📋 Ransomware Response Guide  ·  Step 3 of 7

The evidence you destroy in the first hour cannot be recovered

Most businesses unknowingly destroy critical forensic evidence in the first hours of a ransomware incident. That evidence is what cyber insurers, law enforcement, and digital forensics teams need to investigate the attack, attribute it to a known group, and sometimes recover encrypted data without paying the ransom.

Get the Full PDF Guide Our Cybersecurity Services

Why evidence preservation matters more than you think

In the chaos of a ransomware attack, business owners and IT teams instinctively focus on getting systems back online as fast as possible. That instinct is understandable — and it's the single biggest reason forensic evidence gets destroyed.

The first 24 hours of an incident contain irreplaceable evidence: volatile memory contents, network connection logs, attacker-created files, and timestamps that establish the incident timeline. Reboot a machine, restore from backup, or wipe an infected workstation, and that evidence is gone permanently. With it goes your ability to make a cyber insurance claim, pursue law enforcement action, identify the ransomware variant for potential decryption, and prevent the same attack from happening again.

Do not power off, reboot, or wipe affected machines

This rule overrides every other instinct. Until a forensic investigator gives you clearance, infected machines must remain powered on and disconnected from the network — not shut down.

Why this matters:

  • Volatile memory (RAM) often contains encryption keys, command-and-control communication details, and active process information. All of this disappears when the machine powers off.
  • Active network connections in memory can identify the attacker's infrastructure — IP addresses, domains, and tools — which can be used to identify the threat group.
  • Decryption keys for some ransomware variants have been recovered from memory dumps. Power the machine down, and any chance of free decryption goes with it.
  • Forensic timeline reconstruction depends on file system metadata that can be altered by reboots, defragmentation, or even normal shutdown processes.

Preserve logs before they roll over

Logs are evidence. They establish the timeline, identify the entry point, and document the attacker's actions inside your environment. The problem: most log systems have retention policies that overwrite older entries within hours or days. You need to capture them before they're gone.

Logs to preserve immediately:

  • Windows Event Logs from all affected servers and workstations — especially Security, System, and Application logs
  • Microsoft 365 audit logs and Entra ID sign-in logs
  • Firewall logs showing inbound and outbound traffic in the days leading up to and during the attack
  • VPN connection logs identifying who connected, from where, and when
  • Active Directory authentication logs and changes to user accounts or group memberships
  • EDR and antivirus alerts and detection events
  • Cloud storage access logs (SharePoint, OneDrive, Google Drive)
  • Email security platform logs showing inbound phishing or attacker communication

If you have a SIEM or log aggregation platform, export the relevant time windows immediately. If you don't, copy individual log files to a separate clean drive — never to the production network.

Document the attack as you see it

Take photographs and screenshots of everything before anything changes. This sounds obvious, but it's frequently skipped in the rush of response.

  • Photograph ransom notes on screen — phone camera is fine
  • Screenshot every error message, encrypted file extension, and ransom demand interface
  • Photograph any physical evidence — unusual USB devices, attached external drives
  • Note the exact filenames of ransom notes (often README.txt, HOW_TO_DECRYPT.html, or variant-specific names)
  • Record the cryptocurrency wallet addresses and ransom amounts demanded
  • Save copies of any communication from the attacker — email, chat portals, or ransom note text

This evidence is what cyber insurance carriers require to process claims and what FBI investigators need to identify the threat group and potentially recover funds.

Engage forensics before paying or recovering

If you have cyber insurance, your policy almost certainly includes an incident response retainer or panel — pre-approved forensics firms that the carrier will pay for if you call them in early. Calling them is one of your first priorities, not a later step.

Why this order matters:

  • Forensics firms can image affected systems before recovery efforts destroy evidence
  • They can identify the ransomware variant and check whether free decryptors exist
  • They can detect whether attackers still have persistence in your environment — common with sophisticated attacks
  • Their work product is what your insurance claim and any regulatory notifications will be built on

If you don't have cyber insurance or your policy doesn't include forensics coverage, this is a paid engagement — but for any business with more than 25 users, it's almost always worth it. The cost of a misdiagnosed recovery is much higher than the cost of a forensic investigation.

Chain of custody for collected evidence

Forensic evidence has to be handled carefully or it loses its value in insurance claims, law enforcement investigations, and any legal proceedings that may follow. Maintain a written chain of custody:

  • Who collected the evidence, when, and from which system
  • Where the evidence is stored (locked location, encrypted drive)
  • Who has accessed the evidence since collection, and for what purpose
  • Any copies made and where they were sent (to insurance, law enforcement, forensics)

Even an informal log kept in a spreadsheet is better than nothing. Forensics firms will take over formal chain of custody once they're engaged.

Step 3 Action Checklist
  • Keep infected machines powered on and disconnected — do not shut down or reboot
  • Export logs immediately: Windows Event, M365 audit, Entra sign-in, firewall, VPN, AD, EDR
  • Photograph and screenshot ransom notes, error messages, and encrypted file extensions
  • Document a timeline of discovery and every response action
  • Engage cyber insurance panel forensics firm before attempting recovery
  • Maintain a written chain of custody for any evidence you collect
  • Save cryptocurrency wallet addresses and ransom communications for law enforcement

What's next: Step 4: Attack Vector

Once you've completed this step, the next priority is identifying the attack vector — how the attackers got in. That's covered in Step 4 of this guide.

← Step 2: Assess Scope ↑ Back to guide overview Step 4: Attack Vector →
Ransomware Response · Step-by-Step Guide

The complete 7-step ransomware response cluster

Each step builds on the previous one. Skip a step at your own risk.

  • 1 First 60 seconds Isolate infected systems →
  • 2 First 30 minutes Assess the scope of the attack →
  • 3 First 60 minutes Preserve forensic evidence →
  • 4 First 2 hours Identify the attack vector →
  • 5 First 4 hours Notify stakeholders →
  • 6 First 24–72 hours Assess legal & compliance impact →
  • 7 First 30 days post-recovery Harden the environment →
← Back to main Ransomware Response Guide Download PDF
Need Help Right Now?

We've helped businesses recover from ransomware before

If you're dealing with an active incident or want to make sure you're protected before it happens, call us directly. We pick up.

Schedule a Free Consultation (646) 791-2137
0
Skip to Content
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Home
About
Services
Pricing
Client Stories
Free Consultation

Contact Us

646-791-2137info@mooretechnologyconsulting.com

MTC_logo_R2-01.png

New York Locations
New York City, NY Manhattan | Brooklyn | Queens | Bronx | Staten Island

White Plains, NY 44 S Broadway, White Plains, NY 10601

Connecticut Locations
Stamford, CT 700 Canal Street, Stamford, CT 06902



Westport, CT 55 Post Rd W, Westport, CT 06880

©2026 Moore Technology Consulting.

All Rights Reserved.

Privacy Policy | FAQ

Moore Technology Consulting

Cybersecurity-first managed IT for SMBs across CT, NY & NYC.

(646) 791-2137 ✉ info@mooretechnologyconsulting.com 📍 Stamford, CT · White Plains, NY · Westport, CT
Services
  • Managed IT Services
  • Cybersecurity
  • Microsoft 365
  • Cloud Services
  • Backup & DR
  • Compliance & vCIO
Resources
  • Free Consultation
  • Ransomware Guide
  • About MTC
  • Client Stories
  • Blog
  • Contact Us
Stay Informed

Practical IT & cybersecurity insights for business owners. No spam, no fluff — just useful intel.

We respect your inbox. Unsubscribe anytime.

Powered by an Enterprise-Grade Stack

Microsoft Partner · Datto Partner · Huntress Partner · ThreatLocker Partner
Cisco Meraki · Fortinet · Cloudflare · Pax8

Service Areas

Stamford, CT Greenwich, CT Westport, CT White Plains, NY New York City

Moore Technology Consulting is headquartered in White Plains, NY and certified as a Minority Business Enterprise (MBE) by the New York City Department of Small Business Services (SBS) and New York State Empire State Development (ESD). We deliver managed IT and cybersecurity services to small and mid-sized businesses across Fairfield County, Westchester, and the greater New York metro area.

© 2026 Moore Technology Consulting. All rights reserved.
Privacy Policy Terms of Service Accessibility