Write an Incident Handler Journal Entry
Lab Objective
Create a structured incident record from a synthetic ransomware scenario and separate confirmed scenario facts from questions requiring technical evidence.
Scenario
A small healthcare clinic receives a targeted phishing email with a malicious attachment. An employee opens it, malware executes, ransomware encrypts networked files, and the attacker demands payment. Patient data may also have been copied before encryption.
Procedure
- Record the date, incident description, and tools used. If no tool was used, write that explicitly.
- Answer who, what, when, where, and why using only the supplied scenario.
- List the initial access vector and the affected assets.
- Write unanswered questions about the first endpoint, spread, backups, and possible exfiltration.
- Add containment and evidence-preservation actions without claiming they were performed.
Expected Evidence
The completed journal should contain a concise incident narrative, an explicit phishing hypothesis, a scope question for endpoint and file activity, and a recovery question for isolated backups. It should not claim a live compromise or a confirmed data breach.
Security Takeaways
The five W’s create a reliable starting point. They are not a substitute for endpoint, identity, network, email, and backup evidence. A useful incident note makes the next investigation step obvious.