跳到主要内容
知仓学习社ZHICANG

ransomware-first-response

Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that m…

不碰外部(只输出文字)无严重或高危命中mohitagw15856/pm-claude-skills

它会碰到什么

扫了多少1 个文本文件,5 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Ransomware First Response

The first hour decides how bad a ransomware or malware incident gets. Panic leads to the wrong moves — paying immediately, wiping evidence, or reconnecting an infected machine and spreading it. This gives a calm, correct sequence: isolate, preserve your options, and recover from the safest source — while being honest that a serious business incident needs professional responders.

What This Skill Produces

  • Immediate containment — disconnect from networks and shared drives to stop spread, without destroying recovery options
  • Preserve evidence & options — don't wipe or pay reflexively; photograph the ransom note, note timing, keep the door open
  • The recovery path — restore from clean offline backups, check for a known/legitimate decryptor, or engage a professional
  • The payment decision — the honest tradeoffs and risks of paying (no guarantee, funds crime, marks you as payer)
  • Reporting — the authorities/agencies to notify, and (for orgs) any breach-notification duties
  • A scope flag — personal/small setup vs. a business incident that needs real incident-response help

Required Inputs

Ask for these if not provided:

  • What you're seeing — ransom note, encrypted/renamed files, pop-ups, or just suspicious behavior
  • The setup — personal device, home network, or a business/multi-device environment
  • Backups — do you have recent offline/cloud backups, and are they disconnected
  • Spread — is it one device or possibly shared drives/other machines
  • Sensitivity — is sensitive/regulated data involved

Framework: Isolate, Preserve, Recover — Don't Panic

  1. Isolate now. Disconnect the device from Wi-Fi/network and unplug shared/external drives to stop encryption from spreading — but don't start deleting.
  2. Don't destroy your options. Don't wipe, don't reformat yet, and don't pay on impulse. Photograph the ransom note and record what/when you noticed.
  3. Recover from clean backups. The best outcome is wiping and restoring from a known-good offline backup — verify it wasn't connected during infection.
  4. Check for legitimate decryptors. Some ransomware strains have free, reputable decryptors via official security projects — check before considering payment.
  5. Weigh payment honestly. Paying is risky: no guarantee of recovery, it funds criminals, and it flags you. Treat it as a last resort, ideally with professional advice.
  6. Report and, if serious, get help. Notify the relevant authorities; for a business or sensitive-data incident, engage professional incident response and check notification duties.

Output Format

Suspected [ransomware/malware] · [personal/business] · backups: [yes/no]

Now (first minutes)

  1. Disconnect network + unplug external/shared drives.
  2. Don't wipe, don't pay yet. Photograph the ransom note; note time/first sign.
  3. Isolate any other devices that share the network/drives.

Recover: wipe + restore from a clean offline backup → or check for a legitimate free decryptor → or engage a professional.

Payment: last resort, high risk — [tradeoffs]; get advice first.

Report: [relevant authority/agency] · [breach-notification duties if applicable].

> This is first-response guidance for a personal/small setup. A business incident, or anything with sensitive/regulated data, needs professional incident responders — engage them early.

Quality Checks

  • [ ] Containment (disconnect network/drives) is the first action
  • [ ] Warns against wiping or paying reflexively; preserve evidence
  • [ ] Prioritizes restoring from a verified offline backup
  • [ ] Mentions checking for legitimate free decryptors before payment
  • [ ] Presents the payment decision honestly as a risky last resort
  • [ ] Includes reporting and flags when to get professional IR help

Anti-Patterns

  • Paying immediately out of panic.
  • Reformatting/wiping before preserving evidence and confirming backups.
  • Reconnecting the infected device and spreading it.
  • Restoring from a backup that was connected during infection.
  • Treating a serious business breach as a DIY job.

Example Trigger Phrases

  • "My files are all encrypted and there's a ransom note — what do I do?"
  • "I think I've got ransomware, help me not make it worse."
  • "Suspicious pop-up locked my computer demanding payment."
  • "Should I pay the ransom to get my files back?"
  • "Malware on my work laptop — what's my first move?"

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 3 个不同仓库或目录里都有叫 ransomware-first-response 的技能。它们内容并不相同,别混用: