Prévia do material em texto
LIFECYCLE OF A RANSOMWARE INCIDENT IMPACT ON TARGETCONSOLIDATION AND PREPARATION INITIAL ACCESS Attacker looks for a way into the network Attacker attempts to gain access to all devices Attacker steals and encrypts data, then demands ransom The common attack paths of a human-operated ransomware incident based on examples CERT NZ has seen. Phishing Valid credentials Exploit vulnerability Malicious document Internet- exposed service Malware Lateral movement Data exfiltration Destroy backups Encrypt data Privilege escalation Email Password guessing Command and control Phishing Valid credentials Exploit vulnerability Malicious document Internet- exposed service Malware Lateral movement Data exfiltration Destroy backups Encrypt data Privilege escalation Email Password guessing Command and control LIFECYCLE OF A RANSOMWARE INCIDENT CRITICAL CONTROLS KEY Internet-exposed services Backups Patching Application allowlisting MFA Logging and alerting Network segmentation Disable macros Principle of least privilege Password manager How the CERT NZ Critical Controls can help you stop a ransomware attack in its tracks. IMPACT ON TARGETCONSOLIDATION AND PREPARATION INITIAL ACCESS Attacker looks for a way into the network Attacker attempts to gain access to all devices Attacker steals and encrypts data, then demands ransom