Recover Data After a Ransomware Attack
Scenario
A large-scale ransomware attack or similar cyber event has encrypted or damaged data on your file systems and object storage. This page covers the process to follow to recover that data safely, including the decisions that must be made before any recovery starts.
Prerequisites
- Best practice: Deploy AirGap to protect versions of your data in an offline, protected cyber vault.
- Forensic tools that determine the beginning of the attack. Data Auditing provides historical user behavior searching as input to the forensic research. Use other security tools in addition to audit data to determine when and where the attack began and which additional systems may have been compromised.
- Data Security detections and their CSV exports provide input to the security team's research. Collect the list of users that need further analysis in Active Directory and in the other systems these users had access to, and assess the damage to other systems, applications, and file systems.
- Data Auditing provides interactive search by user or path to narrow down where in the file system the attack started.
- Correlate time stamps with network security logs and SIEM tools to identify where the threat originated within the infrastructure.
- Compile a list of compromised servers, users, and file system paths for a complete forensic analysis of the impact.
- Quarantine compromised data for antivirus scanning and root cause analysis. Recovery Manager can automate data recovery and quarantine for this purpose. See Recovery.
Phases of a Cyber Incident
- Detection: we have a problem.
- How will we know there is a problem with our data?
- Did a security tool raise an event?
- Did a user raise the issue?
- Identify: what is the scope of the incident on file systems and object storage?
- Is the attack still happening now?
- Did we sync the problem from file to object?
- Did we back up the data?
- What data is impacted (file and object)?
- Which user accounts, subnets, and systems are affected?
- Response and protection: how to stop an attacker. Attackers want your data.
- Stop file services and object services (stop the business).
- Shut off the Internet connection.
- Recover: where do I start?
- Forensics. If you don't know who, what, where, and how, it is hard to recover effectively.
- Do we have auditing tools for file systems and object storage systems?
- How far back do we store forensic logs?
- Do we have offline backups?
- How do we determine the fastest, safest method to recover?
Capabilities You Need in Place
| Capability | Why it is important | Phase of cyber event | How to address |
|---|---|---|---|
| File system auditing | Forensics and detection of a possible data attack | Detection, Identification, Recovery forensics | PowerScale OneFS file auditing |
| Object data access monitoring | Forensics and detection of a possible data attack | Detection, Identification, Recovery forensics | ECS web access log forwarding |
| IDS and IPS network systems | Early warning system and key detection vector | Detection, Identification | Zero Trust API from Superna |
| Endpoint protection on all client machines and servers that touch data | Early warning system and key detection vector | Detection, Identification | Data Security threat detection and Data Auditing (ECS and PowerScale) |
| Snapshot features for file systems | Recovery tool | Recovery | PowerScale OneFS snapshots, ECS bucket versioning and object lock |
| Object lock for object storage with versioning | Recovery tool | Protection | ECS object lock and versioning |
| Backup | Slow recovery tool | Recovery | Data Orchestration |
| Cyber vault (offline data) | Rapid recovery tool | Business continuity | PowerScale and ECS Cyber Vault AirGap solution |
When to Start Data Recovery
Complete many steps before you start any data recovery. The senior security team members complete these steps, with input from the storage team, which holds the forensic data the process needs.
- Inspect all of the IT infrastructure to verify the impact and confirm that no threat remains in the environment, for example Active Directory, DNS, application servers, desktop PCs, and any other system required for normal IT operations.
- The chief security officer, or a similar role within your enterprise, declares the start of the data recovery phase. This phase may not start for many days, depending on how long the security audit of the infrastructure takes.
- The chief security officer's team provides the summary of the compromised systems and the order of the recovery effort:
- Application servers and infrastructure are the first priority.
- Do not begin data recovery until the recovery of application servers and infrastructure (AD, DNS, NTP) is complete.
- User workstations are last in the recovery effort.
- Do not attempt any data recovery until senior security management declares this phase. A persistent, active threat can attack the data again and extend your recovery.
- Keep locked-out users in the lockout state until the recovery phase is complete and the infected PCs or VMs have been remediated.
- Identify the time stamp of the initial attack. Use it to drive recovery from the detection CSV files and snapshots, or from AirGap data that Data Security protects.
Recover the Data
Recovery Manager restores affected files from snapshots automatically. If you need to restore files manually, for example to control the order of recovery or to restore from a specific snapshot, follow this procedure.
-
Build a list of snapshots with their creation time stamps in a working document.
-
Open the Threat Detections page. For each locked-out user, open the event and review its Snapshots tab. Record the date and time stamp of the snapshot for each SMB share.
-
For each locked-out user, review the affected files in the event's file list. This list is only a sample of the activity for the user. For a comprehensive list, use the CSV download in Items & Recovery.
-
To get a more precise list, including files the user touched before the detection, run a user activity query in Data Auditing with the path
/ifs/and a time range of the last 24 hours. Data Auditing supports exporting up to 1 million events to CSV for forensic investigations. -
Use the CSV files and the Data Auditing reports to review the absolute path of each affected file. Start with the snapshots taken for the first user that was detected. This user has the oldest detection time on the Threat Detections page.
-
Browse to the snapshots you listed for the first user, and restore the files from the CSV by copying them from the snapshot back into the file system. Repeat for each file in the CSV or Data Auditing report, for each user.
noteVisually inspect the file system where you are restoring data during this process. You can delete any encrypted files you find, or keep them for later analysis.
- For follow-up analysis, create an administrator-only SMB share for a post mortem and move the encrypted files to it. Security personnel should review these files before they are deleted.
- Move ransomware notes and any other strange or unidentifiable file types to the post mortem share for analysis by security personnel.
- After you complete the post mortem and the data recovery, delete the encrypted and compromised files.
-
Unlock locked users. Unlocking requires approval from the chief security officer or similar senior management. Follow Restore User Access.