Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Service

Attack Forensics & Attribution

  • Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.

Reconstruct the attack timeline and entry point from logs, images and memory evidence, assess whether data was exfiltrated, and deliver a traceable forensic report.

What this service covers

Forensics answers three questions: how the attacker got in, what they did inside, and whether they took data out. Those answers drive remediation, and they determine whether the organization has defensible material for police reporting, regulator communication and notifications to customers and partners.

What the engagement covers

  • Evidence acquisition following forensic procedure: disk images, memory captures, edge-device and server logs, each recorded with acquisition time, hash and responsible engineer so the chain of custody holds.
  • Entry-point determination across internet-exposed services, VPN and RDP accounts, edge appliance and middleware vulnerabilities, phishing, third-party administration channels and the supply chain.
  • Timeline reconstruction from initial access through privilege escalation, lateral movement, credential theft, defence evasion, data staging and exfiltration, to the final deployment of the encryptor — each step annotated with time and evidence source.
  • Exfiltration assessment, combining outbound traffic records, archiving and staging artifacts, traces of cloud storage or transfer tooling, and postings on the actor's leak site, to judge likelihood and the data categories involved.
  • Reporting: a forensic report that separates conclusions into confirmed, highly likely and undetermined, with an evidence index and technical appendices.

Limits

Forensic conclusions are bounded by the evidence. Where logging was off, retention was too short, the attacker wiped records, or a host has already been reinstalled, some steps cannot be reconstructed — and we mark those as undetermined in the report rather than filling the gap with a tidy-looking story. We also do not name individual attackers: open-source intelligence can support attribution to a family or crew, but identifying individuals is the remit of law enforcement. The report is suitable for filing a case with the public security authorities and for internal compliance records; whether a case is opened and how it is ultimately characterized is for the authorities to decide.

Deliverables

  • Evidence inventory: image and log sources, acquisition times, hash values
  • Attack timeline report, each step annotated with evidence source and confidence level
  • Entry point and root cause determination, with reproducible supporting evidence
  • Exfiltration assessment and the data categories potentially involved
  • Indicator-of-compromise list and inventory of laterally affected assets
  • Prioritized remediation checklist ordered by urgency

How it works

  1. Scope definition and preservation

    We confirm the purpose of the engagement with the client — police reporting, compliance records, internal accountability, insurance — and the scope boundary: which systems may be imaged and which data must not leave the premises. Evidence is then frozen and any operation that would overwrite logs or disks is paused.

  2. Acquisition and integrity verification

    We acquire disk and memory images from key hosts, domain controller and server logs, firewall, VPN and traffic logs, and logs from the virtualization and backup platforms. Everything is hashed and registered so the chain of custody is traceable.

  3. Artifact analysis and correlation

    We analyse authentication records, process and service creation, scheduled tasks, registry and persistence artifacts, remote-access and penetration tooling traces, and filesystem timelines, correlating them in time with outbound traffic records to locate initial access and the lateral path.

  4. Exfiltration assessment and intelligence matching

    We check for bulk outbound transfers, unusual archiving activity and use of cloud storage or transfer utilities. The ransom note, encryption characteristics and open-source intelligence are matched to attribute the family or crew, and we search the actor's leak site for related postings.

  5. Reporting and support for filing a case

    We issue the forensic report: conclusion summary, timeline, evidence index, IOC list and remediation recommendations. On request we support the client in submitting material to the public security authorities, responding to regulator enquiries, and briefing management once on the findings.

When to use it

  • A case is being filed with the police and technical forensic material is required
  • A regulator, group head office or customer requires an incident investigation report
  • Data is suspected to have been stolen and the exfiltration scope must be assessed
  • The same environment keeps getting breached and the real entry point must be found
  • Responsibility boundaries with an outsourced administrator, vendor or insider need to be established
  • An insurance claim or contractual dispute requires an independent technical conclusion

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related ransomware families

Related questions

FAQ

Frequently asked questions

  • Can the forensic report be used directly to file a police report?

    Yes, as the technical material submitted with the report. It contains the incident timeline, entry-point determination, compromised asset inventory, indicators of compromise and an evidence index, so investigators can grasp the case quickly.

    Note that whether a case is opened and how it is characterized is decided by the public security authorities under law; we supply technical support and material, not an investigative conclusion. Filing early is generally advisable, before evidence expires or is overwritten.

  • How do you determine whether data was actually stolen?

    Four categories of evidence: the direction, volume and timing of outbound traffic; archiving activity and staging directories on hosts; use of cloud storage clients, command-line transfer tools or remote-access file transfer; and whether the actor's leak site has published the organization's data.

    When all four point the same way the conclusion is strong. Where traffic logs are missing we can only give a likelihood based on host artifacts, and the report states that uncertainty explicitly.

  • Operations are already restored — is forensics still worth doing?

    It is. If the entry point is unknown, the same path is likely to be reused — re-encryption within weeks of a restore is something we have handled repeatedly.

    Beyond that, whether data left the network affects notification duties and residual risk, and remediation needs a root cause to aim at. As long as logs and images have not been overwritten, earlier forensics means firmer conclusions.

  • Will forensics take our sensitive data off-site?

    Not beyond what was agreed. The scope, handling method and storage location are confirmed in writing before work starts; for classified or highly sensitive environments we can work entirely on site so that no data leaves the premises and only the analytical conclusions are taken away.

    All client data we touch is handled under the confidentiality terms, working copies are deleted within the agreed period after the engagement, and a deletion confirmation can be issued.

Updated