May 11

Webinar Takeaway: EMERGENCY WEBCAST: OK, let´s talk about ransomware…

0  comments

My key takeaways

  • 3 types of ransomware
    1. encrypt hard drive
    2. steal files and data and threat to release them
    3. both 1 & 2
  • Ransomware gangs usually have great customer support
    • it has become a serious business
  • It doesn’t matter if you consider your organsiation a valuable target, if at least some money could be extorted from you, you will become a target
  • Deception has become essential
    • Attivo Netwoks, Honeypots, Red Canary,….
    • HoneyDocs
    • HoneyAccounts
      • be aware to log in to it so the last login time is not empty!
      • needs to be enabled
  • Use RITA
  • market verticals calling themself "unique" are creating excuses for not doing the "right" thing
  • ransomware deletes all shadow copies using vssadmin pretty often; raccine may help here
  • there is some built-in ransomware protection in Windows, but not enabled by default

Env

additional links


Tags

blue team, deception, ransomware


You may also like

Webinar takeaway – How to Detect and Respond to Business Email (M365) Compromise

Webinar takeaway – How to Detect and Respond to Business Email (M365) Compromise

Webinar takeaway – Nuclear Ransomware 3.0: We Thought It Was Bad and Then It Got Even Worse

Webinar takeaway – Nuclear Ransomware 3.0: We Thought It Was Bad and Then It Got Even Worse
{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}