Evidence Preservation Process
During the initial panic of a ransomware attack, the immediate instinct of most internal IT departments is to reboot compromised servers, run antivirus scans, and frantically begin restoring backups. While the desire to rapidly restore business operations is understandable, taking these actions without a forensic strategy routinely results in the catastrophic spoliation of digital evidence.
A compromised enterprise network is an active crime scene. Altering or destroying digital evidence—whether intentionally or accidentally—can have severe consequences. It can obscure the Initial Access Vector (leaving the network vulnerable to a secondary attack), severely complicate regulatory reporting for data breaches, and frequently results in the outright denial of multi-million dollar cyber insurance claims due to a failure to preserve the forensic record.
At Akira Ransomware Recovery, data restoration is only half of our mandate. The other half is legally defensible digital forensics. This document outlines our rigorous Evidence Preservation Process, engineered to align with the National Institute of Standards and Technology (NIST) SP 800-86 guidelines for integrating forensic techniques into incident response.
The Order of Volatility (RFC 3227)
Digital evidence is highly fragile. To ensure nothing is lost during an engagement, our forensic engineers collect data strictly according to the industry-standard “Order of Volatility.” This principle dictates that evidence must be gathered starting with the data most likely to disappear if the system state changes or loses power.
The Golden Rule of Incident Response: Do not power down a compromised machine. Shutting down a server permanently erases volatile memory (RAM), network connection states, and running malicious processes. This memory often contains the threat actor’s decrypted payload or, in some highly fortuitous scenarios, the actual memory-resident encryption keys necessary to unlock the data without paying a ransom.
Phase 1: Volatile Data Acquisition
Before any changes are made to the disk, and before any remediation tools are deployed, our incident responders execute a targeted capture of the system’s volatile state.
Memory (RAM) Dumping
Using specialized, low-footprint forensic acquisition tools, we extract a bit-for-bit copy of the system’s physical memory. This process captures exactly what the computer was “thinking” at the time of the breach. Our reverse engineers subsequently analyze this memory dump using frameworks like Volatility to identify hidden rootkits, injected DLLs, and the active execution flow of the ransomware payload (such as Akira or LockBit) running in the background.
Network & Process State Capture
Simultaneously, we document the system’s active network connections (including established connections to external Command and Control servers), the local routing table, ARP cache, and all currently executing processes and their parent-child relationships. This allows us to instantly map the lateral movement of the threat actors across the enterprise.
Phase 2: Non-Volatile Data Acquisition (Disk Imaging)
Once the volatile data is safely secured, we proceed to capture the persistent data residing on the physical or virtual hard drives. The objective is to create a perfect, mathematically verifiable clone of the compromised disks without altering a single bit of the original evidence.
Hardware and Software Write-Blocking
If we are interacting with physical hardware, the compromised drives are removed and connected to our forensic workstations utilizing physical hardware write-blockers. These devices physically intercept and reject any write-commands sent by the operating system, ensuring that it is mechanically impossible for our team to accidentally alter the original evidence. In virtualized environments (such as VMware or Hyper-V), we utilize software write-blocking and secure snapshot cloning methodologies.
Forensic Image Formats (E01 and DD)
We do not simply copy and paste files. We generate a bit-stream image of the entire storage volume. This captures not only the encrypted files but also the unallocated space, deleted files, and file system slack space. We utilize industry-standard forensic formats, primarily the Expert Witness Format (E01) or raw (DD) formats. The E01 format intrinsically supports embedded metadata and cryptographic hashing, ensuring the image remains tamper-proof.
Phase 3: Targeted Artifact Extraction
In massive enterprise environments containing hundreds of terabytes of data, imaging every single disk bit-for-bit is operationally inefficient and delays the Wiederherstellungsprozess. In these scenarios, we perform Targeted Artifact Extraction using triage tools like KAPE (Kroll Artifact Parser and Extractor).
Instead of copying the entire disk, we surgically extract only the forensic artifacts critical to identifying the breach timeline and the Initial Access Vector (IAV). These artifacts include:
- Windows Event Logs (EVTX): To trace authentication failures, RDP lateral movement, and service creations.
- The Master File Table (MFT) & USN Journal: To track exactly when files were created, modified, deleted, or encrypted by the ransomware.
- System Registry Hives: To identify persistence mechanisms (e.g., malicious run keys or scheduled tasks).
- Web Server & Firewall Logs: To identify the external IP addresses used by the threat actors during the initial intrusion.
Phase 4: Cryptographic Hashing and Verification
To prove in a court of law or to an insurance claims adjuster that our forensic image is an exact replica of the original compromised drive, we rely on cryptographic hashing algorithms, specifically MD5 and SHA-256.
Before the imaging process begins, a mathematical hash of the original drive is generated. Upon completion of the forensic image, a hash of the newly created image is generated. If the two hashes match perfectly, it provides undeniable mathematical proof that the copy is exact and that our forensic engineers did not alter, add, or destroy any data during the acquisition process.
The Foundation of Trust: This hashing process is the absolute bedrock of digital forensics. If a hash value changes by even a single digit, the evidence is considered spoliated and is generally inadmissible in legal or regulatory proceedings.
Phase 5: Secure Storage & Vaulting
Once the evidence is acquired and mathematically verified, it must be protected. We transfer all forensic images, memory dumps, and extracted artifacts to highly secure, heavily encrypted, and air-gapped storage vaults.
We restrict access to this evidence using the Principle of Least Privilege. Only the specific forensic engineers assigned to the case are granted decryption keys to access the data. Furthermore, every time the evidence is moved, accessed, or analyzed, the action is exhaustively logged in accordance with our strict Chain of Custody protocols. This ensures a flawless, unbroken timeline of evidence handling from the moment of collection to the final resolution of the case.
A Defensible Recovery Strategy
By executing this meticulous Evidence Preservation Process before attempting any decryption or environmental sanitization, Akira Ransomware Recovery ensures that your organization’s legal, regulatory, and insurance positions remain heavily fortified. We provide the peace of mind that comes from knowing your recovery is built on a foundation of undeniable, defensible digital forensics.
Explore Our Core Standards
Need Immediate Incident Response?
If you are actively experiencing a ransomware event, secure your network and reach out to our forensic engineers immediately.
Contact Us Now