Writing an Incident Handler Journal Entry for a Ransomware Scenario With the Five W’s
🔄 Topic
I completed an incident-handler journal entry about a fictional ransomware incident at a small healthcare clinic. The important lesson was not memorizing ransomware terminology. It was learning how to turn an alarming story into a structured investigation.
🎯 Goal
Use the five W’s—who, what, when, where, and why—to establish an initial incident narrative, then identify which facts still need evidence.
🛠 What I Did
The scenario described targeted phishing emails with a malicious attachment, malware execution, ransomware deployment, encrypted patient files, and a ransom demand. I recorded the attacker profile, initial access vector, approximate time, affected environment, and apparent financial motivation.
I then separated the known scenario from the questions an incident handler should ask next: which endpoint first executed the attachment, how far did the encryption spread, were backups available and unaffected, and was patient data exfiltrated before encryption? Those questions prevent the first description from becoming the final incident report.
The exercise also made the defensive response clearer. Email filtering and phishing awareness may reduce initial access, but containment, endpoint scoping, backup validation, identity review, and evidence preservation are needed after execution. I did not use live tools or investigate a real clinic; this was a training scenario.
🔗 Key Cybersecurity Connections
- structured notes preserve a timeline and reduce assumption drift
- phishing is an entry hypothesis, not proof of the full attack path
- encryption impact and data theft are separate questions
- backup availability must be verified, not assumed
- incident response needs both containment actions and evidence collection
🔍 Investigation Questions
- Which account received and opened the attachment?
- What process executed first, and on which endpoint?
- Which hosts, shares, and identities show related activity?
- Was data copied out before files were encrypted?
- Are backups isolated, recent, and restorable?
🚨 Detection Opportunities
Useful pivots include malicious-attachment detections, process creation telemetry, unusual file-renaming or encryption activity, authentication anomalies, large outbound transfers, and backup deletion attempts. No single alert proves the incident; correlation supplies scope.
🧭 MITRE ATT&CK Techniques
The scenario is consistent with T1566.001 Spearphishing Attachment and potentially T1486 Data Encrypted for Impact, but the exercise did not produce telemetry proving those techniques occurred in a real environment.
⚠ Challenges
The hardest part was resisting the urge to fill gaps with a confident story. A good incident journal records what the scenario says and makes the missing evidence visible.
📚 What I Learned
The five W’s are not just a school worksheet. They are a compact way to create an investigation boundary, preserve uncertainty, and hand the next analyst useful questions instead of vague alarm.
➡ Next Steps
- practise the same structure with synthetic endpoint and authentication logs
- add containment, eradication, and recovery checkpoints
- distinguish confirmed observations from working hypotheses in every incident note