Knowledge article

Ransomware Evidence Collection Checklist

Preserve the right artifacts before negotiation or restoration decisions.

Collect ransom notes, encrypted file samples, process trees, and lateral movement telemetry.

Capture identity logs, privileged account activity, and backup access events.

Store immutable copies for legal review, insurance workflows, and post-incident analysis.