All playbooks
Incident scenarios · Incident responders and SOC leads
Ransomware, end to end
Access, then credentials, then movement, then encryption. You are almost never at the start of it.
By the time anything is encrypted the operator has usually been inside for days. Treat the first alert as the middle of the story, not the beginning.
What this does not establish
- How long they have been in. Dwell time is measured in days, not hours.
- Whether encryption is running now or is still being staged.
- Whether data already left. Exfiltration precedes encryption in most families.
0 of 11 ticked
Selected step
DetectStep 1 of 11
Confirm it is encryption, not a failing disk
- Mass rename with one extension, or a note file in many directories.
- A single host writing to hundreds of shares beats file counts as a signal.
- Start the timeline now: every action, who took it, when.