Ransomware
5 matching posts.
The Last Two Steps Are Not in Scope. What Makes Them Survivable Is.
Part five of testing the ransomware playbook: an assessment stops before exfiltration and encryption, and it should. But the two properties that decide how bad either gets — egress and backup reachability — are fully testable, and almost never in scope.
The Blast Radius Is One Number. Almost Nobody Has Measured It.
Part four of testing the ransomware playbook: lateral movement runs on your own administrative tooling, so detection is a signal-to-noise problem — and the number that actually decides the outcome is how many hosts accept the same credential.
Affiliates Do Not Find Novel Paths. They Find Yours.
Part three of testing the ransomware playbook: privilege escalation inside the domain uses a small, stable set of paths — the same ones already written up on this site — and the affiliate picks by reliability, not by cleverness.
Enumeration Cannot Be Prevented. Ask Whether It Was Seen.
Part two of testing the ransomware playbook: the affiliate's first hour is the same directory collection you run, it cannot be blocked, and the engagement usually destroys the only question worth asking about it on day one.
They Do Not Break In. They Log In.
Part one of testing the ransomware playbook: the initial access an affiliate needs is almost always a valid credential against a reachable endpoint — and that finding is usually already in a report somewhere, marked medium.
