| Isolate, Don't Power Off |
Disconnect affected systems from the network: pull the cable, disable the NIC, or use EDR network isolation. Leave them running. |
Powering off destroys memory evidence and can corrupt encrypted volumes mid-write. |
| Protect the Backups |
Take backup infrastructure off the domain network NOW. Verify you have an offline or immutable copy before anything else. |
Modern crews destroy backups first. Your backups are the target, not the fallback. |
| Cut Remote Access |
Disable VPN, RDP exposure, RMM tools, and third-party remote access until each is verified clean. |
The initial access vector is usually still open, and they will come back through it. |
| Contain the Domain |
Reset privileged credentials, then rotate the krbtgt account twice. Audit new accounts and GPO changes. |
Assume domain admin is compromised. Golden tickets survive ordinary password resets. |
| Preserve Evidence |
Keep the ransom note, a sample encrypted file, and logs from firewalls, VPN, EDR, and domain controllers. |
Strain identification and the forensic timeline drive every downstream decision, including legal ones. |
| Establish Clean Comms |
Move incident coordination to out-of-band channels. Assume email and chat are monitored. |
Attackers read response plans in real time and adapt. |