Services
Ransomware emergency services
From identification and decryption through data recovery, forensic attribution and hardening, covering the full lifecycle of a ransomware incident.
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
For organizations whose servers, databases or virtualization platforms have been encrypted: family identification, recoverability assessment and multi-path data extraction, with no ransom payment.
- Family and variant identification, with the evidence and sample analysis behind it
- Recoverability assessment report: recoverable scope, available paths, expected outcome and risks
- Decryption and repair plan, with recovery priorities and downtime windows
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Emergency handling while an incident is still spreading or the attacker may still have access: contain the blast radius, remove persistence, preserve evidence, and open a safe window for recovery.
- Response log and incident timeline covering detection, containment, eradication and re-check
- Affected asset inventory and blast-radius conclusion
- Containment checklist: accounts disabled, channels closed, artifacts removed
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
When direct decryption is not viable, we recover usable production data through backup and snapshot repair, file-level database repair, and extraction of unencrypted remnants and fragments.
- Survey findings: extent of encryption, backup usability, integrity of the storage structure
- Per-path recovery plan with priorities across backup restore, database repair and remnant extraction
- Delivery manifest for recovered data, annotated by system and point in time
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Reconstruct the attack timeline and entry point from logs, images and memory evidence, assess whether data was exfiltrated, and deliver a traceable forensic report.
- Evidence inventory: image and log sources, acquisition times, hash values
- Attack timeline report, each step annotated with evidence source and confidence level
- Entry point and root cause determination, with reproducible supporting evidence
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
Hardening built around the intrusion paths ransomware actually uses: shrink internet exposure, fix credentials and remote access, patch high-risk flaws, reduce privilege, and rebuild backups that cannot be deleted.
- External exposure inventory with a before-and-after comparison
- Hardening checklist: item status, owner, verification method and result
- Remote access and account privilege remediation plan, including MFA rollout guidance
Our process
A standard process with a deliverable at every step
The process is transparent. You get the assessment first and decide whether to continue.
Intake & containment
We answer 24/7 and immediately walk you through isolating systems and preserving evidence so the encryption stops spreading.
Sample analysis & family identification
We analyze encrypted samples and the ransom note to confirm the family, the variant and the encryption characteristics.
Recoverability assessment & quote
Weighing decryptors, backups, snapshots and database structure, we document what can realistically be recovered and quote a firm price.
Recovery & business validation
We recover in business-priority order, verify data integrity item by item and validate the systems together with your teams.
Attribution & hardening
We reconstruct the intrusion path, deliver a forensic report, close the entry point and harden accounts and backups against reinfection.