Systems involved
| System | Role |
|---|---|
| Wazuh / Microsoft Defender / Sentinel | Source detections and timeline. |
| Studio terminal | SSH to access switches for port shutdown and VLAN quarantine. |
| FortiGate / Palo Alto | East-west and north-south containment rules. |
| Microsoft Entra ID | Disable suspect accounts, revoke sessions. |
| Veeam / Datto | Snapshot inventory, identify clean restore points. |
| VMware vCenter / Hyper-V | VM snapshot capture for forensics. |
Microsoft Teams #sec-ir | Internal IR channel. |
| ServiceNow IRM | Customer incident record and case file. |
| Gmail | Customer executive comms and law-enforcement liaison. |
| Studio Procedures | Ransomware containment runbook. |
Walkthrough
Verify the detection in 60 seconds
Quarantine at the switch
shutdown and a VLAN move into the quarantine VLAN. Approval prompt; you approve and execute.Cut east-west at the firewall
10.10.20.0/24 from anything outside the file server segment for the duration of the incident.Disable suspect accounts
Snapshot the affected hosts
Identify clean restore points
Open the IR record and brief the customer
Run the executive call
Restore and validate
Where Studio earns its keep
- Containment fires at the switch, the firewall, and Entra ID from one workspace in minutes — not from three engineers logging into three consoles.
- The restore order is a clean dependency plan, not a guess from a backup admin under pressure.
- The customer executive call has a screen they can read — timeline, status, plan, ETA — instead of a phone call about feelings.
- Every action is timestamped in the case file from the moment it ran. The cyber-insurance investigation has a proper paper trail without anyone reconstructing it.
Related
Procedures
Ransomware containment so the steps are pre-staged for the next time.