Ransomware contained in 47 minutes.
A XXXXXXXXXX manufacturer with 1,400 employees and three plants. A Tuesday night in April. What happened, minute by minute.
Illustrative case · client anonymized with permission · hosts from example.com, IPs from 203.0.113.0/24
T+ TIMELINE · DRAG TO REPLAY
T+00:47
Contained
- T+00:00 Mass file renames on fs-02.example.com trigger a Critical alert. EDR · automated
- T+00:02 L2 analyst confirms ransomware behavior, severity Critical. Keel SOC · A. Demir
- T+00:05 Client IT lead called. Isolation already authorized by contract. Keel SOC → client
- T+00:11 fs-02 and 13 workstations isolated. Encryption stops. Keel SOC · automated + manual
- T+00:19 Compromised service account disabled, Kerberos tickets reset. Keel Response · J. Petersen
- T+00:31 Lateral movement from 203.0.113.40 ruled out on remaining hosts. Threat hunt
- T+00:47 Contained. No further malicious activity observed. Incident lead declaration
- T+00:58 Restore from offline backup begins. Keel Managed IT
Where the chain broke.
The attackers had four steps to go. Host isolation at T+00:11 stopped them at step three.
Downtime and recovery.
- Contained
- T+00:47
- from first alert
- Hosts isolated
- 14
- of 1,160 endpoints
- Data exfiltrated
- None
- verified by forensics
- Full production
- 2 days
- restored from offline backup
“We had a plan on paper. Keel turned it into a phone call at 02:14 where someone calmly told us exactly which switch port to pull.”
Lessons learned.
-
01
Pre-authorized actions save minutes.
Isolation was approved in the contract. Nobody had to be woken up to decide.
-
02
Offline backups made the difference.
Restores were tested monthly, so the restore plan was a checklist, not an experiment.
-
03
MFA on every admin account.
One service account without MFA was the way in. It now has MFA and a vault.