Basyrix SOC Response Atlas by Basyrix

Impact

T1486 — Data Encrypted for Impact

Adversaries may encrypt data on target systems or across a network to interrupt availability — the defining behavior of ransomware — typically as the final stage of an intrusion, after credential access, discovery, and often defense evasion (backup deletion, EDR tampering) have occurred.

Treat mass file modification/renaming with unfamiliar extensions, rapid volume shadow copy deletion, or ransom note creation as an active, time-critical incident requiring immediate isolation — this stage is usually the visible end of a much longer intrusion, so also scope backward for the initial access and lateral movement that preceded it.

Platforms

Windows, Linux, macOS

Priority / status

high / complete

Evidence to collect

  • List of affected hosts and shares
  • Ransom note content and file extension used
  • Timestamp of first encryption event
  • Backup deletion/tampering events
  • Evidence of preceding exfiltration