performing-ransomware-response

Installation
SKILL.md

Performing Ransomware Response

When to Use

  • Ransomware has been detected executing or file encryption is actively occurring
  • Users report inability to open files with unfamiliar extensions appended
  • A ransom note is discovered on one or more systems
  • EDR detects mass file modification patterns consistent with encryption behavior
  • Threat intelligence warns of an imminent ransomware campaign targeting the organization

Do not use for general malware incidents that do not involve file encryption or extortion; use malware incident response procedures instead.

Prerequisites

  • Ransomware-specific incident response playbook reviewed and approved by executive leadership
  • Tested and verified offline backup strategy with air-gapped or immutable copies
  • Incident retainer with a specialized ransomware response firm (e.g., Mandiant, CrowdStrike Services, Kroll)
  • Legal counsel pre-engaged for OFAC sanctions screening and regulatory notification
  • Cyber insurance carrier contact information and policy coverage details
Related skills
Installs
11
GitHub Stars
6.2K
First Seen
Mar 15, 2026