# How not to end up needing forensics, and what to do if it can't be avoided Konstantin Titkov · Gazprombank MOSCOW FORENSICS DAY ’25 · Day 2 — Friday, 12 September 2025: information security day · Scheduled 14:20–14:50 · In the recording 06:58:14–07:26:12 Talk summary · https://2025.moscow-forensics-day.workers.dev/en/summary/16-titkov Transcript: https://2025.moscow-forensics-day.workers.dev/en/transcript/16-titkov · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/15-titkov-kak-ne-dovesti-do-forenziki · Watch from 06:58:14: https://youtu.be/4V7Wez3L_58?t=25094 --- ## In brief What to do when EDR, antivirus and firewalling have not worked: an organizational talk for CISOs/CIOs/CTOs and security managers. The main point — a security incident is not an IT failure: first kick the attacker out, then fix things. To take away — the emergency actions, the stages from the SANS guide and free recommendations published together with Cyberdom. There is no product pitch; the talk continues Nikita Vyugin's. ## Key points - A security incident is not an IT failure but "a deliberate malicious action" against the infrastructure and the personnel, adaptive to attempts to resist. - First kick the attacker out — persistence points, tunnels, web shells, accounts "disguised as service accounts" — and only then fix things: otherwise he destroys what has been restored and raises the ransom, while IT in a panic connects the drives holding the copies to the infected network, and the copies get deleted., - July 2025 cases (no names): a beverage producer with a retail chain and a pharmacy chain — sales stopped and customers lost; an airline was still calculating fuel from the statistics of past flights two weeks later. - They encrypt on a Friday, on public holidays, at weekends, "on Thursdays sometimes": the write operations take time. Hence the printed-out phone numbers of employees and of their relatives, the 24/7 mode, and the roles of HR, PR, IT and security. - Against paying: the keys may not work, they may not be handed over at all "in the.ru zone", the bank will refuse on anti-money-laundering and counter-terrorist-financing grounds, and the payment may later be classified as financing of terrorism. - Emergency steps: cancel the payment orders in online banking; do not power off and do not reboot (forensic data in memory); isolate the backups; take snapshots; examine the outbound traffic. - The stages "based on the SANS guide". Preparation: the logs, locating the disks and decrypting BitLocker, reserves of money, of capacity, of installation packages and of licenses "for 'trophy' software". - Identification is a ladder: TI feeds, SOC, managed EDR, your own EDR, IT monitoring ("antiviruses being methodically disabled"), the worst being a Telegram channel. - Containment: do not reboot, disconnect from the LAN and from the SAN; "particularly cunning" malware encrypts when it loses contact with the C2. Cleanup: all the backdoors, then a change of passwords everywhere. - Recovery: the installation packages, the patches, backups under the 3-2-1 scheme; without them — test environments with production data or keying in the paper originals by hand, "two weeks or so". Before the ransomware "2-3 hours" are enough, after it days or weeks., - If the data is stolen: a second ransom for deleting it, the regulator, competitors poaching the customers, and "100% and more than once" repeated fake leaks. - Compromise assessment — a "light version of DFIR" from the logs and the traffic: the attackers sit inside for "3, 6, or even 9 months". In advance and "for free" — the plan, the reserves, protecting the backup system itself, exercises., ## Tools, artifacts, technologies - **DFIR** — instead of trying to "fight it as an IT failure", with the partner to be chosen in advance; **compromise assessment, TI feeds, SOC, managed EDR, your own EDR, IT monitoring** — the rungs of detection. - **The SANS guide** — the basis for the stages, the document is not named; **the 3-2-1 scheme** — with integrity checking; **the backup system** — criticized for sitting in a flat network. - **BitLocker, snapshots, logs, data in RAM, storage arrays/SAN/LAN, installation packages and licenses, "trophy" software** — the objects of preparation. - **GitHub**, **a Telegram channel** — from memory; **the recommendations published with Cyberdom** — free, the links are on the slide. ## Legal and organizational context - CII entities — "must first of all" report to GosSOPKA, an accredited center or the NKTsKI. - Law enforcement: the complaint and the DFIR report → the crime report register (KUSP) → seizure → a criminal case → a certificate recognizing the company as the victim (to explain, for instance, the failure to file financial statements). - Personal data: Roskomnadzor — 24 hours, "including about a fake leak", the report — 72 hours (per the speaker, with no statute cited); CII — the NKTsKI, the Central Bank — FinCERT, GDPR — with the caveat "I don't know". - The goals are to be defined before the investigation: "to prosecute" and "avoid publicity" — "Those are hard to combine…". ## Questions from the audience One question (no microphone, recorded in fragments, the name is not given): which is there more of — cases where the encryption has already happened, or cases where the attack was spotted while it was still being prepared? The answer: the question should be put to those who get called in to do DFIR; there is "survivorship bias" — the businesses that did not recover "don't come to these conferences"; prepare in advance. There were no other questions. ## The speaker's position He treats the order "kick out → clean up → recover" as not open to discussion; he rejects the ransom on technical, banking and legal grounds. He argues not with people but with the typical IT approach: he found no complete public recommendations and wrote his own. He acknowledges the limits himself: DFIR lasts days even when you have prepared, the remote format requires hands on site, and the 72 hours for the report are not the same as the duration of the investigation. The tone — a practical lecture with sarcasm, with nothing to sell. ## Quotes - "Whereas first of all, of course, you do need to kick the attacker off the infrastructure first and only then fix and restore it." - "You do have the numbers of employees' relatives, so you can reach them on a day off, printed out on paper, right?" - "…it may later be classified precisely as financing of terrorism…" - "And it's not an IT recovery plan at all, it's a completely different kind of plan." - "…survivorship bias is a thing. Many of those who couldn't recover don't come to these conferences…"