Use when executing structured recovery from a ransomware incident following
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill recovering-from-ransomware-attack --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Recovering From Ransomware Attack?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-recovering-from-ransomware-attack)More formats (shields.io, HTML) on the badges page.
---
name: recovering-from-ransomware-attack
description: Use when executing structured recovery from a ransomware incident following
NIST and CISA frameworks, including environment isolation, forensic evidence preservation,
clean infrastructure rebuild, prioritized system restoration from verified backups,
credential reset, and validation against re-infection. Covers Active Directory recovery,
database restoration, and application stack rebuild in dependency order.
domain: cybersecurity
tags:
- ransomware
- recovery
- incident-response
- backup
- defense
subdomain: ransomware-defense
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- PR.DS-11
- RS.MA-01
- RC.RP-01
- PR.IR-01
category: cybersecurity
---
# Recovering From Ransomware Attack
## Overview
Cybersecurity skill for recovering from ransomware attack. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "recovering from ransomware attack"
- "Executes structured recovery from a ransomware incident following NIST and CISA "
- After ransomware has encrypted production systems and the decision has been made to recover from backups
- When building or validating a ransomware recovery runbook before an actual incident
- After receiving a decryption key (paid ransom or law enforcement provided) and needing to safely decrypt
- When partial recovery is needed alongside decryption of remaining systems
- Conducting a recovery drill to validate RTO commitments
**Do not use** before completing containment and forensic scoping. Premature recovery without understanding the attacker's access and persistence mechanisms risks re-infection.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Incident declared and containment phase completed (all attacker access severed)
- Forensic evidence preserved (disk images, memory dumps, network captures)
- Backup integrity verified (immutable/air-gapped copies confirmed clean)
- Clean build media available (OS installation media, golden images)
- Recovery environment prepared (clean network segment isolated from compromised infrastructure)
- Recovery priority list documented (Tier 1/2/3 systems in dependency order)
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Define Objectives** — Clarify the goals and scope for from ransomware attack.
2. **Gather Resources** — Collect tools, data, and access needed for from ransomware attack.
3. **Execute Process** — Carry out from ransomware attack operations methodically.
4. **Verify Quality** — Check results against acceptance criteria.
5. **Document Outcomes** — Record findings, decisions, and next steps.
## Tools
- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing
## Process
1. **Reconnaissance** — Gather target information, identify attack surface, enumerate services
1. **Analysis/Exploitation** — Execute the technique, analyze results, document findings
1. **Reporting** — Document IOCs, write findings, provide remediation recommendations
## Verification
- [ ] All from ransomware attack procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!