Lab Objective

Create a structured incident record from a synthetic ransomware scenario and separate confirmed scenario facts from questions requiring technical evidence.

Scenario

A small healthcare clinic receives a targeted phishing email with a malicious attachment. An employee opens it, malware executes, ransomware encrypts networked files, and the attacker demands payment. Patient data may also have been copied before encryption.

Procedure

  1. Record the date, incident description, and tools used. If no tool was used, write that explicitly.
  2. Answer who, what, when, where, and why using only the supplied scenario.
  3. List the initial access vector and the affected assets.
  4. Write unanswered questions about the first endpoint, spread, backups, and possible exfiltration.
  5. Add containment and evidence-preservation actions without claiming they were performed.

Expected Evidence

The completed journal should contain a concise incident narrative, an explicit phishing hypothesis, a scope question for endpoint and file activity, and a recovery question for isolated backups. It should not claim a live compromise or a confirmed data breach.

Security Takeaways

The five W’s create a reliable starting point. They are not a substitute for endpoint, identity, network, email, and backup evidence. A useful incident note makes the next investigation step obvious.