How to run a ransomware investigation: five phases from containment to recovery
Why digital forensics belongs in every stage of ransomware response
Key takeaways
- A ransomware investigation has to scope the whole intrusion, because encryption is often the final stage of attacker activity that began days or weeks earlier.
- Every containment action changes the evidence. Capture volatile evidence from priority systems before shutdown or reimaging whenever possible.
- A backup isn’t clean just because it pre-dates encryption. It needs to pre-date attacker access.
- Forensic readiness has to be in place before an incident: logging, collection options, defined roles, and evidence-handling procedures.
Ransomware is much more than an encryption event. Modern ransomware incidents often combine credential compromise, lateral movement, persistence, data staging and exfiltration, encryption, and extortion. An effective ransomware response requires more than restoring systems or stopping encryption. It requires a fact-based investigation that preserves evidence, reconstructs attacker activity, determines the full scope of impact, and uses those findings to guide containment, remediation, and recovery.
This post walks through what a ransomware investigation looks like in practice, from the first minutes of containment to the final report, and how to prepare before the next incident.
Core principle of a ransomware response: contain with purpose
Every action taken during incident response changes the environment investigators are trying to reconstruct. Isolating a host, terminating a process, resetting credentials, or restoring a system may stop the immediate threat, but those same actions can also alter or destroy evidence that reveals how the attacker gained access, how far they moved, and what they touched.
The goal is not to slow containment. It’s to contain with purpose. Preserve critical volatile evidence when feasible, stop active harm, and retain enough forensic visibility to reconstruct the attack. That visibility is what allows the response team to move beyond simply stopping what is happening now and determine what happened before containment, the true scope of compromise, what data or systems may have been affected, and what must be remediated before the environment can safely return to service.
What makes ransomware investigations different
Ransomware creates immediate operational pressure because encryption can disrupt essential services within minutes. At the same time, the ransomware payload may represent only the final stage of a longer intrusion. Attackers may have gained access days or weeks earlier, established persistence, stolen credentials, moved laterally, accessed backups, staged data, and exfiltrated sensitive information before encryption begins.

That creates two simultaneous objectives:
- Stop active attacker activity and prevent additional encryption, lateral movement, or data loss.
- Preserve and analyze the evidence needed to determine root cause, scope, attacker actions, data exposure, and the requirements for safe remediation and recovery.
Ultimately, the investigation needs to answer the questions that determine what happens next:
- How did the attacker first gain access?
- Which endpoints, servers, accounts, cloud services, and network resources were affected?
- What persistence mechanisms, backdoors, or unauthorized accounts were created?
- How did the attacker move through the environment?
- Was data accessed, staged, or exfiltrated before encryption?
- When did attacker activity begin, and what recovery points pre-date the compromise?
- What must be remediated before systems and accounts can safely return to service?
The five phases of a ransomware investigation
Answering those questions while an incident is still unfolding takes a structured approach. A ransomware response is most effective when digital forensics is integrated throughout the incident response lifecycle. The workflow below uses five practical phases that connect rapid response with deeper forensic analysis.

Phase 1: Initial response and evidence-guided containment
The first priority is to stop ongoing harm, but response actions can also destroy volatile evidence or alert an attacker who still has access through another foothold. Initial triage should therefore identify what requires immediate isolation and what evidence to preserve first.
Initial triage should focus on:
- Identifying systems showing ransomware indicators, such as encrypted files, ransom notes, unusual file extensions, suspicious processes, abnormal authentication activity, or unexpected network connections.
- Using EDR and security telemetry to identify likely affected systems, compromised accounts, active sessions, and signs of lateral movement.
- Determining whether ransomware activity is still active and which systems or resources require immediate containment.
- Capturing volatile evidence from priority systems before shutdown, reimaging, or other destructive response actions.
- Isolating affected endpoints, restricting network shares, revoking compromised credentials, or blocking attacker infrastructure as required to stop further damage.
Why volatile evidence matters
Live memory, running processes, active network connections, in-memory malware, decrypted credentials, user sessions, encryption material, and short-lived command artifacts may disappear when a system is powered off, rebooted, or otherwise altered. Preserving this evidence can materially affect the ability to identify the ransomware process, understand attacker activity, or reconstruct the intrusion.
Phase 2: Evidence collection and building the forensic record
Once immediate containment priorities are addressed, investigators should build a forensic record that supports both rapid scoping and deeper analysis. Collection should be driven by investigative questions and risk, using targeted or full acquisitions as appropriate to the system and the role it played in the incident.
For isolated or restricted systems, local or offline forensic acquisition can preserve evidence without reconnecting the endpoint to the production network. Remote collection can also support distributed investigations when endpoints remain reachable and organizational policy permits it.
The most valuable evidence depends on the attack path and the questions investigators need to answer. The following categories commonly provide critical context in ransomware cases.
| Evidence category | Examples | Investigative value |
|---|---|---|
| Memory and volatile data | RAM, processes, active connections, sessions, decrypted material | Can reveal running ransomware, attacker tools, short-lived activity, credentials, and other evidence that may disappear after shutdown. |
| File system and execution artifacts | MFT metadata, Prefetch files, LNK files, Jump Lists, scripts, command history | Supports timeline reconstruction and identifies execution, staging, tool use, and user or attacker activity. |
| System and application logs | Windows Event Logs, Sysmon, application and security logs | Shows authentication, process execution, service activity, remote access, and other events across the attack timeline. |
| Registry and persistence artifacts | Run keys, services, scheduled tasks, configuration changes | Helps identify persistence, execution mechanisms, and changes made to maintain access. |
| Identity and remote-access evidence | VPN, IdP, RDP, authentication logs, account activity | Supports analysis of credential compromise, initial access, lateral movement, and account misuse. |
| Network evidence | Firewall, proxy, DNS, connection history, C2 indicators | Can identify command-and-control, lateral movement, staging locations, and potential exfiltration paths. |
| Malware and ransomware artifacts | Executables, ransom notes, hashes, encrypted files, scripts | Helps identify ransomware behavior, related tooling, and technical indicators for broader scoping. |
| Backup and recovery evidence | Backup logs, snapshots, recovery points, deletion activity | Supports recovery decisions and can reveal attempts to impair restoration or destroy backups. |
| Email and cloud evidence | Phishing messages, cloud audit logs, file-sharing activity | May identify initial access, cloud persistence, data access, or exfiltration outside the endpoint. |
Phase 3: Reconstructing the attack and scoping impact
Analysis turns collected evidence into an evidence-based account of the intrusion. Naming the ransomware family is just the starting point. Investigators need to reconstruct the attacker’s path from initial access through impact and determine which systems, accounts, and data were affected.
Key forensic tasks include:
- Determine the initial access vector, such as phishing, exposed remote services, stolen credentials, exploitation of a vulnerability, or another point of compromise.
- Identify the ransomware executable, supporting scripts, tools, and related malware, and correlate hashes, filenames, paths, and execution evidence.
- Reconstruct attacker activity using timestamps, logs, file-system metadata, memory, registry artifacts, and network evidence.
- Map lateral movement, credential access, privilege escalation, remote execution, persistence, and defense-evasion activity.
- Identify data staging, archive creation, unusual file access, cloud transfers, outbound connections, or other indicators of exfiltration.
- Determine the earliest confirmed attacker activity to establish the compromise window and support recovery-point decisions.
- Correlate behavior to MITRE ATT&CK where useful to communicate attacker tactics, techniques, and procedures consistently.
A critical outcome is accurate scoping. Ransomware response cannot stop at the systems that were visibly encrypted. Forensic analysis should determine where the attacker was present, what accounts were used, what data was accessed or removed, and whether additional systems may contain persistence or residual access even if they were not encrypted.
Phase 4: Turning forensic findings into remediation and recovery
Recovery should be guided by what the investigation learned from the compromised environment. Findings from affected systems provide the intelligence remediation teams need to understand what must be fixed, rebuilt, reset, or monitored.
Forensic findings can identify:
- The initial point of compromise and the vulnerabilities, misconfigurations, or compromised credentials that need to be addressed.
- Persistence mechanisms such as services, scheduled tasks, startup locations, web shells, remote-management tools, or unauthorized accounts that must be accounted for during remediation.
- Compromised credentials, tokens, accounts, and access paths that should be reset, revoked, or otherwise secured.
- The extent of lateral movement so remediation includes additional endpoints, servers, accounts, and infrastructure touched by the attacker.
- The compromise timeline so teams can identify backups and recovery points created before attacker access began.
- Attacker behaviors and indicators that can be translated into stronger EDR detections, monitoring, segmentation, identity controls, and alerting.
Backup restoration requires timeline context.
A backup created before encryption is not necessarily a clean backup if the attacker had already established persistence or staged tools in the environment. The investigation should help establish when attacker access began and which recovery points are most appropriate for restoration or rebuilding.
Recovery actions may include rebuilding affected systems, restoring validated data and services, patching exploited vulnerabilities, changing credentials, removing persistence, hardening configurations, improving network segmentation, and deploying enhanced monitoring based on observed attacker techniques.
Phase 5: Documentation, reporting, and post-incident improvement
Ransomware investigations often support executive decision-making, legal and regulatory review, insurance requirements, customer communications, and future security improvements. Documentation should clearly distinguish observed evidence, investigative conclusions, and response actions.
A final report should document, as appropriate:
- Initial access vector and root cause findings.
- Timeline of attacker activity and ransomware execution.
- Affected systems, accounts, cloud resources, and business services.
- Evidence of credential access, persistence, lateral movement, and privilege escalation.
- Whether data was accessed, staged, or exfiltrated and the basis for that conclusion.
- Ransomware and related malware findings, indicators of compromise, and observed attacker infrastructure.
- Forensic collection and analysis methodology.
- Containment, remediation, and recovery actions informed by the investigation.
- Lessons learned and recommended updates to logging, collection readiness, backups, access controls, EDR detections, and incident response procedures.
Three decisions forensic evidence should drive
Taken together, the five phases support three decisions that shape how well an organization recovers:
- Understand the true scope: Determine where the attacker was present, which identities and systems were affected, and whether the compromise extends beyond visibly encrypted endpoints.
- Remediate the intrusion, not just the symptoms: Use findings around initial access, persistence, credential compromise, and lateral movement to determine what needs to be removed, reset, patched, or monitored.
- Recover from a known-good point: Use the compromise timeline to evaluate whether backups and recovery points pre-date attacker access, rather than simply pre-date encryption.
How Magnet Forensics supports ransomware investigations
Investigators rarely obtain the complete story from a single endpoint or evidence source. Ransomware investigations require teams to preserve evidence from isolated and distributed systems, correlate activity across endpoints and cloud sources, and reconstruct a defensible timeline of attacker activity.
Several Magnet capabilities support different stages of the ransomware investigative workflow:
- Magnet Axiom Cyber for deep artifact parsing, timeline reconstruction, endpoint and cloud evidence analysis, and integrated IOC, YARA, and Sigma-based investigative workflows.
- Magnet Nexus for secure, scalable remote collection across distributed environments when endpoints remain available for remote acquisition.
- Magnet Response for local or offline acquisition from isolated systems where maintaining network containment is required.
These capabilities can be used together to preserve evidence, correlate artifacts from multiple systems and sources, reconstruct attacker activity, and support evidence-based scoping and reporting. They’re most effective when collection options and procedures are in place before an incident begins.
Forensic readiness: preparing before the next ransomware incident
Teams cannot preserve evidence under pressure if logging, collection methods, roles, and evidence-handling procedures have not already been established. The quality and speed of a ransomware investigation depend heavily on forensic readiness established before the incident. Organizations should prepare the environment so critical evidence can be preserved and analyzed under pressure.
- Define roles across incident response, IT, security, legal, compliance, and business leadership.
- Maintain logging and audit coverage for endpoints, identity systems, cloud services, remote access, and network infrastructure.
- Establish remote, local, and offline forensic collection options before an incident occurs.
- Document evidence-handling, chain-of-custody, storage, and retention procedures.
- Test backup and restoration processes and protect backup infrastructure from attacker access.
- Maintain workflows for collecting memory and other volatile evidence.
- Practice ransomware response scenarios so teams understand when to preserve evidence, when to isolate immediately, and how to coordinate parallel investigative and recovery work.
Treat ransomware response as an investigation, not just a recovery event
Restoring encrypted systems may bring operations back online, but it doesn’t establish that the attacker has been removed or that the recovery point can be trusted. Digital forensics provides the evidence needed to reconstruct the intrusion, determine its true scope, address the access and persistence that enabled it, and make informed recovery decisions.
Moving quickly and investigating thoroughly can happen together: contain with purpose, preserve the evidence that matters, and use what you learn to drive a safer recovery.