Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to design effective ransomware tabletop exercises through seven critical scenarios that organizations should incorporate to identify gaps in incident response processes. Explore how to structure TTX scenarios as discussion points or injects, covering essential decision-making challenges beyond technical considerations. Master the first scenario of proper incident classification and terminology to align with legal and compliance requirements while avoiding loaded language. Discover preparatory steps internal security teams can take while waiting for third-party digital forensics assistance, including evidence preservation and resource organization. Examine cloud infrastructure impacts and service migration strategies during prolonged outages, plus learn to establish off-network investigation capabilities using cloud resources and alternative tools. Analyze various containment strategies and their organizational impacts, from communication cutoffs between cloud and enterprise systems to application disruptions affecting product shipping. Address wide-ranging credential compromise scenarios beyond simple administrator account breaches, including password store theft and NTDS.dit file compromise implications. Understand health and welfare considerations for response teams during extended incidents, covering team rotation strategies, off-site accommodations, and employee assistance programs to maintain consistent response capabilities throughout multi-week recovery periods.
Syllabus
Ransomware TTX | Seven scenarios to include in your next TTX
Taught by
SANS Digital Forensics and Incident Response