomware Incident.
Ransomware incidents require rapid decisions while important facts are still developing. These questions address common considerations at the beginning of a ransomware investigation and recovery effort.
What should we do immediately after discovering ransomware?
Take reasonable steps to reduce ongoing risk and prevent further spread, but avoid unnecessary reimaging, deletion, log clearing, or other changes that may destroy useful evidence. Preserve affected systems and available logs where practical, document actions already taken, and contact an incident-response firm to assess investigative and containment priorities.
Should we shut down encrypted systems?
The appropriate action depends on the circumstances. Powering off a system may reduce some risks but can also eliminate volatile evidence. If immediate containment is necessary, take reasonable steps to protect the environment while considering evidence preservation and the operational consequences of the action.
Can you determine how the ransomware attack started?
We investigate available evidence for potential initial-access activity such as compromised credentials, remote access, exposed services, phishing, vulnerabilities, third-party access, or other intrusion paths. Whether a specific initial-access vector can be conclusively established depends on the evidence retained by the environment.
Can you determine whether data was stolen before encryption?
Cyber Centaurs evaluates evidence of file access, staging, archive creation, cloud transfer, external sharing, file-transfer utilities, and other potential exfiltration activity. Whether data removal can be conclusively established depends on the evidence available from affected systems, security tools, network infrastructure, cloud platforms, and other sources.
Can you help determine which systems are safe to restore?
Forensic findings can help identify affected systems, compromised accounts, persistence mechanisms, malicious tooling, and other indicators relevant to recovery decisions. Restoration decisions should consider the investigative findings together with the organization's remediation and recovery strategy.
Do you assist with ransomware negotiation or ransom payments?
Cyber Centaurs' primary role is incident response, forensic investigation, breach-impact analysis, and recovery decision support. If specialized ransomware negotiation or payment services are required, those services can be coordinated with appropriate authorized providers as part of the broader response where necessary.
Do you work with cyber insurers and legal counsel?
Yes. Cyber Centaurs can coordinate investigative work with internal and outside counsel, cyber-insurance stakeholders, executive leadership, IT teams, managed service providers, and other authorized participants involved in the response.
How quickly can ransomware response begin?
Cyber Centaurs maintains availability for urgent cybersecurity incidents. Initial priorities depend on the current state of the environment, containment actions already taken, affected systems, evidence availability, and the resources required for the response. For an active incident, call (877) 259-0509.
ACTIVE INCIDENT
Speak With an
Incident Response Investigator.
Tell us briefly what occurred, when ransomware or suspicious activity was discovered, which systems are affected, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.
Confidential inquiry. Please do not submit evidence, credentials, ransom notes containing sensitive information, or other sensitive files through this form.
