Blog
Practical incident response and DFIR guides from the CICADA IR team.
- ·14 min read
Ransomware incident response: the first 24 hours
A containment-and-evidence-first playbook for the first 24 hours of a ransomware incident — isolate without destroying the memory you need, scope the blast radius, validate backups before you trust them, recover in the right order, and produce decisions you can defend to insurers and regulators.
RansomwareIncident ResponseContainmentDFIRCyber Insurance - ·15 min read
Detecting Active Directory ransomware precursors: stopping lateral movement before encryption
Ransomware doesn't start with encryption. It starts with credential theft, lateral movement, and privilege escalation in Active Directory. A practical detection and response playbook for the AD attack chain — kerberoasting, DCSync, ticket-granting attacks, and the tier-2 sequences that catch them.
Active DirectoryRansomwareLateral MovementIncident ResponseDFIR