ENGINEERING GUIDE · SECURITY

Ransomware Attack Path Guide

Understand how ransomware campaigns progress through an environment and design controls that interrupt the chain at multiple points.

Engineering referenceRansomware · Attack Paths

Related Ingenix tool

Assess ransomware resilience in the browser.

Ransomware Readiness Assessment →
Engineering principle: Ransomware is rarely a single event. A useful defensive model is a chain: initial access → execution → credential access → privilege escalation → discovery → lateral movement → attack preparation → recovery disruption → impact. The objective is not to find one perfect control; it is to create multiple independent opportunities to detect, contain or stop the attacker.

1. Initial access

Initial access is the point at which an attacker first gains a foothold in the organisation. Common routes include exposed remote services, stolen credentials, phishing and malicious email attachments or links, exploitation of internet-facing applications and vulnerable appliances, and compromise of a trusted supplier or third party.

How it happens

  • Exposed remote access: Internet-facing RDP, VPN, remote-management interfaces or other services can be targeted directly or accessed using stolen credentials.
  • Credential compromise: Password reuse, credential theft, infostealers, password spraying and previously breached credentials can provide valid access without exploiting a vulnerability.
  • Phishing: A convincing message can persuade a user to disclose credentials, approve an authentication request, open a malicious document or visit an attacker-controlled site.
  • Internet-facing vulnerabilities: Unpatched firewalls, VPN appliances, web applications, remote-management platforms and other perimeter systems can provide a direct foothold.
  • Third-party compromise: An attacker may enter through a supplier, managed service provider or software distribution mechanism that already has trusted access.

Controls required

  • Maintain an accurate inventory of internet-facing systems and remove unnecessary exposure.
  • Require phishing-resistant MFA where practical, particularly for administrators, remote access and cloud services.
  • Disable legacy authentication and prevent authentication paths that bypass MFA.
  • Patch internet-facing systems quickly and maintain an emergency process for critical vulnerabilities.
  • Place remote administration behind controlled access points rather than exposing management interfaces directly to the Internet.
  • Use email filtering, attachment and URL inspection, safe browsing controls and user reporting mechanisms.
  • Apply conditional access and risk-based authentication where the identity platform supports it.
  • Monitor authentication failures, unusual geographies, impossible travel, unfamiliar devices and suspicious new sessions.

Engineering test: Produce a list of every service reachable from the Internet. For each one, document its owner, purpose, authentication method, MFA status, patch level and logging. Anything that cannot be justified should be removed or restricted.

2. Execution

Once a foothold exists, the attacker needs code or commands to execute. Execution may occur through a malicious attachment, script, command interpreter, remote-management tool, compromised application or user-approved payload.

Controls required

  • Use endpoint protection/EDR with behavioural detection rather than relying solely on signature-based antivirus.
  • Restrict unnecessary scripting and administrative interpreters such as PowerShell, Windows Script Host and command shells according to operational need.
  • Use application control or allow-listing on high-value systems where practical.
  • Block execution from common user-writable locations when compatible with the application estate.
  • Prevent standard users from installing or running software requiring administrative rights.
  • Enable endpoint telemetry that records process creation, parent-child relationships and command execution where appropriate.

Engineering test: Verify that an ordinary user cannot simply download an executable or script and execute it on a representative workstation without generating a security event or encountering a policy control.

3. Credential access

Ransomware operators need identities to move through the environment and increase their privileges. Credentials may be obtained through phishing, browser or password-store theft, malware, credential dumping, token/session theft or abuse of poorly protected service accounts.

Controls required

  • Use MFA for privileged and remote access and protect authentication systems as critical infrastructure.
  • Eliminate shared administrator accounts and use named, accountable administrative identities.
  • Separate normal user accounts from privileged administrator accounts.
  • Use managed service accounts or equivalent mechanisms instead of long-lived static service-account passwords where supported.
  • Reduce the number of systems on which privileged credentials can be used or cached.
  • Use privileged access management or just-in-time elevation where appropriate.
  • Monitor abnormal authentication and privileged-account activity.

Key principle: Assume a normal user credential may eventually be compromised. The design objective is to prevent that credential from becoming a universal key to the environment.

4. Privilege escalation

After obtaining an initial identity, attackers may seek higher privileges by exploiting vulnerable software, abusing excessive permissions, stealing administrator credentials or finding insecure delegation and configuration paths.

Controls required

  • Apply least privilege to users, service accounts, applications and administrators.
  • Separate workstation administration from domain or server administration.
  • Use dedicated privileged workstations or hardened administrative paths for high-impact administration.
  • Patch operating systems, applications and management infrastructure.
  • Review local administrator membership and remove unnecessary persistent privileges.
  • Monitor privilege changes, new administrator accounts, suspicious group membership changes and unusual administrative activity.
  • Protect domain controllers and other identity infrastructure as a separate high-trust zone.

Engineering test: Review how a compromised standard workstation account could become a local administrator, server administrator or domain administrator. Every path should have an identified preventative or detective control.

5. Discovery

Attackers normally spend time learning the environment before deploying ransomware. They may identify users, servers, domain controllers, file shares, backup systems, security products, network ranges, management platforms and valuable data.

Controls required

  • Segment management, server, user, backup and critical infrastructure networks according to trust.
  • Restrict unnecessary east-west communication with host and network firewalls.
  • Limit access to management interfaces to authorised administration networks.
  • Monitor unusual network scanning, large-scale authentication attempts and unexpected access to administrative services.
  • Maintain accurate asset and dependency documentation so defenders can distinguish expected discovery activity from suspicious activity.

Discovery cannot always be prevented. The engineering goal is to make unnecessary discovery difficult, make sensitive systems harder to reach, and make abnormal discovery visible.

6. Lateral movement

Lateral movement is the transition from the initially compromised system to additional systems. Common mechanisms include stolen credentials, remote administration protocols, SMB/file sharing, RDP and other management services.

Controls required

  • Design network segmentation around trust boundaries rather than simply creating VLANs.
  • Use firewall policy between user, server, management, backup and critical zones.
  • Permit only the protocols and source/destination combinations required for business operations.
  • Restrict RDP and other remote administration protocols to approved administration paths.
  • Control SMB reachability and remove unnecessary SMB exposure between workstation networks.
  • Use endpoint firewalls as an additional layer of east-west control.
  • Alert on unusual remote logons, administrative share access, new RDP sources and unexpected server-to-server connections.

Engineering test: From a normal workstation VLAN, document which servers and management services are reachable. If the answer is effectively “everything”, segmentation is not providing meaningful ransomware containment.

7. Attack preparation and ransomware deployment

Before encryption or data destruction, attackers may prepare the environment. Preparation can include identifying valuable data, disabling security controls, staging tools, creating persistence, obtaining additional credentials and coordinating access to many systems.

Controls required

  • Protect EDR, antivirus, logging and management agents from unauthorised tampering.
  • Alert on attempts to disable security services or modify security tooling.
  • Monitor unusual use of administrative tools across large numbers of systems.
  • Restrict administrative privileges and separate the people and accounts that administer security systems from ordinary user accounts.
  • Use central logging so an attacker cannot easily erase every useful record from individual hosts.
  • Maintain tested incident-response procedures for rapidly isolating affected endpoints and accounts.

8. Recovery disruption

A capable ransomware operator will often try to prevent recovery before triggering the final impact. Backup servers, repositories, snapshots, hypervisors and backup credentials can therefore become high-value targets.

Controls required

  • Keep backup infrastructure on a separate security boundary from ordinary production systems.
  • Use separate administrative identities for backup management.
  • Protect backup repositories against ordinary domain credentials where technically possible.
  • Maintain offline, immutable or otherwise protected recovery copies appropriate to the organisation's risk.
  • Monitor deletion of backups, unusual retention-policy changes, mass snapshot deletion and unexpected backup administration.
  • Test actual restoration rather than merely checking that backup jobs report success.
  • Document RPO, RTO and the dependency order for critical services.

Engineering test: Ask whether compromise of a normal domain administrator would allow an attacker to delete or encrypt every available backup. If yes, the recovery architecture has a major single point of failure.

9. Impact

Impact occurs when the attacker encrypts data, destroys systems, disrupts services or combines encryption with data theft and extortion. At this point, prevention has failed and the organisation's ability to contain the incident and recover becomes critical.

Controls required

  • Maintain rapid endpoint and account isolation capability.
  • Ensure critical systems can be recovered from protected backups.
  • Prioritise identity, DNS, DHCP, network services, virtualisation, storage and other dependencies in recovery planning.
  • Maintain communications procedures for IT leadership, management, suppliers, insurers, legal advisers and other stakeholders as appropriate.
  • Preserve relevant evidence before systems are rebuilt where operationally possible.
  • Use recovery exercises to validate that documented procedures work under realistic pressure.

Breaking the attack chain

No single control should be expected to stop every ransomware campaign. A resilient design creates multiple barriers:

  • Prevent access: reduce exposure, patch perimeter systems and enforce strong authentication.
  • Prevent execution: use EDR, application control and endpoint hardening.
  • Limit identity abuse: separate privileged accounts and minimise standing administrative access.
  • Contain movement: segment networks and restrict east-west firewall policy.
  • Detect preparation: centralise identity, endpoint, network and backup telemetry.
  • Protect recovery: isolate backup administration and maintain protected recovery copies.
  • Recover quickly: test restoration and document dependencies, RPO and RTO.

Implementation checklist

  • Document every Internet-facing service and its authentication method.
  • Verify MFA coverage for remote and privileged access.
  • Review patch exposure on Internet-facing and high-value systems.
  • Review privileged groups, service accounts and administrative paths.
  • Map workstation-to-server and server-to-server communication.
  • Restrict RDP, SMB and management protocols to required paths.
  • Verify endpoint protection and tamper protection across critical systems.
  • Confirm central logging captures identity, endpoint, firewall and backup events.
  • Test whether a compromised administrator can destroy the available backups.
  • Perform a representative restore and measure the actual recovery time.
  • Document exceptions and review them regularly.