Module 5: Apply Intelligence to Common Security Problems

Analyze Malware and Ransomware Activity

Describe malware behavior, delivery, impact, and defensive relevance without treating a family label as the whole assessment.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Describe malware or ransomware activity through observable behavior, affected assets, operational impact, and defensive opportunities.

Analyze Malware and Ransomware Activity

This lesson teaches a behavior-first approach to malware and ransomware intelligence. You will connect delivery, execution, persistence, discovery, movement, impact, and recovery evidence into a useful defensive picture.

Describe the Behavior Before the Family Name

Malware labels are useful shorthand, but a family name should not replace analysis. Start with what happened: how the payload arrived, what executed it, which permissions it used, how it persisted, what it discovered, how it communicated, and what changed on the host or network. These behaviors remain useful when samples are renamed, repacked, or misclassified.

For ransomware, separate access from impact. An intrusion may begin with stolen credentials, a public-facing vulnerability, or a third-party connection. The actor may then stage data, disable recovery controls, move laterally, and encrypt selected systems. A ransom note is evidence of impact, not proof of every earlier step. Record the timeline and confidence for each part.

Use safe, authorized evidence sources: endpoint telemetry, email metadata, sandbox output, file metadata, network records, backups, and incident reports. Do not execute unknown code on production systems or collect samples outside the organization’s approved handling process. Intelligence should make response safer, not create a new exposure.

Connect Intelligence to Recovery Decisions

Ransomware intelligence has to support decisions under pressure. The response team may need to decide whether to isolate hosts, preserve volatile evidence, protect backups, notify leadership, engage legal or external responders, or prioritize restoration of a critical process. A useful product states which evidence supports each decision and which assumptions remain uncertain.

Separate indicators from response priorities. A file hash can support a hunt, while evidence that backup administration accounts were targeted may change the recovery priority. A known ransomware name may help locate relevant reporting, but asset criticality, business dependencies, recovery options, and confirmed attacker behavior determine what the organization should do next.

Finish with a short decision table: observation, confidence, immediate action, owner, and next evidence request. Include a timestamp and preserve the difference between what the incident team directly observed, what an external source reported, and what the analyst assessed. This structure helps responders move quickly without turning uncertainty into false certainty.