ransomware-first-response
Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that m…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Ransomware First Response
The first hour decides how bad a ransomware or malware incident gets. Panic leads to the wrong moves — paying immediately, wiping evidence, or reconnecting an infected machine and spreading it. This gives a calm, correct sequence: isolate, preserve your options, and recover from the safest source — while being honest that a serious business incident needs professional responders.
What This Skill Produces
- Immediate containment — disconnect from networks and shared drives to stop spread, without destroying recovery options
- Preserve evidence & options — don't wipe or pay reflexively; photograph the ransom note, note timing, keep the door open
- The recovery path — restore from clean offline backups, check for a known/legitimate decryptor, or engage a professional
- The payment decision — the honest tradeoffs and risks of paying (no guarantee, funds crime, marks you as payer)
- Reporting — the authorities/agencies to notify, and (for orgs) any breach-notification duties
- A scope flag — personal/small setup vs. a business incident that needs real incident-response help
Required Inputs
Ask for these if not provided:
- What you're seeing — ransom note, encrypted/renamed files, pop-ups, or just suspicious behavior
- The setup — personal device, home network, or a business/multi-device environment
- Backups — do you have recent offline/cloud backups, and are they disconnected
- Spread — is it one device or possibly shared drives/other machines
- Sensitivity — is sensitive/regulated data involved
Framework: Isolate, Preserve, Recover — Don't Panic
- Isolate now. Disconnect the device from Wi-Fi/network and unplug shared/external drives to stop encryption from spreading — but don't start deleting.
- Don't destroy your options. Don't wipe, don't reformat yet, and don't pay on impulse. Photograph the ransom note and record what/when you noticed.
- Recover from clean backups. The best outcome is wiping and restoring from a known-good offline backup — verify it wasn't connected during infection.
- Check for legitimate decryptors. Some ransomware strains have free, reputable decryptors via official security projects — check before considering payment.
- Weigh payment honestly. Paying is risky: no guarantee of recovery, it funds criminals, and it flags you. Treat it as a last resort, ideally with professional advice.
- Report and, if serious, get help. Notify the relevant authorities; for a business or sensitive-data incident, engage professional incident response and check notification duties.
Output Format
Suspected [ransomware/malware] · [personal/business] · backups: [yes/no]
Now (first minutes)
- Disconnect network + unplug external/shared drives.
- Don't wipe, don't pay yet. Photograph the ransom note; note time/first sign.
- Isolate any other devices that share the network/drives.
Recover: wipe + restore from a clean offline backup → or check for a legitimate free decryptor → or engage a professional.
Payment: last resort, high risk — [tradeoffs]; get advice first.
Report: [relevant authority/agency] · [breach-notification duties if applicable].
> This is first-response guidance for a personal/small setup. A business incident, or anything with sensitive/regulated data, needs professional incident responders — engage them early.
Quality Checks
- [ ] Containment (disconnect network/drives) is the first action
- [ ] Warns against wiping or paying reflexively; preserve evidence
- [ ] Prioritizes restoring from a verified offline backup
- [ ] Mentions checking for legitimate free decryptors before payment
- [ ] Presents the payment decision honestly as a risky last resort
- [ ] Includes reporting and flags when to get professional IR help
Anti-Patterns
- Paying immediately out of panic.
- Reformatting/wiping before preserving evidence and confirming backups.
- Reconnecting the infected device and spreading it.
- Restoring from a backup that was connected during infection.
- Treating a serious business breach as a DIY job.
Example Trigger Phrases
- "My files are all encrypted and there's a ransom note — what do I do?"
- "I think I've got ransomware, help me not make it worse."
- "Suspicious pop-up locked my computer demanding payment."
- "Should I pay the ransom to get my files back?"
- "Malware on my work laptop — what's my first move?"
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
skills/ransomware-first-response/SKILL.md同一个仓库里的其他技能
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 ransomware-first-response 的技能。它们内容并不相同,别混用:
- mohitagw15856/pm-claude-skills — Handle the first hour of a suspected ransomware or malware infection calmly and correctly
- mohitagw15856/pm-claude-skills — Handle the first hour of a suspected ransomware or malware infection calmly and correctly