performing-ransomware-incident-response

Installation
SKILL.md

Performing Ransomware Incident Response

When to Use

  • Ransomware encryption detected on one or more endpoints
  • Ransom note files discovered on file shares or endpoints
  • File extensions changed to known ransomware variants (.locked, .encrypted, .ryuk, etc.)
  • Volume Shadow Copies deleted or backup systems targeted
  • EDR/AV alerts for known ransomware families (LockBit, BlackCat/ALPHV, Cl0p, Royal, Play)

Prerequisites

  • Incident Response Plan with ransomware-specific playbook
  • Offline/immutable backup infrastructure
  • EDR platform with ransomware rollback capability
  • No Ransom (nomoreransom.org) decryptor database access
  • Network segmentation capability for rapid isolation
  • Communication plan for stakeholders and potentially law enforcement

Workflow

Related skills
Installs
2
GitHub Stars
6.2K
First Seen
Mar 15, 2026