What Happens in the First 24 Hours of a Ransomware Attack

· Original article ↗

Summary

A practical, hour-by-hour guide to ransomware response stresses confirming the scope, containing access, investigating possible data theft and root cause, testing backups, and rebuilding in a clean environment.

Key points

  • Ransomware encryption may occur well after initial access: Mandiant's cited 2026 report puts median dwell time at 14 days and the median hand-off between threat groups at 22 seconds.
  • Confirm ransomware and assess the blast radius across endpoints, file shares, domain controllers, and virtualization systems before deciding on containment.
  • Containment choices involve trade-offs: network isolation can preserve forensic evidence, while powering off a host may stop active encryption but destroy useful memory evidence.
  • Treat data theft as possible and investigate unusual outbound volumes and destinations; the cited CISA Akira advisory describes exfiltration within just over two hours of initial access.
  • Test a real backup restore and verify its isolation and immutability before promising recovery times; attackers may target backup infrastructure.
  • Determine the entry point and credential exposure before rebuilding, then restore into a clean environment with trusted identity systems first.
  • Assign decision-makers and deputies in advance for operational shutdowns, notifications, and ransom-related decisions.

Article Details

Defense Focus
Confirm and contain ransomware in the first 24 hours while determining whether data was exfiltrated, credentials were compromised, and backups can support a clean recovery.
Detection Methods
  • Check for ransom notes on multiple hosts, changed file extensions across shares, and mass file modification by a single process.
  • Scope affected endpoints, file shares, domain controllers, and the virtualization layer.
  • Hunt for unusual outbound data volume to unusual destinations, including consumer cloud endpoints, at unusual times.
  • Trace the first account used and review the systems it accessed in the 30 days before encryption.
Data Sources
  • Endpoint detection and response alerts and process activity
  • Host and file-share observations
  • Outbound traffic volume and destination records
  • Domain controller authentication logs
  • Backup job results and restore tests
  • Backup-console immutability and object-lock settings
Platforms
  • Endpoint detection and response console
  • Backup console
  • Domain controllers
  • Virtualization management plane
Defensive Actions
  • Isolate affected hosts through the EDR console where possible; preserve memory unless powering off is the only way to stop active encryption.
  • Close exposed remote-access paths early, subject to documented operational dependencies, and verify multi-factor authentication is enforced.
  • Investigate outbound transfers and involve legal counsel when assessing possible data theft.
  • Restore and open a real file from the newest backup before promising a recovery time; verify immutability and prior full-restore tests.
  • Determine the entry point and credential scope before rebuilding, then restore into a clean environment with trustworthy identity services first.
  • Assign incident, shutdown, notification, and ransom-decision authorities and deputies in advance.

MITRE ATT&CK

Malware

Vendors

Tools

Cobalt StrikeUnderDefense's account of a Colorado engagement describes moving from detecting Cobalt Strike to removing it from 11 critical servers in under 24 hours, which is achievable only when the entry point and the credentialFileZillaThe tooling is ordinary, which is why it survives a casual log review. The advisory names FileZilla and WinRAR for staging, WinSCP and RClone for transfer, Mega for cloud storage and Ngrok for tunneling, nearly all ofLaZagneinvestigation lives. CISA's advisory documents Akira operators dumping credentials with Mimikatz and LaZagne, pulling them from LSASS memory, and running Kerberoasting against service accounts. Any of those meansMimikatzis where this investigation lives. CISA's advisory documents Akira operators dumping credentials with Mimikatz and LaZagne, pulling them from LSASS memory, and running Kerberoasting against service accounts. Any ofNgroknames FileZilla and WinRAR for staging, WinSCP and RClone for transfer, Mega for cloud storage and Ngrok for tunneling, nearly all of it software your admins have a legitimate reason to run.RCloneis why it survives a casual log review. The advisory names FileZilla and WinRAR for staging, WinSCP and RClone for transfer, Mega for cloud storage and Ngrok for tunneling, nearly all of it software your admins haveWinRARThe tooling is ordinary, which is why it survives a casual log review. The advisory names FileZilla and WinRAR for staging, WinSCP and RClone for transfer, Mega for cloud storage and Ngrok for tunneling, nearly all ofWinSCPwhich is why it survives a casual log review. The advisory names FileZilla and WinRAR for staging, WinSCP and RClone for transfer, Mega for cloud storage and Ngrok for tunneling, nearly all of it software your

Industries

Related Articles