, 7 tweets, 2 min read
My Authors
Read all threads
Ransomware Thread: One day a user clicked on a malicious link which caused some havoc - the company files got encryped with ransomware. Upon investigation looking at the headers of the email it was noted that the email had come from one of the DR servers. How? Why?

#infosec
Apparently the Exchange Admin had decided to carry out a DR test but not considered including the spam filter failover as part of the test. It was only meant to be a short while I mean what could possibly go wrong?

Also this was a known threat so why didnt the IPS block it?
Well turns out the DR mailbox IP’s had been added to an access policy but that policy had not been configured with file analysis. Therefore the email attachment went undetected - passed the firewall and since no spam filter was there ended up in the users mailbox.
Ok.... what about the AV? well again turns out the laptop had been off the network and signatures had not been updated too. Wow talk about Defence in Depth thats three layers passed already..
What made the task to recovery easier was that only that particular users department was impacted. Why? because the NTFS permissions applied on that file share were restricted to a very granular level which meant only that user and his team were impacted.
The files were restored from recovery. However many important lessons were learnt.
-Plan your DR properly
-Have incident reponse plans ready
-Don’t work in silo’s communicate your plans to each other
-Monitor endpoints especially AVs for missing signatures etc
-Defense in Depth can be a life saver
-Test backups are working

#infosec #ransomware #CyberSecurity
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Shak The Hack

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!